CVE-2012-0391

CVSS 2.0 Score 9.3 of 10 (high)

Details

Published Jan 8, 2012
Updated: Dec 19, 2024
CWE ID 20

Summary

CVE-2012-0391 is a vulnerability affecting Apache Struts versions prior to 2.2.3.1. The issue lies in the ExceptionDelegator component, which mishandles certain exception types. Maliciously crafted parameter values can be interpreted as Object Graph Navigation Language (OGNL) expressions, allowing remote attackers to execute arbitrary Java code during exception handling for mismatched data types. This vulnerability poses a significant risk, as it enables attackers to manipulate application logic and potentially gain control over the underlying system.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Apache Struts
  • Apache Struts 2.2

Affected Vendors

  • Apache Software Foundation
  • Apache Corporation