CVE-2012-0391
CVSS 2.0 Score 9.3 of 10 (high)
Details
Published Jan 8, 2012
Updated: Dec 19, 2024
CWE ID 20
Summary
CVE-2012-0391 is a vulnerability affecting Apache Struts versions prior to 2.2.3.1. The issue lies in the ExceptionDelegator component, which mishandles certain exception types. Maliciously crafted parameter values can be interpreted as Object Graph Navigation Language (OGNL) expressions, allowing remote attackers to execute arbitrary Java code during exception handling for mismatched data types. This vulnerability poses a significant risk, as it enables attackers to manipulate application logic and potentially gain control over the underlying system.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Apache Struts
- Apache Struts 2.2
Affected Vendors
- Apache Software Foundation
- Apache Corporation