{
  "affected": [
    {
      "database_specific": {
        "unresolved_ranges": [
          {
            "events": [
              {
                "introduced": "0"
              },
              {
                "last_affected": "2.3.0"
              }
            ]
          },
          {
            "events": [
              {
                "introduced": "0"
              },
              {
                "last_affected": "2.4.0"
              }
            ]
          },
          {
            "events": [
              {
                "introduced": "0"
              },
              {
                "last_affected": "2.4.1"
              }
            ]
          },
          {
            "events": [
              {
                "introduced": "0"
              },
              {
                "last_affected": "2.5.0"
              }
            ]
          },
          {
            "events": [
              {
                "introduced": "0"
              },
              {
                "last_affected": "11.1.1.6"
              }
            ]
          },
          {
            "events": [
              {
                "introduced": "0"
              },
              {
                "last_affected": "1.0-beta1"
              }
            ]
          },
          {
            "events": [
              {
                "introduced": "0"
              },
              {
                "last_affected": "1.0-beta2"
              }
            ]
          },
          {
            "events": [
              {
                "introduced": "0"
              },
              {
                "last_affected": "1.0-beta3"
              }
            ]
          }
        ]
      },
      "ranges": [
        {
          "database_specific": {
            "versions": [
              {
                "introduced": "0"
              },
              {
                "last_affected": "1.0"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "1.0.1"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "1.0.2"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "1.1"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "1.1-b1"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "1.1-b2"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "1.1-b3"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "1.1-rc1"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "1.1-rc2"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "1.2.0"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "1.2.1"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "1.2.2"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "1.2.3"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "1.2.4"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "1.2.5"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "1.2.6"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "1.2.7"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "1.2.8"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "1.2.9"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "1.3.5"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "1.3.6"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "1.3.7"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "1.3.8"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "1.3.9"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "1.3.10"
              }
            ]
          },
          "events": [
            {
              "introduced": "0"
            },
            {
              "last_affected": "2f31da8d6315acf6f8e9bf44250345d1d9363f85"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "934faaaf4ddbe38a30a62ae8fc7e58d2dba90ea2"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "eb268ce7a2ebd58b1ca084ecca4682bcbc7cfcaf"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "e5fc9a70d4d586a5215cc74cacfc327490f06caf"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "373154027c65ff19595d954c07ab0e36e93e9c5b"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "18034701406a19516c921c77c5014ec78e821be8"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "d5e1453607684e48e24f51dd3febbf7ab0b5241c"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "fac67d636cbf723cb3d756d1138429350de4a2ee"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "6f05d0d49774a7dbab2903e5aee8a2a0d8f3cee8"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "8afe64135d328af0ed6b4f44c28c9596cc678b2c"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "413367e9ffa791a0225df784dce47e457febe56e"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "e5b1aa84f9057ed10b031fcc5c1b63329e943e8a"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "6d8a0611c2dc40080bf5bc436d09f7e264efe5d9"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "96831d6a8b8e4e84a4d3ba39836daef3a7d525c9"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "80320efbf7bc35d9e14c3caf4d262a2a198a7fe3"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "99c6c7e4fb50a0e5c5b616e7590273d3e47f0596"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "11c038edcbc39fc7dd33a9c4e153449dcd0e4ce6"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "4826731bfd429307a0e19bb602cdaca2b5d31b16"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "bdbf6120a767c1ce000390b2cf953eaf3dabd478"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "b518964f836cc7e92bfc8a182a9b33fa1d8f0d37"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "804ae5cf5ef8c7dac1d44ef7819ff35ad86a81a7"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "69785ef41e6e62e7c7229ce3a82e4acbe175f7a1"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "49dabf9f94b996d78577ef596ac324411c389f6b"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "910e9dac28714ff2fbeeb361f0e52c14d6145b1b"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "432ca08cb5f436f290ab3dcaa9267739cf8f6f89"
            },
            {
              "fixed": "eda3a79907ed8fcb0387a0496d0cb14332f250e8"
            }
          ],
          "repo": "https://github.com/kawasima/struts1-forever",
          "type": "GIT"
        }
      ]
    }
  ],
  "details": "ActionServlet.java in Apache Struts 1 1.x through 1.3.10 mishandles multithreaded access to an ActionForm instance, which allows remote attackers to execute arbitrary code or cause a denial of service (unexpected memory access) via a multipart request, a related issue to CVE-2015-0899.",
  "id": "CVE-2016-1181",
  "modified": "2026-04-01T23:09:07.656859426Z",
  "published": "2016-07-04T22:59:01.617Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://www.oracle.com/security-alerts/cpujan2020.html"
    },
    {
      "type": "WEB",
      "url": "https://www.oracle.com/security-alerts/cpujul2020.html"
    },
    {
      "type": "ADVISORY",
      "url": "http://jvndb.jvn.jp/jvndb/JVNDB-2016-000096"
    },
    {
      "type": "ADVISORY",
      "url": "http://www.securitytracker.com/id/1036056"
    },
    {
      "type": "ADVISORY",
      "url": "https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html"
    },
    {
      "type": "ADVISORY",
      "url": "http://www.securityfocus.com/bid/91068"
    },
    {
      "type": "ADVISORY",
      "url": "http://www.securityfocus.com/bid/91787"
    },
    {
      "type": "ADVISORY",
      "url": "http://jvn.jp/en/jp/JVN03188560/index.html"
    },
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2016-1181"
    },
    {
      "type": "ADVISORY",
      "url": "https://security.netapp.com/advisory/ntap-20180629-0006/"
    },
    {
      "type": "ADVISORY",
      "url": "https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1343538"
    },
    {
      "type": "FIX",
      "url": "http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html"
    },
    {
      "type": "FIX",
      "url": "http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html"
    },
    {
      "type": "FIX",
      "url": "https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html"
    },
    {
      "type": "FIX",
      "url": "http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html"
    },
    {
      "type": "FIX",
      "url": "http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html"
    },
    {
      "type": "FIX",
      "url": "http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html"
    },
    {
      "type": "FIX",
      "url": "http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html"
    },
    {
      "type": "FIX",
      "url": "http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html"
    },
    {
      "type": "FIX",
      "url": "https://github.com/kawasima/struts1-forever/commit/eda3a79907ed8fcb0387a0496d0cb14332f250e8"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ]
}