Vulnerability record · CVE-2013-2251 · published 20 July 2013
CVE-2013-2251: Apache Struts 2 OGNL injection enables remote code execution
Apache · Archiva
Apache Struts 2.0.0 through 2.3.15 fails to properly validate request parameters, allowing crafted action:, redirect:, or redirectAction: prefixes to inject and execute arbitrary OGNL expressions. Because OGNL can invoke Java methods, this is effectively unauthenticated remote code execution on affected Struts 2 deployments. The flaw is old but still widely exploited and appears in CISA's Known Exploited Vulnerabilities catalog.
Description
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable remote code execution with a near-maximum EPSS score and active inclusion in CISA KEV makes this an urgent patch-first issue.
What it is
Apache Struts 2.0.0 through 2.3.15 fails to properly validate request parameters, allowing crafted action:, redirect:, or redirectAction: prefixes to inject and execute arbitrary OGNL expressions. Because OGNL can invoke Java methods, this is effectively unauthenticated remote code execution on affected Struts 2 deployments. The flaw is old but still widely exploited and appears in CISA's Known Exploited Vulnerabilities catalog.
Impact
An unauthenticated remote attacker can execute arbitrary code with the privileges of the application server, leading to full host compromise, data theft, and lateral movement. No user interaction or valid credentials are required.
Attack surface
Reached over the network via HTTP requests to a Struts 2 application, typically by supplying a malicious parameter value with an action:, redirect:, or redirectAction: prefix. The CVSS vector (AV:N/AC:L/PR:N/UI:N) confirms no authentication and no user interaction are needed.
Exploitation
CISA added it to KEV on 2022-03-25 with a 2022-04-15 remediation due date, and EPSS is near 1.0 (0.99998, 99.99th percentile). Multiple public exploit references exist, so exploitation is trivial and ongoing.
What to do
- Upgrade Apache Struts 2 to a version later than 2.3.15 per the S2-016 advisory; patch is the only reliable fix.
- If immediate upgrade is impossible, apply vendor mitigations and restrict or block requests containing action:, redirect:, or redirectAction: parameter prefixes at the WAF or reverse proxy.
- Inventory all applications and embedded frameworks that bundle Struts 2 (including Archiva, Oracle, and Fujitsu products listed) and confirm each is patched.
- Remove or isolate internet-facing Struts 2 instances that cannot be upgraded until they are remediated.
Detection
- Search web and proxy logs for request parameters containing action:, redirect:, or redirectAction: prefixes, especially with OGNL syntax such as @ or # expressions.
- Alert on outbound connections or child processes spawned by the Java application server that are unusual for the app.
- Monitor for known Struts 2 exploit payload patterns in HTTP request bodies and query strings using IDS/WAF signatures.
- Review application server logs for OGNL parsing errors or unexpected class loading around request handling.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2013-2251 to the Known Exploited Vulnerabilities catalog on 25 March 2022 as "Apache Struts Improper Input Validation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 April 2022.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2013-2251 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-2251), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.