Command Injection in Apache Struts - CVE-2016-3081
Published: September 1, 2020
Vulnerability identifier: #VU46152
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-3081
CWE-ID: CWE-77
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insufficient filtration of user-supplied data, when Dynamic Method Invocation is enabled. A remote attacker can pass arbitrary commands via the method: prefix and execute them on the server.
Affected software
Apache Struts
IBM Sterling Order Management
Call Center for Commerce
IBM Sterling Order Management
Call Center for Commerce
How to mitigate CVE-2016-3081
Install updates from vendor's website.
Apache Struts - addressed in versions 2.3.20.3, 2.3.24.3, 2.3.28.1
IBM Sterling Order Management - update to 10.0.0.29
Call Center for Commerce - update to 10.0.12
IBM Sterling Order Management - update to 10.0.0.29
Call Center for Commerce - update to 10.0.12