CVE Vulnerabilities

CVE-2014-0112

Published: Apr 29, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
7.5 IMPORTANT
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V3
7.3 IMPORTANT
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which allows remote attackers to manipulate the ClassLoader and execute arbitrary code via a crafted request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0094.

Affected Software

NameVendorStart VersionEnd Version
StrutsApache2.0.0 (including)2.3.16.2 (excluding)
Red Hat Fuse 7.3RedHat*
Libstruts1.2-javaUbuntulucid*
Libstruts1.2-javaUbuntuprecise*
Libstruts1.2-javaUbuntuquantal*
Libstruts1.2-javaUbuntusaucy*
Libstruts1.2-javaUbuntutrusty*
Libstruts1.2-javaUbuntuupstream*
Libstruts1.2-javaUbuntuutopic*

References