  • S2-033

Who should read this

All Struts 2 developers and users

Impact of vulnerability

Possible Remote Code Execution

Maximum security rating



Disable Dynamic Method Invocation if possible. Alternatively upgrade to Struts, Struts or Struts

Affected Software

Struts 2.3.20 - Struts Struts 2.3.28 (except and


Alvaro Munoz alvaro dot munoz at hpe dot com

CVE Identifier



It is possible to pass a malicious expression which can be used to execute arbitrary code on server side when Dynamic Method Invocation is enabled when using the REST Plugin.