CVE-2013-2251 KEV EXPLOIT
9.8
CRITICAL · CVSS 3.1 · EPSS 100% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2022-04-15.
Description
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 100% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-74 |
| On CISA KEV | yes — remediate by 2022-04-15 |
| Public exploit | yes |
| Published | 2013-07-20 |
| Last modified | 2026-06-16 |
CISA KEV
| Name | Apache Struts Improper Input Validation Vulnerability |
|---|---|
| Added | 2022-03-25 |
| Due | 2022-04-15 |
| Vendor / product | Apache / Struts |
| Ransomware use | none reported |
Affected (9)
| Vendor | Product |
|---|---|
| apache | archiva |
| apache | struts |
| fujitsu | interstage business process manager analytics |
| microsoft | windows server 2003 |
| microsoft | windows server 2008 |
| microsoft | windows server 2012 |
| oracle | siebel apps - e-billing |
| oracle | solaris |
| redhat | enterprise linux |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Apache Struts2 2.0.0 < 2.3.15 - Prefixed Parameters OGNL Injection | 2014-01-14 |
| exploit-db | Apache Struts 2 - DefaultActionMapper Prefixes OGNL Code Execution (Metasploit) | 2013-07-27 |
References
- http://archiva.apache.org/security.html
- http://cxsecurity.com/issue/WLB-2014010087
- http://osvdb.org/98445
- http://packetstormsecurity.com/files/159629/Apache-Struts-2-Remote-Code-Execution.html
- http://seclists.org/fulldisclosure/2013/Oct/96
- http://seclists.org/oss-sec/2014/q1/89
- http://struts.apache.org/release/2.3.x/docs/s2-016.html
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20131023-struts2
- http://www.fujitsu.com/global/support/software/security/products-f/interstage-bpm-analytics-201301e.html
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html
- http://www.securityfocus.com/bid/61189
- http://www.securityfocus.com/bid/64758
- http://www.securitytracker.com/id/1029184
- http://www.securitytracker.com/id/1032916
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90392
- http://archiva.apache.org/security.html
- http://cxsecurity.com/issue/WLB-2014010087
- http://osvdb.org/98445
- http://packetstormsecurity.com/files/159629/Apache-Struts-2-Remote-Code-Execution.html
→ the Explorer · watch your stack · NVD