← Back to CVE List
Vulnerability Intelligence Report
Apache Struts Improper Input Validation Vulnerability

CVE-2013-2251

Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix.

CISA KEV Nuclei Template SSVC: Active Exploitation Automatable
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:100.00%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-74 ↗CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Affected Products & Versions

Vendor Product Affected Versions
apache archiva 1.2, 1.2.2
apache struts all
fujitsu interstage_business_process_manager_analytics 12.0, 12.1
microsoft windows_server_2003 all
microsoft windows_server_2008 all
redhat enterprise_linux all
microsoft windows_server_2012 all
oracle solaris 11
oracle siebel_apps_-_e-billing 6.1, 6.1.1, 6.2

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
99.998%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityRed Hat, Inc. · Vendor · USA
Reserved2013-02-19T00:00:00
Published2013-07-18T01:00:00
Patch Date2013-07-16
Last Updated2025-10-22T00:05:41

LINK COPIED TO CLIPBOARD