CVE-2016-3081

Hoch8.1 Veröffentlicht am 26.04.2016

Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method: prefix, related to chained expressions.

Frühwarnung: Ausnutzung beobachtet

  • Ausnutzung beobachtet seit dem 23.07.2026
  • Noch nicht im offiziellen CISA-Katalog
  • Erster Angriff 3739 Tage nach der Veröffentlichung beobachtet

Quelle: VulnCheck KEV · 23.07.2026

CVSS-Score8.1 / 10CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Schwachstellentyp (CWE)CWE-77, CWE-77
Herstelleroracle, apache

Betroffene Produkte

HerstellerProduktVersionen
apachestruts2.0.0
oraclesiebel e-billing7.1

Verwandte Artikel

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE-Datenbank