Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2012-0394

85
FAUCET Score

CVE-2012-0394 is a remote code execution vulnerability affecting Apache Struts before version 2.3.1.1, specifically within the DebuggingInterceptor component when developer mode is enabled. This vulnerability carries a CVSS score of 6.8, indicating a medium severity, and allows unauthenticated attackers to execute arbitrary commands with partial impact on confidentiality, integrity, and availability. While the vendor initially downplayed its security implications, exploit code, including Metasploit modules and Nuclei templates, is publicly available. Despite the availability of exploits and a high EPSS score, there is no evidence of active exploitation, and it has received minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.0.0, <= 2.3.17CPE matchmatch criteria
cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

6.8MEDIUM

AV:N/AC:M/Au:N/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
74.41%
Probability of exploitation in next 30 days
EPSS Percentile
99.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
Metasploit: Apache Struts 2 Developer Mode OGNL Execution · Jan 6, 2012
Nuclei: CVE-2012-0394 · Nov 14, 2022
ExploitDB: EDB-31434 · Feb 5, 2014
This CVE's current EPSS score of 0.7440 is in the 100th percentile among its peer group of 19,955 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

mavenpatch availablevia ghsa
Product: org.apache.struts.xwork:xwork-coreFixed in: 2.3.18

Vendor Advisories (2)

mavenGHSA-hmvj-gc9q-mg9pmedium

Apache Struts's DebuggingInterceptor component allows remote code execution in developer mode

May 4, 2022
redhatCVE-2012-0394Moderate

struts2: remote execution of arbitrary commands when developer mode is used

Dec 25, 2011

References

archives.neohapsis.com / archives/bugtraq/2012-01/0031.html
Broken Link
struts.apache.org / 2.x/docs/s2-008.html
Vendor Advisory
struts.apache.org / 2.x/docs/version-notes-2311.html
Release NotesVendor Advisory
sec-consult.com / files/20120104-0_Apache_Struts2_Multiple_Critical_Vulnerabilities.txt
Broken Link
exploit-db.com / exploits/18329
ExploitThird Party AdvisoryVDB Entry
exploit-db.com / exploits/31434
ExploitThird Party AdvisoryVDB Entry
osvdb.org / 78276
Broken Link