CVE-2016-3081: Apache Struts Command Injection Vulnerability
High severity, CVSS 8.1. Actively exploited: in CISA KEV since 2026-10-08. EPSS: 96.1% chance of exploitation in the next 30 days.
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method: prefix, related to chained expressions.
Affected products
- Apache Struts: from 2.3.20, before 2.3.20.3 (fixed in 2.3.20.3); from 2.3.21, before 2.3.24.3 (fixed in 2.3.24.3); from 2.3.25, before 2.3.28.1 (fixed in 2.3.28.1)
- Huawei Agile Controller-Campus Firmware: version v100r002c00 only
- Huawei Anyoffice: version v200r005c00 only; version v200r006c00 only
- Huawei FIREHUNTER6000 Firmware: version v100r001c20 only
- Huawei Logcenter: version v100r001c10 only; version v100r001c20 only
- Huawei Oceanstor 18500 v3 Firmware: version v300r001 only; version v300r002 only; version v300r003c00 only; version v300r003c10 only
- Huawei Oceanstor 18500f Firmware: version v300r001 only; version v300r002 only; version v300r003c00 only; version v300r003c10 only
- Huawei Oceanstor 18800 v3 Firmware: version v300r001 only; version v300r002 only; version v300r003c00 only; version v300r003c10 only
- Huawei Oceanstor 18800f Firmware: version v300r001 only; version v300r002 only; version v300r003c00 only; version v300r003c10 only
- Huawei Oceanstor 5300 v3 Firmware: version v300r001 only; version v300r002 only; version v300r003c00 only; version v300r003c10 only
- Huawei Oceanstor 5500 v3 Firmware: version v300r001 only; version v300r002 only; version v300r003c00 only; version v300r003c10 only
- Huawei Oceanstor 5600 v3 Firmware: version v300r001 only; version v300r002 only; version v300r003c00 only; version v300r003c10 only
- Huawei Oceanstor 5800 v3 Firmware: version v300r001 only; version v300r002 only; version v300r003c00 only; version v300r003c10 only
- Huawei Oceanstor 6800 v3 Firmware: version v300r001 only; version v300r002 only; version v300r003c00 only; version v300r003c10 only
- Huawei Oceanstor 9000 Firmware: version v100r001c01 only; version v100r001c30 only; version v300r005c00 only
- Huawei Oceanstor n8500 Firmware: version v200r001c09spc505 only; version v200r001c91spc205 only; version v200r001c91spc900 only; version v200r001c91spc901 only
- Huawei Oceanstor Onebox Firmware: version v100r003c10 only
- Oracle Flexcube Private Banking: version 2.0.0.0 only; version 2.0.1 only; version 2.2.0 only; version 12.0.1 only; version 12.0.3 only; version 12.1.0 only
- Oracle Micros Retail Xbri Loss Prevention: version 10.0.1 only; version 10.5.0 only; version 10.6.0 only; version 10.7.0 only; version 10.8.0 only; version 10.8.1 only
- Oracle Siebel E-Billing: version 7.1 only
Published 2016-04-26. Last modified 2026-10-09.