Vulnerability Intelligence Report
Apache Struts Improper Input Validation Vulnerability
CVE-2013-2251
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix.
CISA KEV
Nuclei Template
SSVC: Active Exploitation
Automatable
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:100.00%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-74 ↗CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| apache | archiva | 1.2, 1.2.2 |
| apache | struts | all |
| fujitsu | interstage_business_process_manager_analytics | 12.0, 12.1 |
| microsoft | windows_server_2003 | all |
| microsoft | windows_server_2008 | all |
| redhat | enterprise_linux | all |
| microsoft | windows_server_2012 | all |
| oracle | solaris | 11 |
| oracle | siebel_apps_-_e-billing | 6.1, 6.1.1, 6.2 |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
99.998%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Red Hat, Inc. · Vendor · USA |
| Reserved | 2013-02-19T00:00:00 |
| Published | 2013-07-18T01:00:00 |
| Patch Date | 2013-07-16 |
| Last Updated | 2025-10-22T00:05:41 |
Community Chatter & Buzz