Disclosure summary
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method: prefix, related to chained expressions.
CISA remediation guidance
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Source-reported weakness categories
CWE-77
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2016-3081
Open original source · Updated Oct 09, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
| Vendor | Product / association | Version / bounds |
|---|---|---|
| huawei | agile_controller-campus_firmware | v100r002c00 |
| huawei | anyoffice | v200r005c00 |
| huawei | anyoffice | v200r006c00 |
| huawei | logcenter | v100r001c10 |
| huawei | logcenter | v100r001c20 |
| huawei | firehunter6000_firmware | v100r001c20 |
| huawei | oceanstor_5300_v3_firmware | v300r001 |
| huawei | oceanstor_5300_v3_firmware | v300r002 |
| huawei | oceanstor_5300_v3_firmware | v300r003c00 |
| huawei | oceanstor_5300_v3_firmware | v300r003c10 |
| huawei | oceanstor_5500_v3_firmware | v300r001 |
| huawei | oceanstor_5500_v3_firmware | v300r002 |
| huawei | oceanstor_5500_v3_firmware | v300r003c00 |
| huawei | oceanstor_5500_v3_firmware | v300r003c10 |
| huawei | oceanstor_5600_v3_firmware | v300r001 |
| huawei | oceanstor_5600_v3_firmware | v300r002 |
| huawei | oceanstor_5600_v3_firmware | v300r003c00 |
| huawei | oceanstor_5600_v3_firmware | v300r003c10 |
| huawei | oceanstor_5800_v3_firmware | v300r001 |
| huawei | oceanstor_5800_v3_firmware | v300r002 |
| huawei | oceanstor_5800_v3_firmware | v300r003c00 |
| huawei | oceanstor_5800_v3_firmware | v300r003c10 |
| huawei | oceanstor_6800_v3_firmware | v300r001 |
| huawei | oceanstor_6800_v3_firmware | v300r002 |
| huawei | oceanstor_6800_v3_firmware | v300r003c00 |
| huawei | oceanstor_6800_v3_firmware | v300r003c10 |
| huawei | oceanstor_18500_v3_firmware | v300r001 |
| huawei | oceanstor_18500_v3_firmware | v300r002 |
| huawei | oceanstor_18500_v3_firmware | v300r003c00 |
| huawei | oceanstor_18500_v3_firmware | v300r003c10 |
| huawei | oceanstor_18500f_firmware | v300r001 |
| huawei | oceanstor_18500f_firmware | v300r002 |
| huawei | oceanstor_18500f_firmware | v300r003c00 |
| huawei | oceanstor_18500f_firmware | v300r003c10 |
| huawei | oceanstor_18800_v3_firmware | v300r001 |
| huawei | oceanstor_18800_v3_firmware | v300r002 |
| huawei | oceanstor_18800_v3_firmware | v300r003c00 |
| huawei | oceanstor_18800_v3_firmware | v300r003c10 |
| huawei | oceanstor_18800f_firmware | v300r001 |
| huawei | oceanstor_18800f_firmware | v300r002 |
| huawei | oceanstor_18800f_firmware | v300r003c00 |
| huawei | oceanstor_18800f_firmware | v300r003c10 |
| huawei | oceanstor_9000_firmware | v100r001c01 |
| huawei | oceanstor_9000_firmware | v100r001c30 |
| huawei | oceanstor_9000_firmware | v300r005c00 |
| huawei | oceanstor_n8500_firmware | v200r001c09spc505 |
| huawei | oceanstor_n8500_firmware | v200r001c91spc205 |
| huawei | oceanstor_n8500_firmware | v200r001c91spc900 |
| huawei | oceanstor_n8500_firmware | v200r001c91spc901 |
| huawei | oceanstor_onebox_firmware | v100r003c10 |
| apache | struts | * {"versionStartIncluding":"2.3.25","versionEndExcluding":"2.3.28.1"} |
| oracle | flexcube_private_banking | 2.0.0.0 |
| oracle | flexcube_private_banking | 2.0.1 |
| oracle | flexcube_private_banking | 2.2.0 |
| oracle | flexcube_private_banking | 12.0.1 |
| oracle | flexcube_private_banking | 12.0.3 |
| oracle | flexcube_private_banking | 12.1.0 |
| oracle | micros_retail_xbri_loss_prevention | 10.0.1 |
| oracle | micros_retail_xbri_loss_prevention | 10.5.0 |
| oracle | micros_retail_xbri_loss_prevention | 10.6.0 |
| oracle | micros_retail_xbri_loss_prevention | 10.7.0 |
| oracle | micros_retail_xbri_loss_prevention | 10.8.0 |
| oracle | micros_retail_xbri_loss_prevention | 10.8.1 |
| oracle | siebel_e-billing | 7.1 |
Original records & references
- NIST NVD record
- CVE Program record
- CISA KEV catalog entry
- struts.apache.org — Patch, Vendor Advisory
- www.exploit-db.com — Exploit, Third Party Advisory, VDB Entry
- struts.apache.org — Patch, Vendor Advisory
- www.exploit-db.com — Exploit, Third Party Advisory, VDB Entry
- www.cisa.gov — US Government Resource
PUBLISHED 2016-04-26T10:59:02-04:00
MODIFIED 2026-10-09T10:43:05-04:00
INGESTED 2026-10-10T20:50:18-04:00