Junglewise Threat Intelligence

CVE-2012-0391: Apache Struts Remote Java Code Execution

CVE-2012-0391 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-05-04

Technologies: Apache Struts 2. Vendors: Maven, Apache.

Executive brief

The `ExceptionDelegator` component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling for mismatched data types of properties, which allows remote attackers to execute arbitrary Java code via a crafted parameter.

Affected products

  • Maven org.apache.struts.xwork:xwork-core
  • Maven org.apache.struts:struts2-core
  • Apache Struts 2

References

Related threats