Netskope Threat Labs

SERVER-APACHE Apache Struts remote code execution attempt

IPS-NPA

5 SIDs: 39191, 41818, 41819, 41923, 49376

Detects an attempt to exploit CVE-2016-3087, CVE-2017-12611, CVE-2018-11776, and 3 others, a remote code execution flaw that can run code on the server in Apache Struts. The flaw saw mass exploitation against internet-facing Struts servers.