CVE-2019-0233: Apache Struts

High severity, CVSS 7.5. EPSS: 66.1% chance of exploitation in the next 30 days.

An access permission override in Apache Struts 2.0.0 to 2.5.20 may cause a Denial of Service when performing a file upload.

Affected products

  • Apache Struts: from 2.0.0, up to and including 2.5.20
  • Oracle Communications Policy Management: version 12.5.0 only
  • Oracle Financial Services Data Integration Hub: version 8.0.3 only; version 8.0.6 only
  • Oracle Financial Services Market Risk Measurement And Management: version 8.0.6 only
  • Oracle MySQL Enterprise Monitor: up to and including 8.0.23

Published 2020-09-14. Last modified 2026-06-17.