peter bassill · operator
$ cve CVE-2019-0230 JSON

CVE-2019-0230 EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 97.4% (pctl 100)

Patch early

A public exploit exists.

Description

Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS97.4% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-1321
On CISA KEVno
Public exploityes
Published2020-09-14
Last modified2026-06-17

Affected (5)

VendorProduct
apachestruts
oraclecommunications policy management
oraclefinancial services data integration hub
oraclefinancial services market risk measurement and management
oraclemysql enterprise monitor

Public exploits

SourceTitleDate
exploit-dbApache Struts 2.5.20 - Double OGNL evaluation2020-11-17

References

→ the Explorer  ·  watch your stack  ·  NVD