CVE-2012-0394: Apache Struts
Medium severity, CVSS 6.8. EPSS: 72.9% chance of exploitation in the next 30 days.
The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers to execute arbitrary commands via unspecified vectors. NOTE: the vendor characterizes this behavior as not "a security vulnerability itself.
Affected products
- Apache Struts: from 2.0.0, up to and including 2.3.17
Published 2012-01-08. Last modified 2026-06-16.