CVE-2012-0393: Medium severity apache struts 2 vulnerability
The ParameterInterceptor component in Apache Struts before 2.3.1.1 does not prevent access to public constructors, which allows remote attackers to create or overwrite arbitrary files via a crafted parameter that triggers the creation of a Java object.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0393?
CVE-2012-0393 is classified as a critical vulnerability due to its potential for remote code execution and file manipulation.
How do I fix CVE-2012-0393?
To fix CVE-2012-0393, upgrade to Apache Struts version 2.3.1.1 or later, or version 2.2.3.1 or later.
What software is affected by CVE-2012-0393?
CVE-2012-0393 affects Apache Struts versions prior to 2.3.1.1.
What types of attacks can be performed using CVE-2012-0393?
Exploitation of CVE-2012-0393 enables attackers to create or overwrite arbitrary files on the server.
Is CVE-2012-0393 easily exploitable?
Yes, CVE-2012-0393 is considered easily exploitable by remote attackers due to insufficient parameter validation.