Vulnerability record · CVE-2014-0094 · published 11 March 2014
CVE-2014-0094: Apache Struts ParametersInterceptor ClassLoader manipulation via class parameter
Apache · Struts
The ParametersInterceptor in Apache Struts before 2.3.16.2 passes the 'class' parameter to the getClass method, letting remote attackers manipulate the ClassLoader. This is a class-loading/integrity flaw in a widely deployed web framework, and the record gives no further detail on the exact manipulation or its end effect.
Description
The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via the class parameter, which is passed to the getClass method.
AV:N/AC:L/Au:N/C:N/I:P/A:N
Automated analysis
high priorityThe flaw is remotely reachable without authentication in a widely deployed framework and has an extremely high EPSS score, though the record does not confirm code execution or in-the-wild exploitation.
What it is
The ParametersInterceptor in Apache Struts before 2.3.16.2 passes the 'class' parameter to the getClass method, letting remote attackers manipulate the ClassLoader. This is a class-loading/integrity flaw in a widely deployed web framework, and the record gives no further detail on the exact manipulation or its end effect.
Impact
An attacker can influence ClassLoader behavior through a request parameter, giving a remote, unauthenticated party a foothold for further class-loading abuse. The record does not state whether code execution is achievable, so the practical end impact is not fully defined.
Attack surface
Reachable over the network via HTTP requests to a Struts application, with no authentication required per the CVSS vector (AV:N/AC:L/Au:N). No user interaction is indicated.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high (0.99524, 99.9th percentile), indicating strong predicted exploitation activity; references are advisories only and do not confirm in-the-wild exploitation.
What to do
- Upgrade Apache Struts to 2.3.16.2 or later, which is the fixed version named in the record.
- If immediate upgrade is not possible, apply the vendor guidance in the S2-020 advisory for the affected Struts release line.
- Restrict or filter request parameters named 'class' at the web tier or WAF as a stopgap.
- Inventory applications and third-party products embedding Struts (the references list IBM, Oracle, VMware, Huawei and Konakart advisories) and patch those bundled versions.
- Retire or isolate end-of-life Struts deployments that cannot be upgraded.
Detection
- Search web and proxy logs for requests containing a 'class' parameter, especially unusual or fully qualified class names.
- Alert on Struts parameter-parsing errors or ClassLoader-related exceptions in application logs.
- Monitor for unexpected class loading or file writes in the application server process.
- Correlate outbound or post-request behavior from the Struts host for signs of follow-on exploitation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2014-0094 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-0094), CISA KEV, FIRST EPSS (scores of 2026-09-22). This page is refreshed as NVD updates the record.