Red Hat Bugzilla – Bug 1341674
CVE-2016-3087 struts: Passing malicious expression can cause RCE when Dynamic Method Invocation is enabled and REST plugin is used
Last modified: 2018-03-01 12:26:54 EST
It was found that it is possible to pass a malicious expression which can be used to execute arbitrary code on server side when Dynamic Method Invocation is enabled when using the REST Plugin with ! operation. External Reference: https://struts.apache.org/docs/s2-033.html
Statement: Not Vulnerable. This issue affects Struts 2 only; it does not affect the versions of struts as shipped with various Red Hat products.