CVE Vulnerabilities

CVE-2014-0094

Published: Mar 11, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
5 IMPORTANT
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to manipulate the ClassLoader via the class parameter, which is passed to the getClass method.

Affected Software

NameVendorStart VersionEnd Version
StrutsApache2.0.0 (including)2.3.16.1 (excluding)
Libstruts1.2-javaUbuntuupstream*

References