Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2016-4438
The REST plugin in Apache Struts 2 2.3.19 through 2.3.28.1 allows remote attackers to execute arbitrary code via a crafted expression.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.535
EPSS Ranking
97.9%
CVSS Severity
CVSS v3 Score
9.8
CVSS v2 Score
7.5
References
http://jvn.jp/en/jp/JVN07710476/index.html
http://jvndb.jvn.jp/jvndb/JVNDB-2016-000110
http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html
http://www.securityfocus.com/bid/91275
https://bugzilla.redhat.com/show_bug.cgi?id=1348238
https://struts.apache.org/docs/s2-037.html
http://jvn.jp/en/jp/JVN07710476/index.html
http://jvndb.jvn.jp/jvndb/JVNDB-2016-000110
http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html
http://www.securityfocus.com/bid/91275
https://bugzilla.redhat.com/show_bug.cgi?id=1348238
https://struts.apache.org/docs/s2-037.html
Products affected by CVE-2016-4438
Apache
»
Struts
»
Version:
2.3.20
cpe:2.3:a:apache:struts:2.3.20
Apache
»
Struts
»
Version:
2.3.20.1
cpe:2.3:a:apache:struts:2.3.20.1
Apache
»
Struts
»
Version:
2.3.20.3
cpe:2.3:a:apache:struts:2.3.20.3
Apache
»
Struts
»
Version:
2.3.24
cpe:2.3:a:apache:struts:2.3.24
Apache
»
Struts
»
Version:
2.3.24.1
cpe:2.3:a:apache:struts:2.3.24.1
Apache
»
Struts
»
Version:
2.3.24.3
cpe:2.3:a:apache:struts:2.3.24.3
Apache
»
Struts
»
Version:
2.3.28
cpe:2.3:a:apache:struts:2.3.28
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved