The ParameterInterceptor component in Apache Struts before 2.3.1.1 does not prevent access to public constructors, which allows remote attackers to create or overwrite arbitrary files via a crafted parameter that triggers the creation of a Java object.
Metrics
Affected Vendors & Products
References
History
Wed, 28 May 2025 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
Thu, 22 May 2025 04:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-16T22:24:46.401Z
Reserved: 2012-01-08T00:00:00Z
Link: CVE-2012-0393

No data.

Status : Deferred
Published: 2012-01-08T15:55:01.420
Modified: 2025-04-11T00:51:21.963
Link: CVE-2012-0393
