peter bassill · operator
$ cve CVE-2014-0112 JSON

CVE-2014-0112 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 97.9% (pctl 100)

Patch early

A public exploit exists.

Description

ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via a crafted request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0094.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS97.92% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-264
On CISA KEVno
Public exploityes
Published2014-04-29
Last modified2026-06-17

Affected (1)

VendorProduct
apachestruts

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD