CVE-2012-0391

apache struts

Published 8 Jan 2012 · updated 16 Jun 2026 · Analyzed

9.8 Critical · CVSS 3.1, NVD

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 21 Jan 2022, with a remediation deadline of 21 Jul 2022 for US federal agencies.

Required action: Apply updates per vendor instructions.

Description

The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling for mismatched data types of properties, which allows remote attackers to execute arbitrary Java code via a crafted parameter.

References