Apache Struts is prone to multiple remote command-execution vulnerabilities. Successful exploits will allow remote attackers to execute arbitrary commands within the context of the affected application.
Apache Struts 2.0.0 prior to 2.3.15.1 are vulnerable.