CVE-2013-2251

CVE Published 2013-07-20
Related CWE(s) CWE-20: Improper Input Validation, CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
Related Vendor(s) fujitsu, apache, oracle
Related Product(s) sparc_firmware, primepower_firmware, struts, archiva, interstage_business_process_manager_analytics, gp5000_firmware, siebel_apps_-_e-billing, primergy_firmware, gp-s_firmware, gp7000f_firmware
Exploitation Reported (CISA KEV) 2022-03-25
CVSS 3 Base Score 9.8 (CRITICAL)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References