CVE-2016-3081

High8.1 Published on Apr 26, 2016

Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method: prefix, related to chained expressions.

Early warning: exploitation observed

  • Exploitation observed since Jul 23, 2026
  • Not yet in the official CISA catalogue
  • First attack observed 3739 days after disclosure

Source: VulnCheck KEV · Jul 23, 2026

CVSS score8.1 / 10CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness type (CWE)CWE-77, CWE-77
Vendorsoracle, apache

Affected products

VendorsProductVersions
apachestruts2.0.0
oraclesiebel e-billing7.1

Related articles

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE database