CVE-2007-4556

N/A Unknown
Published: August 28, 2007 Modified: April 23, 2026
View on NVD

Description

Struts support in OpenSymphony XWork before 1.2.3, and 2.x before 2.0.4, as used in WebWork and Apache Struts, recursively evaluates all input as an Object-Graph Navigation Language (OGNL) expression when altSyntax is enabled, which allows remote attackers to cause a denial of service (infinite loop) or execute arbitrary code via form input beginning with a "%{" sequence and ending with a "}" character.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://forums.opensymphony.com/ann.jspa?annID=54
Source: cve@mitre.org
Patch Vendor Advisory
http://issues.apache.org/struts/browse/WW-2030
Source: cve@mitre.org
Third Party Advisory
http://jira.opensymphony.com/browse/XW-544
Source: cve@mitre.org
Vendor Advisory
http://osvdb.org/37072
Source: cve@mitre.org
Broken Link
http://secunia.com/advisories/26681
Source: cve@mitre.org
Third Party Advisory
http://secunia.com/advisories/26693
Source: cve@mitre.org
Third Party Advisory
http://secunia.com/advisories/26694
Source: cve@mitre.org
Third Party Advisory
http://struts.apache.org/2.x/docs/s2-001.html
Source: cve@mitre.org
Patch Third Party Advisory
http://www.securityfocus.com/bid/25524
Source: cve@mitre.org
Third Party Advisory VDB Entry
http://www.vupen.com/english/advisories/2007/3041
Source: cve@mitre.org
Third Party Advisory
http://www.vupen.com/english/advisories/2007/3042
Source: cve@mitre.org
Third Party Advisory
http://forums.opensymphony.com/ann.jspa?annID=54
Source: af854a3a-2127-422b-91ae-364da2661108
Patch Vendor Advisory
http://issues.apache.org/struts/browse/WW-2030
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://jira.opensymphony.com/browse/XW-544
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://osvdb.org/37072
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
http://secunia.com/advisories/26681
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://secunia.com/advisories/26693
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://secunia.com/advisories/26694
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://struts.apache.org/2.x/docs/s2-001.html
Source: af854a3a-2127-422b-91ae-364da2661108
Patch Third Party Advisory
http://wiki.opensymphony.com/display/WW/1.2.3+Press+Release
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://www.securityfocus.com/bid/25524
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory VDB Entry
http://www.vupen.com/english/advisories/2007/3041
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://www.vupen.com/english/advisories/2007/3042
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

28 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
25.7%
98th percentile
Exploitation Status
Not in CISA KEV

Affected Vendors

opensymphony