'; } else{ echo ''; } echo '
|
|||
Release Date:2025/9/15
Rule Name:CVE-2016-3087: WEB Apache Struts 2 '_memberAccess' Evasion(and CVE-2016-4438)
Severity:critical
CVE ID:CVE-2016-3087 CVE-2016-4438
Descripiton:
|
Apache Struts 2 is an open-source Web application framework for developing Java EE Web applications. It uses and extends the Java Servlet API to encourage developers to adopt a model-view-controller (MVC) architecture. Apache struts 2.3.20.x before 2.3.20.3, 2.3.24.x before 2.3.24.3, and 2.3.28.x before 2.3.28.1, when Dynamic Method Invovation is enabled, allow remote attackers to execute arbitrary code via vectors related to an !(exclamation mark) operator to the REST plugin. This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021.
Other reference:None
Solution:
|
Update vendor patches.