cbcvebase.
CVE-2016-0785
published 2016-04-12

CVE-2016-0785: Apache Struts 2.x before 2.3.28 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribute, aka forced double OGNL evaluation.

PriorityP357high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
8.81%
94.6th percentile
Apache Struts 2.x before 2.3.28 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribute, aka forced double OGNL evaluation.

Affected

3 ranges
VendorProductVersion rangeFixed in
apachestruts>= 2.0.0 < 2.3.292.3.29
apachestruts>= 2.0.0 < 2.3.20.32.3.20.3
apachestruts2.3.21 – 2.3.24.1

Detection & IOCsextracted from sources · hover to see the quote

  • Detect forced double OGNL evaluation by looking for '%{}' sequences in HTTP request tag attribute values targeting Apache Struts 2.x endpoints
  • Monitor for double evaluation of attributes' values assigned to certain tags in Apache Struts — input containing OGNL expressions that get evaluated a second time during tag rendering is the attack pattern
  • Reference the vendor advisory S2-029 for payload patterns and affected tag list associated with this vulnerability
  • ·The fix for CVE-2016-0785 (patched in 2.3.28) was incomplete; CVE-2016-4461 covers the same attack vector and requires upgrading to Apache Struts 2.3.29 or later for full remediation
  • ·struts2-core JARs were bundled in source packages of Red Hat Fuse Service Works 6.0.0 and Single Sign On 7.3.0+ via a Google Guice import; customers who built artifacts from those source packages may have introduced vulnerable JARs into their environments

CVSS provenance

nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
ghsa8.8HIGH
osv8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.