CVE-2016-3093: Apache Struts
Medium severity, CVSS 5.3. EPSS: 8.4% chance of exploitation in the next 30 days.
Apache Struts 2.0.0 through 2.3.24.1 does not properly cache method references when used with OGNL before 3.0.12, which allows remote attackers to cause a denial of service (block access to a web site) via unspecified vectors.
Affected products
- Apache Struts: version 2.0.0 only; version 2.0.1 only; version 2.0.2 only; version 2.0.3 only; version 2.0.4 only; version 2.0.5 only; …
- Ognl Project Ognl: up to and including 3.0.11
Published 2016-06-07. Last modified 2026-06-17.