CVE-2012-0391
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Apache Struts 2 Improper Input Validation Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling for mismatched data types of properties, which allows remote attackers to execute arbitrary Java code via a crafted parameter.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 75% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-94
מוצרים מושפעים
apache: struts
קישורים
- http://secunia.com/advisories/47393 Vendor Advisory
- http://struts.apache.org/2.x/docs/s2-008.html Vendor Advisory
- http://struts.apache.org/2.x/docs/version-notes-2311.html Vendor Advisory
- https://issues.apache.org/jira/browse/WW-3668 Vendor Advisory
- http://secunia.com/advisories/47393 Vendor Advisory
- http://struts.apache.org/2.x/docs/s2-008.html Vendor Advisory
- http://struts.apache.org/2.x/docs/version-notes-2311.html Vendor Advisory
- https://issues.apache.org/jira/browse/WW-3668 Vendor Advisory
- http://archives.neohapsis.com/archives/bugtraq/2012-01/0031.html Broken LinkExploit
- http://www.exploit-db.com/exploits/18329 Exploit