CVE-2013-2251
Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
Vulnerability Description
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix.
Affected Platforms (CPE)
π¦
Apache
Archiva
>= 1.3 and < 1.3.8π¦
Apache
Archiva
= 1.2π¦
Apache
Archiva
= 1.2.2π¦
Apache
Struts
>= 2.0.0 and <= 2.3.15π¦
Fujitsu
Interstage Business Process Manager Analytics
= 12.0π¦
Fujitsu
Interstage Business Process Manager Analytics
= 12.1π¦
Oracle
Siebel Apps E Billing
= 6.1π¦
Oracle
Siebel Apps E Billing
= 6.1.1π¦
Oracle
