Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HApache Archiva
APPApache1.21.2.21.3 – 1.3.8 (excl.)Apache Struts
APPApache2.0.0 – 2.3.15Fujitsu Interstage Business Process Manager Analytics
APPFujitsu12.012.1Microsoft Windows Server 2003
OSMicrosoftall versionsMicrosoft Windows Server 2008
OSMicrosoftall versionsMicrosoft Windows Server 2012
OSMicrosoftall versionsOracle Siebel Apps E Billing
APPOracle6.16.1.16.2Oracle Solaris
OSOracle11Red Hat Enterprise Linux
OSRedhat5.0 – 6.10
CISA KEV — detailsi
- Vendori
- Apache ↗
- Producti
- Struts
- Added to KEVi
- March 25, 2022
- Remediation deadline (US Federal)i
- April 15, 2022(overdue)
Required action (CISA)i
Apply updates per vendor instructions.
CISA descriptioni
Apache Struts allows remote attackers to execute arbitrary Object-Graph Navigation Language (OGNL) expressions.
🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
⏰CISA DEADLINE: 15 kwietnia 2022
References
Related vulnerabilities
CVE-2025-59287CRITICAL9.8⚠ KEVPL ✓same product
RCE w Windows Server Update Service (WSUS) — deserializacja danych
CVE-2025-32463CRITICAL9.3⚠ KEVPL ✓same product
Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)
CVE-2021-40438CRITICAL9.0⚠ KEVPL ✓same product
SSRF w mod_proxy Apache HTTP Server — przekierowanie żądań przez atakującego
CVE-2020-17530CRITICAL9.8⚠ KEVPL ✓same product
RCE w Apache Struts 2 poprzez wymuszoną ewaluację OGNL
CVE-2020-14871CRITICAL10.0⚠ KEVPL ✓same product
Oracle Solaris PAM — zdalne przejęcie systemu bez uwierzytelnienia