CVE-2016-3087
Publication date 7 June 2016
Last updated 25 August 2025
Ubuntu priority
Cvss 3 Severity Score
Description
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via vectors related to an ! (exclamation mark) operator to the REST Plugin.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| libstruts1.2-java | 16.04 LTS xenial | Not in release |
| 14.04 LTS trusty | Not in release | |
Notes
Severity score breakdown
CVSS version: CVSS v3.0
Base score
9.8 · Critical
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H