ZeroHour

CVE-2019-0230

PoC ×2
CVSS 3.1
9.8 critical
EPSS
97%p100
Published
()
Modified
Description

Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.

Vendors
apacheoracle
Products
struts, communications policy management, financial services data integration hub, financial services market risk measurement and management, mysql enterprise monitor
Weakness
CWE-1321
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news