Apache Commons BeanUtils fails to suppress the class property during JavaBean property binding, allowing attacker-controlled parameters to expose and manipulate ClassLoader functionality. In Apache Struts 1, the ActionForm class parameter maps directly to getClass(), providing access to the application's ClassLoader. Affected software includes Apache Struts 1.x through 1.3.10, distributed with Commons BeanUtils 1.8.0, and other products using Commons BeanUtils through 1.9.2. Exploitation can lead to remote arbitrary code execution under certain deployment-dependent conditions.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module: 'struts_code_exec_classloader.rb', which exploits remote code execution vulnerabilities in Apache Struts 1.x (<= 1.3.10) and 2.x (< 2.3.16.2) via class loader manipulation. The exploit abuses the 'class' parameter in HTTP requests to manipulate the Java ClassLoader, allowing arbitrary code execution. The module supports both Java and native payloads, delivering them as JSP files or executables depending on the target platform (Linux, Windows, or Java). For certain Windows targets, it can leverage SMB to deliver the payload. The module is highly weaponized, supporting customizable payloads and automatic cleanup. The main attack vector is network-based, targeting HTTP endpoints exposed by vulnerable Struts applications. The repository is structured as a single Ruby file compatible with the Metasploit framework, and all exploit logic is contained within this file.
This repository is a proof-of-concept (PoC) for exploiting CVE-2014-0114, a critical vulnerability in Apache Struts 1.x that allows attackers to manipulate Java bean properties via HTTP parameters. The project is structured as a simple Struts 1 web application with a login form (LoginForm, LoginAction) and several JSP pages, including a dedicated 'struts-tester.jsp' for exploring bean property traversal. The README provides detailed background on the vulnerability, including exploitation techniques for both remote code execution (RCE) on Tomcat (by writing a malicious JSP) and denial of service (DoS) on JBoss/Wildfly (by triggering resource exhaustion through recursive property access). The main attack vector is network-based, targeting HTTP endpoints such as '/Login.do' and '/struts-tester.jsp', where crafted parameters can traverse and manipulate internal Java objects. The repository includes references to related CVEs, external presentations, and a Metasploit module. The code is primarily Java and JSP, with configuration in XML and properties files. This PoC is intended for security research and demonstration of the Struts 1 class property manipulation vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote code execution vulnerability in Apache Commons BeanUtils through version 1.9.2, including its use in Apache Struts 1.x through 1.3.10. Failure to suppress the class property permits ClassLoader manipulation. The advisory recommends updating the library and related packages to version 1.9.3+echo.1 or later.
A Struts 1 class-level property injection flaw that allows traversal through multipartRequestHandler into Jetty internals, enabling unauthenticated rewriting of authentication filter mappings on SonicWall SMA 1000 appliances.
A request-parameter class-loader manipulation vulnerability in Apache Struts 1.
A remote code execution vulnerability in Apache Struts 1 ActionForm handling. Access to the class parameter can enable manipulation of an application server's ClassLoader under certain conditions.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.