CISA Known Exploited Vulnerability

CVE-2012-0391

Apache · Struts 2

Apache Struts 2 Improper Input Validation Vulnerability

Date added
BOD 22-01 due date
CWE CWE-20
Ransomware Unknown

CISA description

The ExceptionDelegator component in Apache Struts 2 before 2.2.3.1 contains an improper input validation vulnerability that allows for remote code execution.

Required action

Apply updates per vendor instructions.