CVE-2012-4387: Medium severity Apache struts vulnerability
Published Sep 5, 2012
·Updated
Apache Struts 2.0.0 through 2.3.4 allows remote attackers to cause a denial of service (CPU consumption) via a long parameter name, which is processed as an OGNL expression.
Affected Software
36 affected componentsFixes available
maven/org.apache.struts.xwork:xwork-core>=2.0.0<2.3.4.1
2.3.4.1
Apache struts=2.0.0
Apache struts=2.0.1
Apache struts=2.0.2
Apache struts=2.0.3
Apache struts=2.0.4
Apache struts=2.0.5
Apache struts=2.0.6
Apache struts=2.0.7
Apache struts=2.0.8
Apache struts=2.0.9
Apache struts=2.0.10
Apache struts=2.0.11
Apache struts=2.0.11.1
Apache struts=2.0.11.2
Apache struts=2.0.12
Apache struts=2.0.13
Apache struts=2.0.14
Apache struts=2.1.0
Apache struts=2.1.1
Apache struts=2.1.2
Apache struts=2.1.3
Apache struts=2.1.4
Apache struts=2.1.5
Apache struts=2.1.6
Apache struts=2.1.8
Apache struts=2.1.8.1
Apache struts=2.2.1
Apache struts=2.2.1.1
Apache struts=2.2.3
Apache struts=2.2.3.1
Apache struts=2.3.1
Apache struts=2.3.1.1
Apache struts=2.3.1.2
Apache struts=2.3.3
Apache struts=2.3.4
Remediation
Patch Available
Event History
Sep 5, 2012
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
May 17, 2022
Advisory Published
01:42 AM
Frequently Asked Questions
1
What is the severity of CVE-2012-4387?
CVE-2012-4387 has a severity rating that indicates it can lead to denial of service through excessive CPU consumption.
2
How do I fix CVE-2012-4387?
To mitigate CVE-2012-4387, upgrade to Apache Struts version 2.3.4.1 or later.
3
What software versions are affected by CVE-2012-4387?
CVE-2012-4387 affects Apache Struts versions 2.0.0 through 2.3.4.
4
Can CVE-2012-4387 be exploited remotely?
Yes, CVE-2012-4387 can be exploited remotely by attackers via specially crafted parameter names.
5
Is CVE-2012-4387 still a concern for users of Apache Struts?
Users of Apache Struts versions prior to 2.3.4.1 should be aware of CVE-2012-4387's potential impact and upgrade immediately.