← Back

CVE-2011-2088

nvd nist
Published: May 13, 2011Modified: Apr 29, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

XWork 2.2.1 in Apache Struts 2.2.1, and OpenSymphony XWork in OpenSymphony WebWork, allows remote attackers to obtain potentially sensitive information about internal Java class paths via vectors involving an s:submit element and a nonexistent method, a different vulnerability than CVE-2011-1772.3.

Affected (4)

1 product
Struts
2 products
Xwork
Webwork
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Version 2.2.1
Version 2.2.1
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
All versions
All versions

Timeline

No history available yet.