CVE Details

CVE-2016-3081 Apache Struts Command Injection Vulnerability
Published: 2026-10-08 CVSS: 8.1 HIGH Product: Apache Struts Due Date: 2026-10-11

Apache Struts contains a command injection vulnerability that could allow remote attackers to execute arbitrary code via method:prefix when Dynamic Method Invocation is enabled.

GitHub PoC

Warning: GitHub PoC repositories are unverified. Some may be fake or contain malware. Use caution and review code before running anything.
  • zhzyker/exphub • ⭐ 4291 • 2020-04-01 • Conf: 93.0%
  • Exphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本,最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-10204、CVE-2020-10199、CVE-2020-1938、CVE-2020-2551、CVE-2020-2555、CVE-2020-2883、CVE-2019-17558、CVE-2019-6340
  • zhzyker/vulmap • ⭐ 3518 • 2020-10-09 • Conf: 90.0%
  • Vulmap 是一款 web 漏洞扫描和验证工具, 可对 webapps 进行漏洞扫描, 并且具备漏洞验证功能

FIRST EPSS

EPSS estimates the probability of exploitation in the next 30 days. Higher values indicate higher likelihood of real-world exploitation.

Timeline

CVE Stalker KEV MITRE GitHub FIRST (EPSS)

MITRE

CVSS

  • Score: 8.1
  • Severity: HIGH
  • Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

