Red Hat Bugzilla – Bug 1348238
CVE-2016-4438 struts: Possible RCE via REST plugin
Last modified: 2018-01-30 10:44:53 EST
It was found that it is possible to pass a malicious expression which can be used to execute arbitrary code on server side when using the REST Plugin. External References: https://struts.apache.org/docs/s2-037.html
thanks for the information, but I remove from the CC list.