CVE-2016-3081

Élevée8.1 Publiée le 26 avr. 2016

Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method: prefix, related to chained expressions.

Alerte précoce : exploitation observée

  • Exploitation observée depuis le 23 juil. 2026
  • Pas encore dans le catalogue officiel de la CISA
  • Première attaque observée 3739 jours après la divulgation

Source : VulnCheck KEV · 23 juil. 2026

Score CVSS8.1 / 10CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Type de faiblesse (CWE)CWE-77, CWE-77
Éditeursoracle, apache

Produits concernés

ÉditeursProduitVersions
apachestruts2.0.0
oraclesiebel e-billing7.1

Articles liés

This product uses the NVD API but is not endorsed or certified by the NVD.

Base de données CVE