HIGHCVSS 8.1Vulnerability
CVE-2016-3081
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method: prefix, related to chained expressions.
Properties
- severity
- HIGH
- product
- Struts
- vulnerabilityName
- Apache Struts Command Injection Vulnerability
- cvss_score
- 8.1
- cvss_severity
- HIGH
- dueDate
- 2026-10-11
- retrieved_at
- 2026-10-08T19:23:26+00:00
- requiredAction
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discon
- dateAdded
- 2026-10-08
- last_source
- NVD
- score
- 8.1
- cve_id
- CVE-2016-3081
- cvss_vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- signal_observed_at
- 2026-10-08T19:23:25+00:00
- vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- vendorProject
- Apache
- published_at
- 2016-04-26T14:59:02.207
- last_modified
- 2026-10-08T18:17:11.817
Related Entities (50)
DESCRIBED_BY (1)
→[Source]NVD
HAS_WEAKNESS (1)
→[Weakness]Improper Neutralization of Special Elements used in a Command ('Command Injection')
KNOWN_EXPLOITED (1)
→[Source]CISA KEV
AFFECTS_PRODUCT (47)
→[Product]
→[Product]
→[Product]
→[Product]
→[Product]
→[Product]
→[Product]
→[Product]
→[Product]
→[Product]
→[Product]
→[Product]
→[Product]
→[Product]
→[Product]
→[Product]
→[Product]
→[Product]
→[Product]
→[Product]
Explore deeper with Ninja Signal's threat intelligence graph