← Vulnerability feed

Vulnerability record · CVE-2013-2251 · published 20 July 2013

CVE-2013-2251: Apache Struts 2 OGNL injection enables remote code execution

Apache · Archiva

Apache Struts 2.0.0 through 2.3.15 fails to properly validate request parameters, allowing crafted action:, redirect:, or redirectAction: prefixes to inject and execute arbitrary OGNL expressions. Because OGNL can invoke Java methods, this is effectively unauthenticated remote code execution on affected Struts 2 deployments. The flaw is old but still widely exploited and appears in CISA's Known Exploited Vulnerabilities catalog.

9.8 CVSS 3.1 Critical CISA KEV since 25 Mar 2022 EPSS 100% · top 0.1% CWE-74 · Injection
9.8CVSS 3.1 base score, v2 9.3
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
4Affected product versions listed by NVD
33References, 6 tagged exploit
16 Jun 2026Last modified by NVD

Description

Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable remote code execution with a near-maximum EPSS score and active inclusion in CISA KEV makes this an urgent patch-first issue.

What it is

Apache Struts 2.0.0 through 2.3.15 fails to properly validate request parameters, allowing crafted action:, redirect:, or redirectAction: prefixes to inject and execute arbitrary OGNL expressions. Because OGNL can invoke Java methods, this is effectively unauthenticated remote code execution on affected Struts 2 deployments. The flaw is old but still widely exploited and appears in CISA's Known Exploited Vulnerabilities catalog.

Impact

An unauthenticated remote attacker can execute arbitrary code with the privileges of the application server, leading to full host compromise, data theft, and lateral movement. No user interaction or valid credentials are required.

Attack surface

Reached over the network via HTTP requests to a Struts 2 application, typically by supplying a malicious parameter value with an action:, redirect:, or redirectAction: prefix. The CVSS vector (AV:N/AC:L/PR:N/UI:N) confirms no authentication and no user interaction are needed.

Exploitation

CISA added it to KEV on 2022-03-25 with a 2022-04-15 remediation due date, and EPSS is near 1.0 (0.99998, 99.99th percentile). Multiple public exploit references exist, so exploitation is trivial and ongoing.

What to do

  • Upgrade Apache Struts 2 to a version later than 2.3.15 per the S2-016 advisory; patch is the only reliable fix.
  • If immediate upgrade is impossible, apply vendor mitigations and restrict or block requests containing action:, redirect:, or redirectAction: parameter prefixes at the WAF or reverse proxy.
  • Inventory all applications and embedded frameworks that bundle Struts 2 (including Archiva, Oracle, and Fujitsu products listed) and confirm each is patched.
  • Remove or isolate internet-facing Struts 2 instances that cannot be upgraded until they are remediated.

Detection

  • Search web and proxy logs for request parameters containing action:, redirect:, or redirectAction: prefixes, especially with OGNL syntax such as @ or # expressions.
  • Alert on outbound connections or child processes spawned by the Java application server that are unusual for the app.
  • Monitor for known Struts 2 exploit payload patterns in HTTP request bodies and query strings using IDS/WAF signatures.
  • Review application server logs for OGNL parsing errors or unexpected class loading around request handling.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2013-2251 to the Known Exploited Vulnerabilities catalog on 25 March 2022 as "Apache Struts Improper Input Validation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 April 2022.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://archiva.apache.org/security.html Product
http://cxsecurity.com/issue/WLB-2014010087 ExploitThird Party Advisory
http://osvdb.org/98445 Broken Link
http://packetstormsecurity.com/files/159629/Apache-Struts-2-Remote-Code-Execution.html ExploitThird Party AdvisoryVDB Entry
http://seclists.org/fulldisclosure/2013/Oct/96 ExploitMailing ListThird Party Advisory
http://seclists.org/oss-sec/2014/q1/89 Mailing ListThird Party Advisory
http://struts.apache.org/release/2.3.x/docs/s2-016.html Patch
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20131023-struts2 Third Party Advisory
http://www.fujitsu.com/global/support/software/security/products-f/interstage-bpm-analytics-201301e.html Broken LinkThird Party Advisory
http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html PatchThird Party Advisory
http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html PatchThird Party Advisory
http://www.securityfocus.com/bid/61189 Broken LinkThird Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/64758 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1029184 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1032916 Broken LinkThird Party AdvisoryVDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/90392 Third Party AdvisoryVDB Entry
http://archiva.apache.org/security.html Product
http://cxsecurity.com/issue/WLB-2014010087 ExploitThird Party Advisory
http://osvdb.org/98445 Broken Link
http://packetstormsecurity.com/files/159629/Apache-Struts-2-Remote-Code-Execution.html ExploitThird Party AdvisoryVDB Entry
http://seclists.org/fulldisclosure/2013/Oct/96 ExploitMailing ListThird Party Advisory
http://seclists.org/oss-sec/2014/q1/89 Mailing ListThird Party Advisory
http://struts.apache.org/release/2.3.x/docs/s2-016.html Patch
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20131023-struts2 Third Party Advisory
http://www.fujitsu.com/global/support/software/security/products-f/interstage-bpm-analytics-201301e.html Broken LinkThird Party Advisory
http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html PatchThird Party Advisory
http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html PatchThird Party Advisory
http://www.securityfocus.com/bid/61189 Broken LinkThird Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/64758 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1029184 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1032916 Broken LinkThird Party AdvisoryVDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/90392 Third Party AdvisoryVDB Entry
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-2251 US Government Resource

Track CVE-2013-2251 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-17530Apache Struts forced OGNL evaluation enables remote code executionApache Struts 2.0.0 through 2.5.25 performs forced OGNL evaluation on raw user input placed in tag attributes, allowing expression language injection…KEVEPSS 96%analysed9.8CVE-2017-9791Apache Struts 1 plugin input validation flaw enables remote code executionThe Struts 1 plugin in Apache Struts 2.1.x and 2.3.x may allow remote code execution when a malicious field value is passed in a raw message to the A…KEVEPSS 99%analysed9.8CVE-2017-5638Apache Struts 2 Jakarta Multipart parser remote code executionThe Jakarta Multipart parser in Apache Struts 2 mishandles exceptions and error messages during file-upload attempts, letting a crafted Content-Type,…KEVEPSS 100%analysed9.8CVE-2012-0391Apache Struts ExceptionDelegator OGNL injection enables remote code executionApache Struts before 2.2.3.1 evaluates parameter values as OGNL expressions in the ExceptionDelegator component during exception handling for mismatc…KEVEPSS 76%analysed8.1CVE-2018-11776Apache Struts namespace handling flaw enables remote code executionApache Struts 2.3 through 2.3.34 and 2.5 through 2.5.16 can execute remote code when alwaysSelectFullNamespace is enabled and results or url tags are…KEVEPSS 100%analysed8.1CVE-2017-9805Apache Struts REST Plugin XStream deserialization RCEThe REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an XStream instance for deseri…KEVEPSS 99%analysed7.5CVE-2006-1547Apache Struts 1 ActionForm multipart parameter denial of serviceApache Struts before 1.2.9 with BeanUtils 1.7 exposes the public getMultipartRequestHandler method through ActionForm parameter binding. A remote att…KEVEPSS 55%analysed10.0CVE-2013-4316Apache struts improper access control vulnerabilityApache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation by default, which has unknown impact and attack vectors.EPSS 8.4%

Source: NIST National Vulnerability Database (record CVE-2013-2251), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.