CVE-2014-0094
5.0
CVSS v2.0 Base Score
93.13%
HIGH RiskEPSS (100th percentile)
NVD-CWE-noinfo
The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via the class parameter, which is passed to the getClass method.
Published: 3/11/2014
Modified: 5/6/2026
Vulnerability Summary
CVSS v2 Score
5
AV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS Score (Exploitation Probability)
93.13%HIGH Exploitation Risk
100th percentile
This vulnerability has a 93.13% probability of being exploited in the next 30 days, ranking higher than 100% of all scored CVEs.
CWE Classification
NVD-CWE-noinfo