Launch Week Day 1: Announcing Security Design Review
HIGH 8.1 Maven

Improper Input Validation in Apache Struts

GHSA-7jw3-5q4w-89qg · CVE-2016-1181

Published · Modified

Description

ActionServlet.java in Apache Struts 1 1.x through 1.3.10 mishandles multithreaded access to an ActionForm instance, which allows remote attackers to execute arbitrary code or cause a denial of service (unexpected memory access) via a multipart request, a related issue to CVE-2015-0899.

Ready to move

Start Securing

Free, no credit card | First findings in minutes