A AegiFlow
UNKNOWNKNOWN EXPLOITED

CVE-2012-0391

Apache Struts 2 Improper Input Validation Vulnerability

Published
2022-01-21
Modified
2026-07-31
Sources
cisa-kev

Summary

The ExceptionDelegator component in Apache Struts 2 before 2.2.3.1 contains an improper input validation vulnerability that allows for remote code execution.

References

Includes data from the CISA Known Exploited Vulnerabilities catalog.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.