CVE-2012-0838

EPSS 11.1%

Apache Struts Code injection due to conversion error

Published: 5/14/2022Modified: 12/5/2024

Description

Apache Struts 2 before 2.2.3.1 evaluates a string as an OGNL expression during the handling of a conversion error, which allows remote attackers to modify run-time data values, and consequently execute arbitrary code, via invalid input to a field.

Affected packages (2)

References (9)