CVE-2013-2251: Apache Struts Improper Input Validation Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2022-03-25. EPSS: 100% chance of exploitation in the next 30 days.
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix.
Affected products
- Apache Archiva: from 1.3, before 1.3.8 (fixed in 1.3.8); version 1.2 only; version 1.2.2 only
- Apache Struts: from 2.0.0, up to and including 2.3.15
- Fujitsu Interstage Business Process Manager Analytics: version 12.0 only; version 12.1 only
- Oracle Siebel Apps - E-Billing: version 6.1 only; version 6.1.1 only; version 6.2 only
Published 2013-07-20. Last modified 2026-06-16.