CyberSec.Space Logo
CVEブラウザに戻る

CVE-2012-0838

CRITICAL
10.0
CVSS Severity Score
EPSS Score0.1350%
EPSS Percentile30.09th
Published2012年3月2日
Last Modified2026年4月29日

Vulnerability Description

Apache Struts 2 before 2.2.3.1 evaluates a string as an OGNL expression during the handling of a conversion error, which allows remote attackers to modify run-time data values, and consequently execute arbitrary code, via invalid input to a field.

Affected Platforms (CPE)

📦
Apache

Struts

>= 2.0.0 and <= 2.2.3

References & Advisories

関連する脆弱性情報