CVE-2019-0233: Apache Struts
High severity, CVSS 7.5. EPSS: 66.1% chance of exploitation in the next 30 days.
An access permission override in Apache Struts 2.0.0 to 2.5.20 may cause a Denial of Service when performing a file upload.
Affected products
- Apache Struts: from 2.0.0, up to and including 2.5.20
- Oracle Communications Policy Management: version 12.5.0 only
- Oracle Financial Services Data Integration Hub: version 8.0.3 only; version 8.0.6 only
- Oracle Financial Services Market Risk Measurement And Management: version 8.0.6 only
- Oracle MySQL Enterprise Monitor: up to and including 8.0.23
Published 2020-09-14. Last modified 2026-06-17.