EXPOSURES › CVE-2013-2251
CVE-2013-2251
HIGH ⌖ ON CISA KEV · EXPLOITEDApache Struts allowed remote attackers to execute arbitrary OGNL expressions due to improper input validation.
This vulnerability enabled remote code execution, allowing attackers to take full control of affected systems. DIB organizations must ensure all Apache Struts components are patched to the latest version to prevent exploitation and maintain compliance with security requirements.
Shame score — A long-standing, widely known vulnerability that was actively exploited in the wild, demonstrating severe negligence in patch management and security hygiene.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Apache Struts allows remote attackers to execute arbitrary Object-Graph Navigation Language (OGNL) expressions.