{"id":"CVE-2016-3090","description":"The TextParseUtil.translateVariables method in Apache Struts 2.x before 2.3.20 allows remote attackers to execute arbitrary code via a crafted OGNL expression with ANTLR tooling.","cvssScore":8.8,"cvssVersion":"3.0","cvssVector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cvssMetrics":[{"version":"3.0","score":8.8,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","source":"nvd@nist.gov","sourceName":"NVD","type":"Primary"},{"version":"2.0","score":6.5,"vector":"AV:N/AC:L/Au:S/C:P/I:P/A:P","source":"nvd@nist.gov","sourceName":"NVD","type":"Primary"}],"cwes":["CWE-20"],"resolved":"NO-EXPLOIT-PUBLISHED","published":"2017-10-30","lastModified":"2026-06-17","affectedProducts":[{"vendor":"apache","product":"struts","version":"2.0.1"},{"vendor":"apache","product":"struts","version":"2.0.2"},{"vendor":"apache","product":"struts","version":"2.0.3"},{"vendor":"apache","product":"struts","version":"2.0.4"},{"vendor":"apache","product":"struts","version":"2.0.5"},{"vendor":"apache","product":"struts","version":"2.0.6"},{"vendor":"apache","product":"struts","version":"2.0.7"},{"vendor":"apache","product":"struts","version":"2.0.8"},{"vendor":"apache","product":"struts","version":"2.0.9"},{"vendor":"apache","product":"struts","version":"2.0.10"},{"vendor":"apache","product":"struts","version":"2.0.11"},{"vendor":"apache","product":"struts","version":"2.0.11.1"},{"vendor":"apache","product":"struts","version":"2.0.11.2"},{"vendor":"apache","product":"struts","version":"2.0.12"},{"vendor":"apache","product":"struts","version":"2.0.13"},{"vendor":"apache","product":"struts","version":"2.0.14"},{"vendor":"apache","product":"struts","version":"2.1.0"},{"vendor":"apache","product":"struts","version":"2.1.1"},{"vendor":"apache","product":"struts","version":"2.1.2"},{"vendor":"apache","product":"struts","version":"2.1.3"}],"totalAffectedProducts":1,"references":[{"url":"https://github.com/apache/struts","source":"osv","tags":["PACKAGE"]},{"url":"https://security.netapp.com/advisory/ntap-20180629-0005","source":"osv","tags":["WEB"]},{"url":"https://struts.apache.org/docs/s2-027.html","source":"osv","tags":["WEB"]},{"url":"https://web.archive.org/web/20210123095942/http://www.securityfocus.com/bid/85131","source":"osv","tags":["WEB"]},{"url":"https://web.archive.org/web/20211206100940/https://www.securitytracker.com/id/1035267","source":"osv","tags":["WEB"]},{"url":"http://www.securityfocus.com/bid/85131","source":"secalert@redhat.com","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://security.netapp.com/advisory/ntap-20180629-0005/","source":"secalert@redhat.com"},{"url":"https://www.securitytracker.com/id/1035267","source":"secalert@redhat.com","tags":["Third Party Advisory","VDB Entry"]}],"reasoning":{"decidingSource":"no-exploit-published","decidingReason":"This CVE is not listed in CISA KEV, CISA Vulnrichment records no active exploitation, and no reviewed exploit catalogue carries an entry for it. Nobody has published something a stranger can run, so it is not a candidate for a rule ahead of the ones where somebody has; an upstream fix path does exist, so the remediation half of the candidacy still holds. This is a statement about what has been published, not about whether the defect is reachable or serious.","verdicts":[{"rule":"rejected","stage":"identity","outcome":"no-match"},{"rule":"armr-patch-file","stage":"scope","outcome":"no-match"},{"rule":"armr-secure-rule-file","stage":"scope","outcome":"no-match"},{"rule":"manual-classification","stage":"scope","outcome":"no-match"},{"rule":"h2-history","stage":"scope","outcome":"no-match"},{"rule":"non-java-upstream","stage":"scope","outcome":"no-match"},{"rule":"oracle-component","stage":"scope","outcome":"no-match"},{"rule":"osv-maven","stage":"scope","outcome":"matched","status":"QUEUED-FOR-REVIEW","detail":"Maven packages: org.apache.struts:struts2-parent"},{"rule":"patch-hint","stage":"disposition","outcome":"no-match"},{"rule":"open-source-maven","stage":"disposition","outcome":"matched","status":"MITIGATION-CANDIDATE","detail":"Open-source Maven artifact indexed by OSV (Maven packages: org.apache.struts:struts2-parent). The source is public, which makes an ARMR patch rule a candidate; nothing here establishes that one can be written."},{"rule":"poc-derivable","stage":"disposition","outcome":"skipped"},{"rule":"no-exploit","stage":"disposition","outcome":"skipped"},{"rule":"secure-rule-match","stage":"disposition","outcome":"no-match"},{"rule":"below-action-threshold","stage":"disposition","outcome":"no-match","detail":"Severity is HIGH — only MEDIUM/LOW are deprioritized"},{"rule":"no-exploit-published","stage":"disposition","outcome":"matched","status":"NO-EXPLOIT-PUBLISHED","detail":"No working exploit has been published, and an upstream fix path does exist, so the remediation half of the candidacy still holds.","decisive":true}],"affectedProducts":[{"vendor":"apache","product":"struts","isKnown":true,"cpe":"cpe:2.3:a:apache:struts:2.0.1:*:*:*:*:*:*:*","source":"yaml"}],"affectedPackages":[{"name":"org.apache.struts:struts2-parent","introduced":"2.0.0","fixed":"2.3.20"}]},"assessment":{"record":{"state":"active"},"protection":{"level":"none"},"action":{"state":"unverified","type":"patch-rule"},"review":{"state":"automated","basis":"upstream-data"}},"signals":{"hasPOC":false,"pocCount":0},"kev":{"inKEV":false},"epss":{"available":true,"score":0.05709,"percentile":0.92602},"ssvc":{"available":false}}