CyberICT

CVE-2016-3081

Apache · Published April 26, 2016

CVSS v3.1

HIGH
Patch availableGet patch

Description

Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method: prefix, related to chained expressions.

Affected Products

  • Struts
  • Siebel E Billing

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H