Lucene search

K
cvelistMitreCVELIST:CVE-2012-0392
HistoryOct 03, 2022 - 4:15 p.m.

CVE-2012-0392

2022-10-0316:15:40
mitre
www.cve.org
2
apache struts
cookieinterceptor
security vulnerability
remote attackers
java code execution

9.7 High

AI Score

Confidence

High

0.962 High

EPSS

Percentile

99.5%

The CookieInterceptor component in Apache Struts before 2.3.1.1 does not use the parameter-name whitelist, which allows remote attackers to execute arbitrary commands via a crafted HTTP Cookie header that triggers Java code execution through a static method.

9.7 High

AI Score

Confidence

High

0.962 High

EPSS

Percentile

99.5%