CVE-2016-8738 Information

Description

In Apache Struts 2.5 through 2.5.5 if an application allows entering a URL in a form field and the built-in URLValidator is used it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL.

CVSS Vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Reference

http://www.securityfocus.com/bid/94657 https://security.netapp.com/advisory/ntap-20180629-0003/ https://struts.apache.org/docs/s2-044.html

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

NONE

Base Score

HIGH

Base Severity

5.9

Share on: