CVE-2016-3087

Source
https://cve.org/CVERecord?id=CVE-2016-3087
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-3087.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2016-3087
Aliases
Published
2016-06-07T18:59:02.713Z
Modified
2026-07-08T05:48:11.139667538Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via vectors related to an ! (exclamation mark) operator to the REST Plugin.

Database specific
{
    "unresolved_ranges": [
        {
            "vendor_product": "apache:struts",
            "extracted_events": [
                {
                    "introduced": "2.3.20"
                },
                {
                    "last_affected": "2.3.20"
                }
            ],
            "cpes": [
                "cpe:2.3:a:apache:struts:2.3.20:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        }
    ]
}
References

Affected packages

Git / github.com/apache/struts

Affected ranges

Type
GIT
Repo
https://github.com/apache/struts
Events
Database specific
Show details
{
    "cpe": [
        "cpe:2.3:a:apache:struts:2.3.20:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:struts:2.3.20.1:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:struts:2.3.24:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:struts:2.3.24.1:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:struts:2.3.28:*:*:*:*:*:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "2.3.20"
        },
        {
            "last_affected": "2.3.20"
        },
        {
            "introduced": "2.3.20.1"
        },
        {
            "last_affected": "2.3.20.1"
        },
        {
            "introduced": "2.3.24"
        },
        {
            "last_affected": "2.3.24"
        },
        {
            "introduced": "2.3.24.1"
        },
        {
            "last_affected": "2.3.24.1"
        },
        {
            "introduced": "2.3.28"
        },
        {
            "last_affected": "2.3.28"
        }
    ],
    "source": "CPE_STRING"
}

Affected versions

2.*
2.3.20
2.3.20.1
2.3.24
2.3.24.1
2.3.28

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-3087.json"