RULE(RULE ID:324337)

Rule General Information
Release Date: 2020-02-19
Rule Name: Apache Struts 2 method Prefix Arbitrary Remote Command Execution Vulnerability (CVE-2016-3081)
Severity:
CVE ID:
Rule Protection Details
Description: Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method: prefix, related to chained expressions.
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference: SecurityFocusBID:87327
SecurityTrackerID:1035665
ExploitDB:39756
http://packetstormsecurity.com/files/136856/Apache-Struts-2.3.28-Dynamic-Method-Invocation-Remote-Code-Execution.html
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://struts.apache.org/docs/s2-032.html