CVE-2016-3087 is a critical remote code execution vulnerability affecting Apache Struts versions 2.3.19 to 2.3.28 when Dynamic Method Invocation is enabled. Attackers can exploit this flaw via the REST Plugin using an exclamation mark operator. With a CVSS score of 9.8, this vulnerability allows unauthenticated remote attackers to achieve full compromise of confidentiality, integrity, and availability. While not on the CISA KEV catalog, exploit modules are publicly available in Metasploit and ExploitDB, and it has garnered significant community discussion, indicating a high potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.3.20CPE matchmatch criteria | cpe:2.3:a:apache:struts:2.3.20:*:*:*:*:*:*:* | ||
2.3.20.1CPE matchmatch criteria | cpe:2.3:a:apache:struts:2.3.20.1:*:*:*:*:*:*:* | ||
2.3.24CPE matchmatch criteria | cpe:2.3:a:apache:struts:2.3.24:*:*:*:*:*:*:* | ||
2.3.24.1CPE matchmatch criteria | cpe:2.3:a:apache:struts:2.3.24.1:*:*:*:*:*:*:* | ||
2.3.28CPE matchmatch criteria | cpe:2.3:a:apache:struts:2.3.28:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.