Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2012-0391 | First vendor Publication | 2012-01-08 |
Vendor | Cve | Last vendor Modification | 2025-03-12 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 9.3 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling for mismatched data types of properties, which allows remote attackers to execute arbitrary Java code via a crafted parameter. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0391 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-20 | Improper Input Validation |
CPE : Common Platform Enumeration
SAINT Exploits
Description | Link |
---|---|
Apache Struts 2 ConversionErrorInterceptor Java Injection | More info here |
OpenVAS Exploits
Date | Description |
---|---|
2012-08-31 | Name : VMSA-2012-0013 VMware vSphere and vCOps updates to third party libraries. File : nvt/gb_VMSA-2012-0013.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
78277 | Apache Struts ExceptionDelegator Component Parameter Parsing Remote Code Exec... |
Information Assurance Vulnerability Management (IAVM)
Date | Description |
---|---|
2012-09-27 | IAVM : 2012-A-0153 - Multiple Vulnerabilities in VMware ESX 4.0 and ESXi 4.0 Severity : Category I - VMSKEY : V0033884 |
2012-09-13 | IAVM : 2012-B-0086 - VMware vCenter Operations Arbitrary File Overwrite Vulnerability Severity : Category I - VMSKEY : V0033791 |
2012-09-13 | IAVM : 2012-A-0146 - Multiple Vulnerabilities in VMware vCenter Update Manager 4.1 Severity : Category I - VMSKEY : V0033792 |
2012-09-13 | IAVM : 2012-A-0147 - Multiple Vulnerabilities in VMware vCenter Server 4.1 Severity : Category I - VMSKEY : V0033793 |
2012-09-13 | IAVM : 2012-A-0148 - Multiple Vulnerabilities in VMware ESXi 4.1 and ESX 4.1 Severity : Category I - VMSKEY : V0033794 |
Snort® IPS/IDS
Date | Description |
---|---|
2014-01-10 | Apache Struts remote code execution attempt - POST parameter RuleID : 23631 - Revision : 7 - Type : SERVER-APACHE |
2014-01-10 | Apache Struts remote code execution attempt - GET parameter RuleID : 21656 - Revision : 6 - Type : SERVER-APACHE |
2014-01-10 | Apache Struts allowStaticMethodAccess invocation attempt RuleID : 21073 - Revision : 7 - Type : SERVER-APACHE |
2014-01-10 | Apache Struts remote code execution attempt - GET parameter RuleID : 21072 - Revision : 8 - Type : SERVER-APACHE |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2016-02-29 | Name : The remote VMware ESX / ESXi host is missing a security-related patch. File : vmware_VMSA-2012-0013_remote.nasl - Type : ACT_GATHER_INFO |
2013-11-13 | Name : The remote VMware ESXi 5.0 host is affected by multiple vulnerabilities. File : vmware_esxi_5_0_build_912577_remote.nasl - Type : ACT_GATHER_INFO |
2013-08-07 | Name : The remote web server contains a web application that uses a Java framework t... File : struts_exceptiondelegator_command_execution.nasl - Type : ACT_ATTACK |
2013-07-29 | Name : The remote host has a virtualization appliance installed that is affected by ... File : vcenter_operations_manager_vmsa_2012-0013.nasl - Type : ACT_GATHER_INFO |
2013-06-17 | Name : The remote host has an update manager installed that is affected by multiple ... File : vmware_vcenter_update_mgr_vmsa-2012-0013.nasl - Type : ACT_GATHER_INFO |
2013-06-05 | Name : The remote host has a virtualization management application installed that is... File : vmware_vcenter_vmsa-2012-0013.nasl - Type : ACT_GATHER_INFO |
2012-08-31 | Name : The remote VMware ESXi / ESX host is missing one or more security-related pat... File : vmware_VMSA-2012-0013.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2025-03-13 00:21:28 |
|
2025-02-11 17:21:37 |
|
2024-12-20 00:21:19 |
|
2024-11-28 23:03:09 |
|
2024-11-28 12:28:36 |
|
2021-05-05 01:09:57 |
|
2021-05-04 12:19:03 |
|
2021-04-22 01:22:45 |
|
2020-05-23 13:16:59 |
|
2020-05-23 01:47:57 |
|
2020-05-23 00:32:42 |
|
2019-06-21 12:04:12 |
|
2018-11-29 21:19:28 |
|
2018-11-23 17:19:57 |
|
2017-11-22 12:04:31 |
|
2016-06-28 18:59:20 |
|
2016-04-26 21:26:01 |
|
2014-03-13 21:20:55 |
|
2014-02-17 11:07:28 |
|
2014-01-19 21:28:24 |
|
2013-05-10 22:32:21 |
|