RULE(RULE ID:316989)

Rule General Information
Release Date: 2017-03-22
Rule Name: WEB-SERVER Apache Struts Dynamic Method Invocation Remote Code Execution -1.x
Severity:
CVE ID:
Rule Protection Details
Description: A vulnerability has been reported in the Dynamic Method Invocation feature of Apache Struts 2.
Impact: Remote command execution
Affected OS: Windows, Linux, FreeBSD, Other Unix, Mac OS
Reference: CVE-2016-3082; CVE-2016-3081; CVE-2016-3087; CVE-2016-4438; CVE-2017-5638; Struts2 s2-032; Struts2 s2-033; Struts2 s2-037; Struts2 s2-045; CVE-2017-5638; Struts2 s2-046; msf
Solutions
Update vendor's patch.