← Vulnerability feed

Vulnerability record · CVE-2012-0392 · published 8 January 2012

CVE-2012-0392: Apache Struts CookieInterceptor parameter whitelist bypass enables remote code execution

Apache · Struts

The CookieInterceptor component in Apache Struts before 2.3.1.1 fails to apply the parameter-name whitelist, so a crafted HTTP Cookie header can reach Java static methods and execute arbitrary commands. This is a remote, unauthenticated code execution flaw in a widely deployed web framework, making it a serious risk for any unpatched Struts 2 deployment.

6.8 CVSS 2.0 Medium EPSS 98% · top 0.1%
6.8CVSS 2.0 base score
98%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

The CookieInterceptor component in Apache Struts before 2.3.1.1 does not use the parameter-name whitelist, which allows remote attackers to execute arbitrary commands via a crafted HTTP Cookie header that triggers Java code execution through a static method.

AV:N/AC:M/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityUnauthenticated remote code execution in a widely used framework with public exploit code and very high EPSS probability warrants immediate patching.

What it is

The CookieInterceptor component in Apache Struts before 2.3.1.1 fails to apply the parameter-name whitelist, so a crafted HTTP Cookie header can reach Java static methods and execute arbitrary commands. This is a remote, unauthenticated code execution flaw in a widely deployed web framework, making it a serious risk for any unpatched Struts 2 deployment.

Impact

An attacker can execute arbitrary commands on the server hosting the Struts application, leading to full compromise of the application and potentially the underlying host. No credentials are required.

Attack surface

Reached over the network via a crafted HTTP Cookie header sent to a Struts 2 application; the CVSS vector (AV:N/AC:M/Au:N) indicates no authentication is needed, though some attack complexity is present. No user interaction is required.

Exploitation

Public exploit code exists (Exploit-DB 18329 and a dailydave post are tagged Exploit), and EPSS is very high at 0.975 (99.9th percentile), though the CVE is not listed in CISA KEV.

What to do

  • Upgrade Apache Struts to 2.3.1.1 or later, which applies the parameter-name whitelist in CookieInterceptor.
  • If immediate upgrade is not possible, restrict or block Cookie headers containing suspicious parameter names at a reverse proxy or WAF.
  • Remove or disable the CookieInterceptor if it is not required by the application.
  • Review server logs for signs of command execution and rotate any credentials or keys exposed on affected hosts.

Detection

  • Inspect HTTP request logs for Cookie headers containing parameter names that match Struts action or OGNL-style patterns.
  • Monitor for unexpected child processes spawned by the Java/Struts application server.
  • Alert on outbound network connections from the Struts host to unusual destinations following HTTP requests.
  • Use the public Exploit-DB 18329 payload patterns as signatures in IDS/WAF rules.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-0392 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-17530Apache Struts forced OGNL evaluation enables remote code executionApache Struts 2.0.0 through 2.5.25 performs forced OGNL evaluation on raw user input placed in tag attributes, allowing expression language injection…KEVEPSS 96%analysed9.8CVE-2017-9791Apache Struts 1 plugin input validation flaw enables remote code executionThe Struts 1 plugin in Apache Struts 2.1.x and 2.3.x may allow remote code execution when a malicious field value is passed in a raw message to the A…KEVEPSS 99%analysed9.8CVE-2017-5638Apache Struts 2 Jakarta Multipart parser remote code executionThe Jakarta Multipart parser in Apache Struts 2 mishandles exceptions and error messages during file-upload attempts, letting a crafted Content-Type,…KEVEPSS 100%analysed9.8CVE-2013-2251Apache Struts 2 OGNL injection enables remote code executionApache Struts 2.0.0 through 2.3.15 fails to properly validate request parameters, allowing crafted action:, redirect:, or redirectAction: prefixes to…KEVEPSS 100%analysed9.8CVE-2012-0391Apache Struts ExceptionDelegator OGNL injection enables remote code executionApache Struts before 2.2.3.1 evaluates parameter values as OGNL expressions in the ExceptionDelegator component during exception handling for mismatc…KEVEPSS 76%analysed8.1CVE-2018-11776Apache Struts namespace handling flaw enables remote code executionApache Struts 2.3 through 2.3.34 and 2.5 through 2.5.16 can execute remote code when alwaysSelectFullNamespace is enabled and results or url tags are…KEVEPSS 100%analysed8.1CVE-2017-9805Apache Struts REST Plugin XStream deserialization RCEThe REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an XStream instance for deseri…KEVEPSS 99%analysed7.5CVE-2006-1547Apache Struts 1 ActionForm multipart parameter denial of serviceApache Struts before 1.2.9 with BeanUtils 1.7 exposes the public getMultipartRequestHandler method through ActionForm parameter binding. A remote att…KEVEPSS 55%analysed

Source: NIST National Vulnerability Database (record CVE-2012-0392), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.