Vulnerability record · CVE-2016-3081 · published 26 April 2016
CVE-2016-3081: Apache Struts 2 DMI method: prefix remote code execution
Apache · Struts
Apache Struts 2.3.19 through 2.3.28 permits remote code execution when Dynamic Method Invocation is enabled, because the method: prefix can be abused through chained expressions. This is a command injection flaw (CWE-77) in a widely deployed web framework, so any exposed Struts application with DMI enabled is at risk.
Description
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method: prefix, related to chained expressions.
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote code execution with mature public exploits and an EPSS score above the 99th percentile makes this an urgent patch target despite the AC:H vector.
What it is
Apache Struts 2.3.19 through 2.3.28 permits remote code execution when Dynamic Method Invocation is enabled, because the method: prefix can be abused through chained expressions. This is a command injection flaw (CWE-77) in a widely deployed web framework, so any exposed Struts application with DMI enabled is at risk.
Impact
An unauthenticated remote attacker can execute arbitrary code in the context of the application server, leading to full compromise of the host and any data it can reach.
Attack surface
Reached over the network via HTTP requests to a Struts 2 application; the CVSS vector shows no privileges and no user interaction required, but exploitation depends on Dynamic Method Invocation being enabled.
Exploitation
Not listed in CISA KEV, but EPSS is 0.93352 (99.8th percentile) and public exploit references exist, including Packet Storm, Exploit-DB and Rapid7 Metasploit modules, indicating mature public exploitation.
What to do
- Upgrade Apache Struts to a fixed release (2.3.28.1 or later) as the primary action.
- Disable Dynamic Method Invocation (struts.enable.DynamicMethodInvocation=false) where it is not strictly required.
- Apply the referenced Oracle CPU patches for bundled Struts components such as Siebel E-Billing.
- Restrict network access to Struts application endpoints and place them behind a WAF with rules for method: prefix abuse.
- Audit for other Struts 2 instances running the affected 2.3.x versions.
Detection
- Search HTTP request logs for the literal string 'method:' in parameters and request bodies.
- Monitor for OGNL or chained expression payloads in Struts action parameters.
- Alert on unexpected child processes spawned by the Java application server (e.g. shell, curl, wget).
- Use the Rapid7 Metasploit module signatures and known Exploit-DB payload patterns for IDS/IPS coverage.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-3081 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-3081), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.