Lucene search

K
cve[email protected]CVE-2014-0094
HistoryMar 11, 2014 - 1:00 p.m.

CVE-2014-0094

2014-03-1113:00:37
web.nvd.nist.gov
99
2
cve-2014-0094
apache struts
parametersinterceptor
classloader
manipulation
nvd

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

9.1 High

AI Score

Confidence

High

0.971 High

EPSS

Percentile

99.8%

The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to “manipulate” the ClassLoader via the class parameter, which is passed to the getClass method.

Affected configurations

NVD
Node
apachestrutsRange2.0.02.3.16.1
CPENameOperatorVersion
apache:strutsapache strutslt2.3.16.1

Social References

More

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

9.1 High

AI Score

Confidence

High

0.971 High

EPSS

Percentile

99.8%