CyberSec.Space Logo
Back to CVE Browser

CVE-2012-0838

CRITICAL
10.0
CVSS Severity Score
EPSS Score0.1350%
EPSS Percentile30.09th
PublishedMar 2, 2012
Last ModifiedApr 29, 2026

Vulnerability Description

Apache Struts 2 before 2.2.3.1 evaluates a string as an OGNL expression during the handling of a conversion error, which allows remote attackers to modify run-time data values, and consequently execute arbitrary code, via invalid input to a field.

Affected Platforms (CPE)

πŸ“¦
Apache

Struts

>= 2.0.0 and <= 2.2.3

References & Advisories

Related Vulnerabilities