CVE Vulnerabilities

CVE-2014-0094

Published: Mar 11, 2014 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
5 IMPORTANT
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM

The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to manipulate the ClassLoader via the class parameter, which is passed to the getClass method.

Affected Software

Name Vendor Start Version End Version
Struts Apache 2.0.0 (including) 2.3.16.1 (excluding)
Libstruts1.2-java Ubuntu upstream *

References