Back to search
CVE-2016-4465
Published: Jul 4, 2016
Modified: Aug 6, 2024
PUBLISHED
Description
The URLValidator class in Apache Struts 2 2.3.20 through 2.3.28.1 and 2.5.x before 2.5.1 allows remote attackers to cause a denial of service via a null value for a URL field.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://bugzilla.redhat.com/show_bug.cgi?id=1348253
x_refsource_CONFIRM
91278
vdb-entry
x_refsource_BID
https://struts.apache.org/docs/s2-041.html
x_refsource_CONFIRM
http://www-01.ibm.com/support/docview.wss?uid=swg21987854
x_refsource_CONFIRM
JVN#12352818
third-party-advisory
x_refsource_JVN
http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html
x_refsource_CONFIRM
JVNDB-2016-000114
third-party-advisory
x_refsource_JVNDB
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now