NA
CVSSv3

CVE-2011-5057

CVSSv4: NA | CVSSv3: NA | CVSSv2: 5 | VMScore: 600 | EPSS: 0.50546 | KEV: Not Included
Published: 08/01/2012 Updated: 11/04/2025

Vulnerability Summary

Apache Struts 2.3.1.2 and previous versions, 2.3.19-2.3.23, provides interfaces that do not properly restrict access to collections such as the session and request collections, which might allow remote malicious users to modify run-time data values via a crafted parameter to an application that implements an affected interface, as demonstrated by the SessionAware, RequestAware, ApplicationAware, ServletRequestAware, ServletResponseAware, and ParameterAware interfaces. NOTE: the vendor disputes the significance of this report because of an "easy work-around in existing apps by configuring the interceptor."

Vulnerable Product Search on Vulmon Subscribe to Product

apache struts

Exploits

source: wwwsecurityfocuscom/bid/50940/info Apache Struts is prone to a security-bypass vulnerability that allows session tampering Successful attacks will allow attackers to bypass security restrictions and gain unauthorized access Apache Struts versions 209 and 2181 are vulnerable; other versions may also be affected w ...