CVE-2016-3081

Alta8.1 Pubblicata il 26 apr 2016

Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method: prefix, related to chained expressions.

Preallarme: sfruttamento osservato

  • Sfruttamento osservato dal 23 lug 2026
  • Non ancora nel catalogo ufficiale CISA
  • Primo attacco osservato 3739 giorni dopo la divulgazione

Fonte: VulnCheck KEV · 23 lug 2026

Punteggio CVSS8.1 / 10CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Tipo di debolezza (CWE)CWE-77, CWE-77
Vendororacle, apache

Prodotti coinvolti

VendorProdottoVersioni
apachestruts2.0.0
oraclesiebel e-billing7.1

Articoli correlati

This product uses the NVD API but is not endorsed or certified by the NVD.

Database CVE