Red Hat Bugzilla – Bug 1331015
CVE-2016-3081 Struts2: RCE via method: prefix when Dynamic Method Invocation is enabled (S2-032)
Last modified: 2018-03-01 12:27:29 EST
It is possible to pass a malicious expression which can be used to execute arbitrary code on server side when Dynamic Method Invocation is enabled. External References: https://struts.apache.org/docs/s2-032.html
Statement: Not Vulnerable. This issue affects Struts 2 only; it does not affect the versions of struts as shipped with various Red Hat products.