peter bassill · operator
$ cve CVE-2014-0094 JSON

CVE-2014-0094 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 99.6% (pctl 100)

Patch early

A public exploit exists.

Description

The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via the class parameter, which is passed to the getClass method.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS99.57% — more likely to be exploited than 100% of all CVEs
On CISA KEVno
Public exploityes
Published2014-03-11
Last modified2026-06-17

Affected (1)

VendorProduct
apachestruts

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD