CVE-2017-9805 KEV EXPLOIT
8.1
HIGH · CVSS 3.1 · EPSS 99.4% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2022-05-03.
Description
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.
Scoring
| CVSS | 8.1 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 99.4% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-502 |
| On CISA KEV | yes — remediate by 2022-05-03 |
| Public exploit | yes |
| Published | 2017-09-15 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Apache Struts Deserialization of Untrusted Data Vulnerability |
|---|---|
| Added | 2021-11-03 |
| Due | 2022-05-03 |
| Vendor / product | Apache / Struts |
| Ransomware use | none reported |
Affected (7)
| Vendor | Product |
|---|---|
| apache | struts |
| cisco | digital media manager |
| cisco | hosted collaboration solution |
| cisco | media experience engine |
| cisco | network performance analysis |
| cisco | video distribution suite for internet streaming |
| netapp | oncommand balance |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Apache Struts 2.5 < 2.5.12 - REST Plugin XStream Remote Code Execution | 2017-09-06 |
References
- http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-9805-3889403.html
- http://www.securityfocus.com/bid/100609
- http://www.securitytracker.com/id/1039263
- https://blogs.apache.org/foundation/entry/apache-struts-statement-on-equifax
- https://bugzilla.redhat.com/show_bug.cgi?id=1488482
- https://cwiki.apache.org/confluence/display/WW/S2-052
- https://lgtm.com/blog/apache_struts_CVE-2017-9805
- https://security.netapp.com/advisory/ntap-20170907-0001/
- https://struts.apache.org/docs/s2-052.html
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170907-struts2
- https://www.exploit-db.com/exploits/42627/
- https://www.kb.cert.org/vuls/id/112992
- http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-9805-3889403.html
- http://www.securityfocus.com/bid/100609
- http://www.securitytracker.com/id/1039263
- https://blogs.apache.org/foundation/entry/apache-struts-statement-on-equifax
- https://bugzilla.redhat.com/show_bug.cgi?id=1488482
- https://cwiki.apache.org/confluence/display/WW/S2-052
- https://lgtm.com/blog/apache_struts_CVE-2017-9805
- https://security.netapp.com/advisory/ntap-20170907-0001/
→ the Explorer · watch your stack · NVD