CVE-2016-4461 is a critical remote code execution vulnerability affecting Apache Struts versions prior to 2.3.29, stemming from an incomplete fix for a previous vulnerability. Attackers can exploit this by injecting a "%{}" sequence into a tag attribute, leading to forced double OGNL evaluation. This vulnerability carries a CVSS score of 8.8 (High), indicating a high potential for impact on confidentiality, integrity, and availability, with low attack complexity and no user interaction required. While no public exploit intelligence (Metasploit, Nuclei, ExploitDB) is currently available and it's not listed on the KEV catalog, its high FAUCET Risk Score of 73/100 suggests significant risk, despite minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0.0, < 2.3.29CPE matchmatch criteria | cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:oncommand_balance:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.