CVE-2012-0391

CVE Published 2012-01-08
Related CWE(s) CWE-20: Improper Input Validation
Related Vendor(s) apache
Related Product(s) struts
Exploitation Reported (CISA KEV) 2022-01-21

The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling for mismatched data types of properties, which allows remote attackers to execute arbitrary Java code via a crafted parameter.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References