CVE-2016-3081
KEV
🔴 Łataj teraz
Wykonanie kodu zdalnie w Apache Struts przez Dynamic Method Invocation umożliwia atakującym.
CVSS
8.1
EPSS
93.3%
Exploit
weaponized
Vendor
apache
Opis źródłowy (NVD)
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method: prefix, related to chained expressions.
exploit
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 8.1 |
| CISA KEV (aktywnie wykorzystywane) | Tak |
| FIRST EPSS (prawdopodobieństwo exploita) | 93.3% |
| Opublikowano (NVD) | 2016-04-26 14:59:02 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-08 18:17:11 UTC |
Referencje
- http://packetstormsecurity.com/files/136856/Apache-Struts-2.3.28-Dynamic-Method-Invocation-Remote-Code-Execution.html ([email protected]) [Exploit, Third Party Advisory]
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20160527-01-struts2-en ([email protected])
- http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html ([email protected]) [Patch, Third Party Advisory]
- http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html ([email protected]) [Vendor Advisory]
- http://www.rapid7.com/db/modules/exploit/linux/http/struts_dmi_exec ([email protected]) [Third Party Advisory]
- http://www.rapid7.com/db/modules/exploit/multi/http/struts_dmi_exec ([email protected])
- http://www.securityfocus.com/bid/87327 ([email protected])
- http://www.securityfocus.com/bid/91787 ([email protected]) [Third Party Advisory, VDB Entry]
- http://www.securitytracker.com/id/1035665 ([email protected]) [Third Party Advisory, VDB Entry]
- https://struts.apache.org/docs/s2-032.html ([email protected]) [Patch, Vendor Advisory]
- https://www.exploit-db.com/exploits/39756/ ([email protected])
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-3081 (134c704f-9b21-4f2e-91b3-4a467353bcc0)