CVE-2013-2134 - CVSS 9.3
CVE-2013-2134
Published Date:16 July, 2013CWE-94
Last modified:16 June, 2026
Link: CVE-2013-2134
NVD: CVE-2013-2134
UBUNTU: CVE-2013-2134
REDHAT: CVE-2013-2134
EUVD: EUVD-2022-3996
Last modified:16 June, 2026
Link: CVE-2013-2134
NVD: CVE-2013-2134
UBUNTU: CVE-2013-2134
REDHAT: CVE-2013-2134
EUVD: EUVD-2022-3996
Description
Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted action name that is not properly handled during wildcard matching, a different vulnerability than CVE-2013-2135.
CVSS Base Score
BASE
9.3
High
CVSS scores for CVE-2013-2134
CVSS v2 : 9.3 HIGH
| Access Vector | Network |
| Access Complexity | Medium |
| Authentication | None |
| Confidentiality Impact | Complete |
| Integrity Impact | Complete |
| Availability Impact | Complete |
Threat Intelligence
- Has Public Exploit: Yes
- CISA KEV Release Date: N/A
- CISA KEV Due Date: N/A
- CISA KEV Required Action: N/A
Exploit Prediction in the next 30 days
70%
EPSS
Likely Exploited Vulnerabilities Probability
100%
LEV
Common Weakness Enumeration for CVE-2013-2134
CWE-94 : Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Products affected by CVE-2013-2134
Running on:
struts
cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:*
Version Range:
from 2.0.0 (including)up to 2.3.14.3 (excluding)
