Evidence dossier

CVE-2013-2251

CVE-2013-2251

83.299.5Priority evidence range
As known Jul 21, 2026, 8:13 AM UTCgen-409cbd0c

Normalized restatement

Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix.

State
PUBLISHED
Published
Jul 18, 2013
Updated
Oct 22, 2025
Evidence coverage
72%
CISA KEVCatalog member

Apply updates per vendor instructions.

FIRST EPSS100.00%

2026-07-18 · v2026.06.15 · percentile 100.0%

Source stateConflict visible

Distinct CVSS assessments remain side by side; none are averaged.

Source comparison

Who said what

CISA-ADPindependent enrichment
container

CISA ADP Vulnrichment

CVEderivative copy
container

CVE Program Container

redhatoriginal assertion
container

Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix.

CISA KEVoriginal assertion
observed_exploitation

Apache Struts Improper Input Validation Vulnerability

FIRST EPSSoriginal assertion
model_probability

Probability 0.999980000000; percentile 0.999900000000

Applicability

Cited product scope

Trace impact →
17Underlying assertions
9Canonical products
9Target assertions
8Constraint assertions

Grouped from 6 configuration nodes in this exact generation. Visual grouping does not establish asset exposure or common root cause.

Identity source boundaries
  • cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

10 scope groups

redhat · source assertedn/an/aDirect source scope
[{"status": "affected", "version": "n/a"}]
unknown
NVD CPE · APPLICATIONapachearchivaVulnerable target · 3 assertions
Any version (unconstrained) (>= 1.3, < 1.3.8); Version 1.2; Version 1.2.2Canonical identity product-6cabc65111b21a76e20244fab9a2d5eb0762375d4646ceb4e2751224f079d8eflinked exact
supported
Inspect 3 returned assertions
  1. cpe:2.3:a:apache:archiva:1.2.2:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    cccf9a1c-7091-4d72-8afc-5373f45ff7d5
  2. cpe:2.3:a:apache:archiva:*:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 1.3; through excluding 1.3.8
    Match ID
    3a10fb76-761d-4411-b6a8-b1ad5c133071
  3. cpe:2.3:a:apache:archiva:1.2:-:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f0e0751c-e0bd-4c33-a541-c6fc67ce6663
NVD CPE · APPLICATIONapachestrutsVulnerable target · 1 assertions
Any version (unconstrained) (>= 2.0.0, <= 2.3.15)Canonical identity product-9cd0052bcd831ad951c3a83f953006d77d3ff2278903b02b620cad9fb02389e0linked exact
supported
Inspect 1 returned assertions
  1. cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 2.0.0; through including 2.3.15
    Match ID
    61c63f76-5afe-4d2f-b81c-d3476c165227
NVD CPE · APPLICATIONfujitsuinterstage_business_process_manager_analyticsVulnerable target · 2 assertions
Version 12.0; Version 12.1Canonical identity product-4fc9b42ec477e57914a3d4cf39e18d151300ec6ed4569d59396c646f85bb8190linked exact
supported
Inspect 2 returned assertions
  1. cpe:2.3:a:fujitsu:interstage_business_process_manager_analytics:12.0:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6d24308c-eefb-477d-a88c-95e76cac8ad7
  2. cpe:2.3:a:fujitsu:interstage_business_process_manager_analytics:12.1:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2825c5b3-6495-43fe-9d87-750c8b9b25ec
NVD CPE · OPERATING SYSTEMmicrosoftwindows_server_2003Environmental constraint · 2 assertions
Version not applicableCanonical identity product-21c8a455c6651c09ac3fd0874c5219dd6081913f4835e8de22662b3821fec60blinked exact
constrained
Inspect 2 returned assertions
  1. cpe:2.3:o:microsoft:windows_server_2003:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Environmental constraint
    Configuration
    2 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e3527f41-a6ed-437d-9833-458a2c60c2a3
  2. cpe:2.3:o:microsoft:windows_server_2003:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e3527f41-a6ed-437d-9833-458a2c60c2a3
NVD CPE · OPERATING SYSTEMmicrosoftwindows_server_2008Environmental constraint · 2 assertions