SSVC

  • Exploitation: active
  • Automatable: no
  • Technical Impact: total

References

Show Raw Data
Key Remaining Key Value
containers > cna > affected > 0 > product n/a
containers > cna > affected > 0 > vendor n/a
containers > cna > affected > 0 > versions > 0 > status affected
containers > cna > affected > 0 > versions > 0 > version n/a
containers > cna > datePublic 2016-04-19T00:00:00.000Z
containers > cna > descriptions > 0 > lang en
containers > cna > descriptions > 0 > value Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method: prefix, related to chained expressions.
containers > cna > problemTypes > 0 > descriptions > 0 > description n/a
containers > cna > problemTypes > 0 > descriptions > 0 > lang en
containers > cna > problemTypes > 0 > descriptions > 0 > type text
containers > cna > providerMetadata > dateUpdated 2019-08-12T20:45:53.000Z
containers > cna > providerMetadata > orgId 53f830b8-0a3f-465b-8143-3b8a9948e749
containers > cna > providerMetadata > shortName redhat
containers > cna > references > 0 > name 1035665
containers > cna > references > 0 > tags > 0 vdb-entry
containers > cna > references > 0 > tags > 1 x_refsource_SECTRACK
containers > cna > references > 0 > url http://www.securitytracker.com/id/1035665
containers > cna > references > 1 > tags > 0 x_refsource_CONFIRM
containers > cna > references > 1 > url https://struts.apache.org/docs/s2-032.html
containers > cna > references > 2 > tags > 0 x_refsource_CONFIRM
containers > cna > references > 2 > url http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20160527-01-struts2-en
containers > cna > references > 3 > tags > 0 x_refsource_CONFIRM
containers > cna > references > 3 > url http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html
containers > cna > references > 4 > tags > 0 x_refsource_CONFIRM
containers > cna > references > 4 > url http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html
containers > cna > references > 5 > tags > 0 x_refsource_MISC
containers > cna > references > 5 > url http://www.rapid7.com/db/modules/exploit/linux/http/struts_dmi_exec
containers > cna > references > 6 > name 39756
containers > cna > references > 6 > tags > 0 exploit
containers > cna > references > 6 > tags > 1 x_refsource_EXPLOIT-DB
containers > cna > references > 6 > url https://www.exploit-db.com/exploits/39756/
containers > cna > references > 7 > name 91787
containers > cna > references > 7 > tags > 0 vdb-entry
containers > cna > references > 7 > tags > 1 x_refsource_BID
containers > cna > references > 7 > url http://www.securityfocus.com/bid/91787
containers > cna > references > 8 > tags > 0 x_refsource_MISC
containers > cna > references > 8 > url http://packetstormsecurity.com/files/136856/Apache-Struts-2.3.28-Dynamic-Method-Invocation-Remote-Code-Execution.html
containers > cna > references > 9 > name 87327
containers > cna > references > 9 > tags > 0 vdb-entry
containers > cna > references > 9 > tags > 1 x_refsource_BID
containers > cna > references > 9 > url http://www.securityfocus.com/bid/87327
containers > cna > references > 10 > tags > 0 x_refsource_MISC
containers > cna > references > 10 > url http://www.rapid7.com/db/modules/exploit/multi/http/struts_dmi_exec
containers > cna > x_legacyV4Record > CVE_data_meta > ASSIGNER [email protected]
containers > cna > x_legacyV4Record > CVE_data_meta > ID CVE-2016-3081
containers > cna > x_legacyV4Record > CVE_data_meta > STATE PUBLIC
containers > cna > x_legacyV4Record > affects > vendor > vendor_data > 0 > product > product_data > 0 > product_name n/a
containers > cna > x_legacyV4Record > affects > vendor > vendor_data > 0 > product > product_data > 0 > version > version_data > 0 > version_value n/a
containers > cna > x_legacyV4Record > affects > vendor > vendor_data > 0 > vendor_name n/a
containers > cna > x_legacyV4Record > data_format MITRE
containers > cna > x_legacyV4Record > data_type CVE
containers > cna > x_legacyV4Record > data_version 4.0
containers > cna > x_legacyV4Record > description > description_data > 0 > lang eng
containers > cna > x_legacyV4Record > description > description_data > 0 > value Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method: prefix, related to chained expressions.
containers > cna > x_legacyV4Record > problemtype > problemtype_data > 0 > description > 0 > lang eng
containers > cna > x_legacyV4Record > problemtype > problemtype_data > 0 > description > 0 > value n/a
containers > cna > x_legacyV4Record > references > reference_data > 0 > name 1035665
containers > cna > x_legacyV4Record > references > reference_data > 0 > refsource SECTRACK
containers > cna > x_legacyV4Record > references > reference_data > 0 > url http://www.securitytracker.com/id/1035665
