CVE-2012-0391

Description

The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling for mismatched data types of properties, which allows remote attackers to execute arbitrary Java code via a crafted parameter.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
88.319

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2012-0838,CVE-2012-0392,CVE-2012-0391 are fixed in Apache-struts2-core 2.2.3.1Windows
Vulnerabilities CVE-2012-0838,CVE-2012-0392,CVE-2012-0391,CVE-2012-0393 are fixed in Apache-Xwork-core 2.2.3.1Windows
Vulnerabilities CVE-2012-0838,CVE-2012-0392,CVE-2012-0391 are fixed in Apache-structs2-core for Linux 2.2.3.1Linux
Vulnerabilities CVE-2012-0838,CVE-2012-0392,CVE-2012-0391,CVE-2012-0393 are fixed in Apache-Xwork-core for Linux 2.2.3.1Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234