CVE-2012-4387
published 2012-09-05CVE-2012-4387: Apache Struts 2.0.0 through 2.3.4 allows remote attackers to cause a denial of service (CPU consumption) via a long parameter name, which is processed as an…
PriorityP423medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
8.07%
94.2th percentile
Apache Struts 2.0.0 through 2.3.4 allows remote attackers to cause a denial of service (CPU consumption) via a long parameter name, which is processed as an OGNL expression.
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Denial of service in Apache Struts
ghsa·2022-05-17
CVE-2012-4387 [MEDIUM] Denial of service in Apache Struts
Denial of service in Apache Struts
Apache Struts 2.0.0 through 2.3.4 allows remote attackers to cause a denial of service (CPU consumption) via a long parameter name, which is processed as an OGNL expression.
OSV
Denial of service in Apache Struts
osv·2022-05-17
CVE-2012-4387 [MEDIUM] Denial of service in Apache Struts
Denial of service in Apache Struts
Apache Struts 2.0.0 through 2.3.4 allows remote attackers to cause a denial of service (CPU consumption) via a long parameter name, which is processed as an OGNL expression.
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/50420http://struts.apache.org/2.x/docs/s2-011.htmlhttp://www.openwall.com/lists/oss-security/2012/09/01/4http://www.openwall.com/lists/oss-security/2012/09/01/5http://www.securityfocus.com/bid/55346https://exchange.xforce.ibmcloud.com/vulnerabilities/78183https://issues.apache.org/jira/browse/WW-3860http://secunia.com/advisories/50420http://struts.apache.org/2.x/docs/s2-011.htmlhttp://www.openwall.com/lists/oss-security/2012/09/01/4http://www.openwall.com/lists/oss-security/2012/09/01/5http://www.securityfocus.com/bid/55346https://exchange.xforce.ibmcloud.com/vulnerabilities/78183https://issues.apache.org/jira/browse/WW-3860
2012-09-05
Published