EXPOSURES › CVE-2012-0391
CVE-2012-0391
HIGH ⌖ ON CISA KEV · EXPLOITEDApache Struts 2's ExceptionDelegator component allowed remote code execution via improper input validation before version 2.2.3.1.
This vulnerability enabled attackers to execute arbitrary code on vulnerable systems, leading to potential data breaches, system compromise, and ransomware deployment. DIB organizations must ensure all Apache Struts 2 instances are patched to version 2.2.3.1 or later to prevent exploitation, as this flaw was actively exploited in the wild and remains a high-priority remediation target under CMMC/NIST 800-171 controls.
Shame score — A long-standing, widely known RCE vulnerability that was actively exploited in the wild, demonstrating severe negligence in patch management and leaving systems exposed to critical threats.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
The ExceptionDelegator component in Apache Struts 2 before 2.2.3.1 contains an improper input validation vulnerability that allows for remote code execution.