Input validation error in Apache Struts - CVE-2012-0838
Published: April 17, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to Apache Struts evaluates a string as an OGNL expression during the handling of a conversion error. A remote attacker can pass specially crafted input to the application to modify run-time data values, and consequently execute arbitrary code, via invalid input to a field.
Affected software
Call Center for Commerce
IBM Sterling Order Management
How to mitigate CVE-2012-0838
Call Center for Commerce - update to 10.0.12
IBM Sterling Order Management - update to 10.0.2403.1