CVE-2019-0230: Apache Struts
Critical severity, CVSS 9.8. EPSS: 96.9% chance of exploitation in the next 30 days.
Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.
Affected products
- Apache Struts: from 2.0.0, up to and including 2.5.20
- Oracle Communications Policy Management: version 12.5.0 only
- Oracle Financial Services Data Integration Hub: version 8.0.3 only; version 8.0.6 only
- Oracle Financial Services Market Risk Measurement And Management: version 8.0.6 only
- Oracle MySQL Enterprise Monitor: up to and including 8.0.23
Published 2020-09-14. Last modified 2026-06-17.