High severity7.5NVD Advisory· Published Jul 4, 2016· Updated Jun 17, 2026
CVE-2016-4433
CVE-2016-4433
Description
Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redirection attacks via a crafted request.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.struts.xwork:xwork-coreMaven | >= 2.3.20, < 2.3.29 | 2.3.29 |
Affected products
8cpe:2.3:a:apache:struts:2.3.20:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:apache:struts:2.3.20:*:*:*:*:*:*:*
- cpe:2.3:a:apache:struts:2.3.20.1:*:*:*:*:*:*:*
- cpe:2.3:a:apache:struts:2.3.20.3:*:*:*:*:*:*:*
- cpe:2.3:a:apache:struts:2.3.24:*:*:*:*:*:*:*
- cpe:2.3:a:apache:struts:2.3.24.1:*:*:*:*:*:*:*
- cpe:2.3:a:apache:struts:2.3.24.3:*:*:*:*:*:*:*
- cpe:2.3:a:apache:struts:2.3.28:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
12- jvn.jp/en/jp/JVN45093481/index.htmlnvdVendor AdvisoryWEB
- jvndb.jvn.jp/jvndb/JVNDB-2016-000112nvdVDB EntryVendor AdvisoryWEB
- www-01.ibm.com/support/docview.wssnvdThird Party AdvisoryWEB
- www-01.ibm.com/support/docview.wssnvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-wm8w-qp2f-728qghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2016-4433ghsaADVISORY
- struts.apache.org/docs/s2-039.htmlnvdVendor AdvisoryWEB
- www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.htmlnvdWEB
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingWEB
- github.com/apache/struts/commit/b28b78c062f0bf3c79793a25aab8c9b6c12bce6eghsaWEB
- web.archive.org/web/20210123144955/http://www.securityfocus.com/bid/91282ghsaWEB
- www.securityfocus.com/bid/91282nvd
News mentions
0No linked articles in our index yet.