High severity8.8NVD Advisory· Published Apr 12, 2016· Updated Jun 17, 2026
CVE-2016-0785
CVE-2016-0785
Description
Apache Struts 2.x before 2.3.28 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribute, aka forced double OGNL evaluation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.struts:struts2-coreMaven | >= 2.0.0, < 2.3.20.3 | 2.3.20.3 |
org.apache.struts:struts2-coreMaven | >= 2.3.24, < 2.3.24.3 | 2.3.24.3 |
Affected products
2Patches
Vulnerability mechanics
References
8- struts.apache.org/docs/s2-029.htmlnvdVendor AdvisoryWEB
- www.securityfocus.com/bid/85066nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1035271nvdThird Party AdvisoryVDB Entry
- github.com/advisories/GHSA-876p-4wgc-75rxghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2016-0785ghsaADVISORY
- github.com/apache/struts/commit/15857a69e7baf3675804495a5954cd0756ac8364ghsaWEB
- web.archive.org/web/20210123095715/http://www.securityfocus.com/bid/85066ghsaWEB
- web.archive.org/web/20220118185853/http://www.securitytracker.com/id/1035271ghsaWEB
News mentions
0No linked articles in our index yet.