← Vulnerability feed

Vulnerability record · CVE-2019-0230 · published 14 September 2020

CVE-2019-0230: Apache Struts 2 forced double OGNL evaluation enables remote code execution

Apache · Struts

Apache Struts versions 2.0.0 through 2.5.20 force double OGNL evaluation when tag attributes are evaluated on raw user input, which can lead to remote code execution. The flaw is network-reachable with no privileges or user interaction required, so any exposed Struts application using affected tag attributes is a candidate target.

9.8 CVSS 3.1 Critical EPSS 97% · top 0.1% CWE-1321 · Prototype pollution
9.8CVSS 3.1 base score, v2 7.5
97%EPSS exploitation probability, 30 days
NoNot in CISA KEV
5Affected product versions listed by NVD
18References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8 with network-only, unauthenticated access and public exploit references makes this a top remediation priority despite no KEV listing.

What it is

Apache Struts versions 2.0.0 through 2.5.20 force double OGNL evaluation when tag attributes are evaluated on raw user input, which can lead to remote code execution. The flaw is network-reachable with no privileges or user interaction required, so any exposed Struts application using affected tag attributes is a candidate target.

Impact

An unauthenticated attacker can execute arbitrary code in the context of the application server, leading to full compromise of confidentiality, integrity and availability.

Attack surface

Reached over the network via HTTP requests that place crafted input into Struts tag attributes subject to forced double OGNL evaluation. No authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).

Exploitation

Not listed in CISA KEV, but EPSS is 0.97399 (99.895th percentile) and multiple references are tagged Exploit, indicating public exploit material exists.

What to do

  • Upgrade Apache Struts to a version above 2.5.20 (see the S2-059 vendor advisory for the fixed release).
  • Apply the Oracle CPU patches (Jan 2021, Apr 2021, Oct 2021) for affected Oracle products that bundle Struts.
  • Avoid passing raw, unvalidated user input into Struts tag attributes; validate and encode input at the boundary.
  • If immediate upgrade is not possible, restrict network access to Struts application endpoints and monitor for OGNL-style payloads.
  • Inventory applications and dependencies for Struts 2.0.0 through 2.5.20, including third-party products that embed it.

Detection

  • Inspect HTTP request parameters and headers for OGNL expression syntax (e.g. %{, ${, #, @) reaching Struts tag attributes.
  • Monitor web and application logs for unexpected errors or stack traces from OGNL evaluation.
  • Alert on outbound connections or process spawning from the Java application server that are not part of normal behavior.
  • Use WAF or IDS signatures for known Struts OGNL exploitation patterns and review hits against affected endpoints.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/160108/Apache-Struts-2.5.20-Double-OGNL-Evaluation.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/160721/Apache-Struts-2-Forced-Multi-OGNL-Evaluation.html ExploitThird Party AdvisoryVDB Entry
https://cwiki.apache.org/confluence/display/ww/s2-059 Vendor Advisory
https://launchpad.support.sap.com/#/notes/2982840 Permissions Required
https://lists.apache.org/thread.html/r1125f3044a0946d1e7e6f125a6170b58d413ebd4a95157e4608041c7%40%3Cannounce.apache.org%
https://lists.apache.org/thread.html/r90890afea72a9571d666820b2fe5942a0a5f86be406fa31da3dd0922%40%3Cannounce.apache.org%
https://www.oracle.com/security-alerts/cpuApr2021.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpujan2021.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpuoct2021.html PatchThird Party Advisory
http://packetstormsecurity.com/files/160108/Apache-Struts-2.5.20-Double-OGNL-Evaluation.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/160721/Apache-Struts-2-Forced-Multi-OGNL-Evaluation.html ExploitThird Party AdvisoryVDB Entry
https://cwiki.apache.org/confluence/display/ww/s2-059 Vendor Advisory
https://launchpad.support.sap.com/#/notes/2982840 Permissions Required
https://lists.apache.org/thread.html/r1125f3044a0946d1e7e6f125a6170b58d413ebd4a95157e4608041c7%40%3Cannounce.apache.org%
https://lists.apache.org/thread.html/r90890afea72a9571d666820b2fe5942a0a5f86be406fa31da3dd0922%40%3Cannounce.apache.org%
https://www.oracle.com/security-alerts/cpuApr2021.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpujan2021.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpuoct2021.html PatchThird Party Advisory

Track CVE-2019-0230 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-22965Spring Framework data binding remote code execution (Spring4Shell)Spring MVC and Spring WebFlux applications on JDK 9+ can be exploited through data binding to achieve remote code execution. The known exploit path r…KEVEPSS 100%analysed9.8CVE-2022-22963Spring Cloud Function routing expression SpEL injection RCESpring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions allow a user to supply a crafted SpEL expression as a routing-expression w…KEVEPSS 100%analysed9.8CVE-2020-17530Apache Struts forced OGNL evaluation enables remote code executionApache Struts 2.0.0 through 2.5.25 performs forced OGNL evaluation on raw user input placed in tag attributes, allowing expression language injection…KEVEPSS 96%analysed9.8CVE-2020-1938Apache Tomcat AJP connector file read and JSP execution flawApache Tomcat shipped an AJP Connector enabled by default that listened on all configured IP addresses, and Tomcat treats AJP connections as more tru…KEVEPSS 99%analysed9.8CVE-2017-9791Apache Struts 1 plugin input validation flaw enables remote code executionThe Struts 1 plugin in Apache Struts 2.1.x and 2.3.x may allow remote code execution when a malicious field value is passed in a raw message to the A…KEVEPSS 99%analysed9.8CVE-2016-8735Apache Tomcat JmxRemoteLifecycleListener remote code executionApache Tomcat's JmxRemoteLifecycleListener was not updated to match the Oracle CVE-2016-3427 credential-type fix, leaving a deserialization weakness …KEVEPSS 90%analysed9.8CVE-2017-5638Apache Struts 2 Jakarta Multipart parser remote code executionThe Jakarta Multipart parser in Apache Struts 2 mishandles exceptions and error messages during file-upload attempts, letting a crafted Content-Type,…KEVEPSS 100%analysed9.8CVE-2013-2251Apache Struts 2 OGNL injection enables remote code executionApache Struts 2.0.0 through 2.3.15 fails to properly validate request parameters, allowing crafted action:, redirect:, or redirectAction: prefixes to…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2019-0230), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.