Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2014-0112

85
FAUCET Score

CVE-2014-0112 is a critical remote code execution vulnerability affecting Apache Struts versions prior to 2.3.20. It allows unauthenticated attackers to manipulate the ClassLoader via a crafted request due to improper access restrictions in the ParametersInterceptor, building on an incomplete fix for a previous vulnerability. With a CVSS score of 7.5 and an EPSS score indicating high exploitability, this flaw poses a significant risk. Exploit code is publicly available through Metasploit modules and ExploitDB, demonstrating its ease of exploitation. While not currently on the CISA KEV catalog, its high FAUCET Risk Score and past media coverage highlight its historical importance and potential for impact.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.0.0, < 2.3.16.2CPE matchmatch criteria
cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

7.5HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
97.91%
Probability of exploitation in next 30 days
EPSS Percentile
99.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Metasploit: Apache Struts ClassLoader Manipulation Remote Code Execution · Mar 6, 2014
ExploitDB: EDB-33142 · May 2, 2014
This CVE's current EPSS score of 0.9791 is in the 100th percentile among its peer group of 51,506 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

mavenpatch availablevia ghsa
Product: org.apache.struts:struts2-coreFixed in: 2.3.20
redhatpatch availablevia redhat_api
Product: Red Hat Fuse 7.3
View patch

Vendor Advisories (2)

mavenGHSA-prjv-jj26-wf8hhigh

ClassLoader manipulation in Apache Struts

May 14, 2022
redhatCVE-2014-0112Important

struts2: ClassLoader manipulation via request parameters

Apr 25, 2014

References

jvndb.jvn.jp / jvndb/JVNDB-2014-000045
Third Party AdvisoryVDB Entry
jvn.jp / en/jp/JVN19294237/index.html
Third Party AdvisoryVDB Entry
packetstormsecurity.com / files/127215/VMware-Security-Advisory-2014-0007.html
Third Party AdvisoryVDB Entry
access.redhat.com / errata/RHSA-2019:0910
Third Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue Tracking
cwiki.apache.org / confluence/display/WW/S2-021
PatchVendor Advisory
secunia.com / advisories/59178
Permissions Required
secunia.com / advisories/59500
Permissions Required
www-01.ibm.com / support/docview.wss
Third Party Advisory
oracle.com / technetwork/topics/security/cpuapr2015-2365600.html
Third Party Advisory
securityfocus.com / archive/1/531952/100/0/threaded
Third Party AdvisoryVDB Entry
securityfocus.com / archive/1/532549/100/0/threaded
Third Party AdvisoryVDB Entry
securityfocus.com / bid/67064
Third Party AdvisoryVDB Entry
vmware.com / security/advisories/VMSA-2014-0007.html
Third Party Advisory