peter bassill · operator
$ cve CVE-2013-2251 JSON

CVE-2013-2251 KEV EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 100% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-04-15.

Description

Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS100% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-74
On CISA KEVyes — remediate by 2022-04-15
Public exploityes
Published2013-07-20
Last modified2026-06-16

CISA KEV

NameApache Struts Improper Input Validation Vulnerability
Added2022-03-25
Due2022-04-15
Vendor / productApache / Struts
Ransomware usenone reported

Affected (9)

VendorProduct
apachearchiva
apachestruts
fujitsuinterstage business process manager analytics
microsoftwindows server 2003
microsoftwindows server 2008
microsoftwindows server 2012
oraclesiebel apps - e-billing
oraclesolaris
redhatenterprise linux

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD