← לוח פגיעויות

CVE-2013-2251

קריטית 9.8 מנוצלת בשטח (KEV)

ניצול פעיל מאומת — קטלוג CISA KEV

שם
Apache Struts Improper Input Validation Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply updates per vendor instructions.

תיאור (מקור, אנגלית)

Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix.

מדדים

CVSS 3.1
9.8 (CRITICAL) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS — סבירות ניצול
100% (אחוזון 100) נכון ל-24/7/2026
CWE
CWE-74

מוצרים מושפעים

apache: archiva; apache: struts; fujitsu: interstage business process manager analytics; microsoft: windows server 2003; microsoft: windows server 2008; redhat: enterprise linux; microsoft: windows server 2012; oracle: solaris; oracle: siebel apps - e-billing

קישורים