Skip to content
COOEY

EXPOSURES › CVE-2013-2251

CVE-2013-2251

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2013-2251 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildunpatched

Apache Struts allowed remote attackers to execute arbitrary OGNL expressions due to improper input validation.

This vulnerability enabled remote code execution, allowing attackers to take full control of affected systems. DIB organizations must ensure all Apache Struts components are patched to the latest version to prevent exploitation and maintain compliance with security requirements.

Shame score — A long-standing, widely known vulnerability that was actively exploited in the wild, demonstrating severe negligence in patch management and security hygiene.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Apache Struts allows remote attackers to execute arbitrary Object-Graph Navigation Language (OGNL) expressions.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.