containers > cna > x_legacyV4Record > references > reference_data > 1 > name https://struts.apache.org/docs/s2-032.html
containers > cna > x_legacyV4Record > references > reference_data > 1 > refsource CONFIRM
containers > cna > x_legacyV4Record > references > reference_data > 1 > url https://struts.apache.org/docs/s2-032.html
containers > cna > x_legacyV4Record > references > reference_data > 2 > name http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20160527-01-struts2-en
containers > cna > x_legacyV4Record > references > reference_data > 2 > refsource CONFIRM
containers > cna > x_legacyV4Record > references > reference_data > 2 > url http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20160527-01-struts2-en
containers > cna > x_legacyV4Record > references > reference_data > 3 > name http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html
containers > cna > x_legacyV4Record > references > reference_data > 3 > refsource CONFIRM
containers > cna > x_legacyV4Record > references > reference_data > 3 > url http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html
containers > cna > x_legacyV4Record > references > reference_data > 4 > name http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html
containers > cna > x_legacyV4Record > references > reference_data > 4 > refsource CONFIRM
containers > cna > x_legacyV4Record > references > reference_data > 4 > url http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html
containers > cna > x_legacyV4Record > references > reference_data > 5 > name http://www.rapid7.com/db/modules/exploit/linux/http/struts_dmi_exec
containers > cna > x_legacyV4Record > references > reference_data > 5 > refsource MISC
containers > cna > x_legacyV4Record > references > reference_data > 5 > url http://www.rapid7.com/db/modules/exploit/linux/http/struts_dmi_exec
containers > cna > x_legacyV4Record > references > reference_data > 6 > name 39756
containers > cna > x_legacyV4Record > references > reference_data > 6 > refsource EXPLOIT-DB
containers > cna > x_legacyV4Record > references > reference_data > 6 > url https://www.exploit-db.com/exploits/39756/
containers > cna > x_legacyV4Record > references > reference_data > 7 > name 91787
containers > cna > x_legacyV4Record > references > reference_data > 7 > refsource BID
containers > cna > x_legacyV4Record > references > reference_data > 7 > url http://www.securityfocus.com/bid/91787
containers > cna > x_legacyV4Record > references > reference_data > 8 > name http://packetstormsecurity.com/files/136856/Apache-Struts-2.3.28-Dynamic-Method-Invocation-Remote-Code-Execution.html
containers > cna > x_legacyV4Record > references > reference_data > 8 > refsource MISC
containers > cna > x_legacyV4Record > references > reference_data > 8 > url http://packetstormsecurity.com/files/136856/Apache-Struts-2.3.28-Dynamic-Method-Invocation-Remote-Code-Execution.html
containers > cna > x_legacyV4Record > references > reference_data > 9 > name 87327
containers > cna > x_legacyV4Record > references > reference_data > 9 > refsource BID
containers > cna > x_legacyV4Record > references > reference_data > 9 > url http://www.securityfocus.com/bid/87327
containers > cna > x_legacyV4Record > references > reference_data > 10 > name http://www.rapid7.com/db/modules/exploit/multi/http/struts_dmi_exec
containers > cna > x_legacyV4Record > references > reference_data > 10 > refsource MISC
containers > cna > x_legacyV4Record > references > reference_data > 10 > url http://www.rapid7.com/db/modules/exploit/multi/http/struts_dmi_exec
containers > adp > 0 > providerMetadata > orgId af854a3a-2127-422b-91ae-364da2661108
containers > adp > 0 > providerMetadata > shortName CVE
containers > adp > 0 > providerMetadata > dateUpdated 2024-08-05T23:40:15.633Z
containers > adp > 0 > title CVE Program Container
containers > adp > 0 > references > 0 > name 1035665
containers > adp > 0 > references > 0 > tags > 0 vdb-entry
containers > adp > 0 > references > 0 > tags > 1 x_refsource_SECTRACK
containers > adp > 0 > references > 0 > tags > 2 x_transferred
containers > adp > 0 > references > 0 > url http://www.securitytracker.com/id/1035665
containers > adp > 0 > references > 1 > tags > 0 x_refsource_CONFIRM
containers > adp > 0 > references > 1 > tags > 1 x_transferred
containers > adp > 0 > references > 1 > url https://struts.apache.org/docs/s2-032.html
containers > adp > 0 > references > 2 > tags > 0 x_refsource_CONFIRM
containers > adp > 0 > references > 2 > tags > 1 x_transferred
containers > adp > 0 > references > 2 > url http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20160527-01-struts2-en
containers > adp > 0 > references > 3 > tags > 0 x_refsource_CONFIRM
containers > adp > 0 > references > 3 > tags > 1 x_transferred
