CVE-2012-0391
apache struts
Published 8 Jan 2012 · updated 16 Jun 2026 · Analyzed
9.8 Critical · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 21 Jan 2022, with a remediation deadline of 21 Jul 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling for mismatched data types of properties, which allows remote attackers to execute arbitrary Java code via a crafted parameter.
References
- archives.neohapsis.com/archives/bugtraq/2012-01/0031.html · Broken Link, Exploit
- secunia.com/advisories/47393 · Vendor Advisory
- struts.apache.org/2.x/docs/s2-008.html · Vendor Advisory
- struts.apache.org/2.x/docs/version-notes-2311.html · Vendor Advisory
- www.exploit-db.com/exploits/18329 · Exploit
- issues.apache.org/jira/browse/WW-3668 · Vendor Advisory
- www.sec-consult.com/files/20120104-0_Apache_Struts2_Multiple_Critical_Vulnerabilities.txt · Broken Link, Exploit
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2012-0391 · US Government Resource