CVE-2016-3087: Input Validation
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via vectors related to an ! (exclamation mark) operator to the REST Plugin.
Other sources
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via vectors related to an ! (exclamation mark) operator to the REST Plugin.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-3087?
CVE-2016-3087 is considered a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2016-3087?
To fix CVE-2016-3087, upgrade Apache Struts to version 2.3.28.1 or later.
What versions of Apache Struts are affected by CVE-2016-3087?
CVE-2016-3087 affects Apache Struts versions 2.3.19 to 2.3.28.
Can CVE-2016-3087 be exploited without user interaction?
Yes, CVE-2016-3087 can be exploited by remote attackers without any user interaction.
What functionality in Apache Struts does CVE-2016-3087 target?
CVE-2016-3087 targets the Dynamic Method Invocation feature in Apache Struts.