CVE-2016-3087

Source
https://cve.org/CVERecord?id=CVE-2016-3087
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-3087.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2016-3087
Aliases
Published
2016-06-07T18:59:02.713Z
Modified
2026-04-10T03:49:21.417141Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via vectors related to an ! (exclamation mark) operator to the REST Plugin.

References

Affected packages

Git / github.com/apache/struts

Affected ranges

Type
GIT
Repo
https://github.com/apache/struts
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.3.20"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.3.20.1"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.3.24"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.3.24.1"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.3.28"
        }
    ]
}

Affected versions

Other
STRUTS_2_3_20
STRUTS_2_3_20_1
STRUTS_2_3_24
STRUTS_2_3_24_1
STRUTS_2_3_25
STRUTS_2_3_26
STRUTS_2_3_27
STRUTS_2_3_28

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-3087.json"