Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix.
History

Wed, 22 Apr 2026 14:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:h:fujitsu:gp-s:-:*:*:*:*:*:*:*
cpe:2.3:h:fujitsu:gp5000:-:*:*:*:*:*:*:*
cpe:2.3:h:fujitsu:gp7000f:-:*:*:*:*:*:*:*
cpe:2.3:h:fujitsu:primepower:-:*:*:*:*:*:*:*
cpe:2.3:h:fujitsu:primergy:-:*:*:*:*:*:*:*
cpe:2.3:h:fujitsu:sparc:-:*:*:*:*:*:*:*
cpe:2.3:o:fujitsu:gp-s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:fujitsu:gp5000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:fujitsu:gp7000f_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:fujitsu:primepower_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:fujitsu:primergy_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:fujitsu:sparc_firmware:-:*:*:*:*:*:*:*
Vendors & Products Fujitsu gp-s
Fujitsu gp-s Firmware
Fujitsu gp5000
Fujitsu gp5000 Firmware
Fujitsu gp7000f
Fujitsu gp7000f Firmware
Fujitsu primepower
Fujitsu primepower Firmware
Fujitsu primergy
Fujitsu primergy Firmware
Fujitsu sparc
Fujitsu sparc Firmware

Wed, 22 Oct 2025 01:30:00 +0000


Tue, 21 Oct 2025 20:30:00 +0000


Tue, 21 Oct 2025 19:30:00 +0000


Fri, 07 Feb 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2022-03-25'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 27 Nov 2024 16:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:oracle:solaris:11:*:*:*:*:*:*:* cpe:2.3:o:oracle:solaris:11:*:*:*:*:*:*:*

Tue, 13 Aug 2024 23:45:00 +0000

Type Values Removed Values Added
References

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2013-07-18T01:00:00.000Z

Updated: 2025-10-22T00:05:41.250Z

Reserved: 2013-02-19T00:00:00.000Z

Link: CVE-2013-2251

cve-icon Vulnrichment

Updated: 2024-08-06T15:27:41.156Z

cve-icon NVD

Status : Analyzed

Published: 2013-07-20T03:37:30.737

Modified: 2026-04-22T14:39:34.350

Link: CVE-2013-2251

cve-icon Redhat

Severity : Important

Publid Date: 2013-07-14T00:00:00Z

Links: CVE-2013-2251 - Bugzilla