containers > adp > 0 > references > 3 > url http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html
containers > adp > 0 > references > 4 > tags > 0 x_refsource_CONFIRM
containers > adp > 0 > references > 4 > tags > 1 x_transferred
containers > adp > 0 > references > 4 > url http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html
containers > adp > 0 > references > 5 > tags > 0 x_refsource_MISC
containers > adp > 0 > references > 5 > tags > 1 x_transferred
containers > adp > 0 > references > 5 > url http://www.rapid7.com/db/modules/exploit/linux/http/struts_dmi_exec
containers > adp > 0 > references > 6 > name 39756
containers > adp > 0 > references > 6 > tags > 0 exploit
containers > adp > 0 > references > 6 > tags > 1 x_refsource_EXPLOIT-DB
containers > adp > 0 > references > 6 > tags > 2 x_transferred
containers > adp > 0 > references > 6 > url https://www.exploit-db.com/exploits/39756/
containers > adp > 0 > references > 7 > name 91787
containers > adp > 0 > references > 7 > tags > 0 vdb-entry
containers > adp > 0 > references > 7 > tags > 1 x_refsource_BID
containers > adp > 0 > references > 7 > tags > 2 x_transferred
containers > adp > 0 > references > 7 > url http://www.securityfocus.com/bid/91787
containers > adp > 0 > references > 8 > tags > 0 x_refsource_MISC
containers > adp > 0 > references > 8 > tags > 1 x_transferred
containers > adp > 0 > references > 8 > url http://packetstormsecurity.com/files/136856/Apache-Struts-2.3.28-Dynamic-Method-Invocation-Remote-Code-Execution.html
containers > adp > 0 > references > 9 > name 87327
containers > adp > 0 > references > 9 > tags > 0 vdb-entry
containers > adp > 0 > references > 9 > tags > 1 x_refsource_BID
containers > adp > 0 > references > 9 > tags > 2 x_transferred
containers > adp > 0 > references > 9 > url http://www.securityfocus.com/bid/87327
containers > adp > 0 > references > 10 > tags > 0 x_refsource_MISC
containers > adp > 0 > references > 10 > tags > 1 x_transferred
containers > adp > 0 > references > 10 > url http://www.rapid7.com/db/modules/exploit/multi/http/struts_dmi_exec
containers > adp > 1 > metrics > 0 > cvssV3_1 > scope UNCHANGED
containers > adp > 1 > metrics > 0 > cvssV3_1 > version 3.1
containers > adp > 1 > metrics > 0 > cvssV3_1 > baseScore 8.1
containers > adp > 1 > metrics > 0 > cvssV3_1 > attackVector NETWORK
containers > adp > 1 > metrics > 0 > cvssV3_1 > baseSeverity HIGH
containers > adp > 1 > metrics > 0 > cvssV3_1 > vectorString CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
containers > adp > 1 > metrics > 0 > cvssV3_1 > integrityImpact HIGH
containers > adp > 1 > metrics > 0 > cvssV3_1 > userInteraction NONE
containers > adp > 1 > metrics > 0 > cvssV3_1 > attackComplexity HIGH
containers > adp > 1 > metrics > 0 > cvssV3_1 > availabilityImpact HIGH
containers > adp > 1 > metrics > 0 > cvssV3_1 > privilegesRequired NONE
containers > adp > 1 > metrics > 0 > cvssV3_1 > confidentialityImpact HIGH
containers > adp > 1 > metrics > 1 > other > type ssvc
containers > adp > 1 > metrics > 1 > other > content > id CVE-2016-3081
containers > adp > 1 > metrics > 1 > other > content > role CISA Coordinator
containers > adp > 1 > metrics > 1 > other > content > options > 0 > Exploitation active
containers > adp > 1 > metrics > 1 > other > content > options > 1 > Automatable no
containers > adp > 1 > metrics > 1 > other > content > options > 2 > Technical Impact total
containers > adp > 1 > metrics > 1 > other > content > version 2.0.3
containers > adp > 1 > metrics > 1 > other > content > timestamp 2026-10-08T17:40:07.972437Z
containers > adp > 1 > references > 0 > url https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-3081
containers > adp > 1 > references > 0 > tags > 0 government-resource
containers > adp > 1 > problemTypes > 0 > descriptions > 0 > lang en
containers > adp > 1 > problemTypes > 0 > descriptions > 0 > type CWE
containers > adp > 1 > problemTypes > 0 > descriptions > 0 > cweId CWE-77
containers > adp > 1 > problemTypes > 0 > descriptions > 0 > description CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')
containers > adp > 1 > title CISA ADP Vulnrichment
containers > adp > 1 > providerMetadata > orgId 134c704f-9b21-4f2e-91b3-4a467353bcc0
containers > adp > 1 > providerMetadata > shortName CISA-ADP
containers > adp > 1 > providerMetadata > dateUpdated 2026-10-08T17:41:47.155Z
cveMetadata > assignerOrgId 53f830b8-0a3f-465b-8143-3b8a9948e749
cveMetadata > assignerShortName redhat
cveMetadata > cveId CVE-2016-3081
cveMetadata > datePublished 2016-04-26T14:00:00.000Z
cveMetadata > dateReserved 2016-03-10T00:00:00.000Z
cveMetadata > dateUpdated 2026-10-08T17:41:47.155Z
cveMetadata > state PUBLISHED
dataType CVE_RECORD
dataVersion 5.2