Exploited Vulnerabilities Daily
🌐 Nederlands

CVE-2016-3081: Apache Struts

CISA (English)

Apache Struts contains a command injection vulnerability that could allow remote attackers to execute arbitrary code via method:prefix when Dynamic Method Invocation is enabled.

Leverancier
Apache
Product
Struts
Kwetsbaarheid
Apache Struts Command Injection Vulnerability
Toegevoegd op
8 okt 2026
CISA-termijn (Amerikaanse federale instanties)
11 okt 2026
Bekend gebruik in ransomwarecampagnes
Onbekend
Zwakte (CWE)
CWE-77

Referenties

Deze site vat de CISA-catalogus alleen ter informatie samen. Het is geen beveiligingsadvies – volg de richtlijnen van uw leverancier en officiële adviezen.

Laatst bijgewerkt: · Catalogusversie 2026.10.08

Over deze pagina

Apache Struts bevat een commando-injectie kwetsbaarheid die kan toestaan dat externe aanvallers willekeurige code uit te voeren via methode:prefix wanneer Dynamic Method Invocation is ingeschakeld.