Version not applicableCanonical identity product-217b1ab3d25f361a639824f86753d418b35aa2a816ee370bb71b5d1dd883d87alinked exact
constrained
Inspect 2 returned assertions
  1. cpe:2.3:o:microsoft:windows_server_2008:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    32623d48-7000-4c7d-823f-7d2a9841d88c
  2. cpe:2.3:o:microsoft:windows_server_2008:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Environmental constraint
    Configuration
    2 · node/1 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    32623d48-7000-4c7d-823f-7d2a9841d88c
NVD CPE · OPERATING SYSTEMmicrosoftwindows_server_2012Environmental constraint · 1 assertions
Version not applicableCanonical identity product-5a80416e92fed0cddbb3d4f3840218b448dee11159824ad25a0353da566963felinked exact
constrained
Inspect 1 returned assertions
  1. cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Environmental constraint
    Configuration
    2 · node/1 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a7df96f8-ba6a-4780-9ca3-f719b3f81074
NVD CPE · APPLICATIONoraclesiebel_apps_-_e-billingVulnerable target · 3 assertions
Version 6.1; Version 6.1.1; Version 6.2Canonical identity product-46749c1a95bbfedc3a8f110454019bfeb2380dd856211bdb2d55b8396135bd13linked exact
supported
Inspect 3 returned assertions
  1. cpe:2.3:a:oracle:siebel_apps_-_e-billing:6.1.1:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    51d5bac9-e5b1-4a19-8b87-0ca2fa046d27
  2. cpe:2.3:a:oracle:siebel_apps_-_e-billing:6.2:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5f0dbe55-667b-45ef-8c3a-9c7aa33adde6
  3. cpe:2.3:a:oracle:siebel_apps_-_e-billing:6.1:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    109a2a5d-d631-472f-aa80-2e1d707943f5
NVD CPE · OPERATING SYSTEMoraclesolarisEnvironmental constraint · 1 assertions
Version 11Canonical identity product-539219b1ee59962407ed68b1ceec26467cc69e69724392149215aa94f97bef9blinked exact
constrained
Inspect 1 returned assertions
  1. cpe:2.3:o:oracle:solaris:11:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Environmental constraint
    Configuration
    2 · node/1 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8e8c192b-8044-4bf9-9f1f-57371fc0e8fd
NVD CPE · OPERATING SYSTEMredhatenterprise_linuxEnvironmental constraint · 2 assertions
Any version (unconstrained) (>= 5.0, <= 6.10)Canonical identity product-ec20120153af988d42a6a2dfd3cdd9595762b35581f66014faaa4f85d8f844eelinked exact
constrained
Inspect 2 returned assertions
  1. cpe:2.3:o:redhat:enterprise_linux:*:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Environmental constraint
    Configuration
    2 · node/1 · match 4
    Logic
    OR
    Version bounds
    from including 5.0; through including 6.10
    Match ID
    8d0c7ab6-1b62-49e3-99f8-53dd9329264e
  2. cpe:2.3:o:redhat:enterprise_linux:*:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 2
    Logic
    OR
    Version bounds
    from including 5.0; through including 6.10
    Match ID
    8d0c7ab6-1b62-49e3-99f8-53dd9329264e

Assessments

CVSS by origin

9.8
nvd@nist.govCVSS 3.1 · role PrimaryCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.3
nvd@nist.govCVSS 2.0 · role PrimaryAV:N/AC:M/Au:N/C:C/I:C/A:C
9.8
134c704f-9b21-4f2e-91b3-4a467353bcc0CVSS 3.1 · role SecondaryCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.8
CISA-ADPCVSS 3.1 · role unknownCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Limitations and unknowns

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; unresolved scope remains unknown.
  • NVD-carried upstream facts remain derivative and are not independent corroboration.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Factor D remains unknown because WC-03 has not converted canonical CPE mappings into generation-bound mapping obligations; canonical identity alone does not score applicability.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.