Security Advisory
CVE-2014-0094
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via the class parameter, which is passed to the getClass method.