CVE-2017-5638
Apache Struts Remote Code Execution Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 3 May 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header, as exploited in the wild in March 2017 with a Content-Type header containing a #cmd= string.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 100.00% probability · 100th percentile
- CISA KEV
- Listed 3 November 2021 · due 3 May 2022 · used in ransomware campaigns
- Weakness
- CWE-755
- Affected
- apache/struts · ibm/storwize v3500 firmware · ibm/storwize v5000 firmware · ibm/storwize v7000 firmware · lenovo/storage v5030 firmware · hp/server automation · oracle/weblogic server · arubanetworks/clearpass policy manager · netapp/oncommand balance
- Source
- security@apache.org
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2017-5638
References
- http://blog.talosintelligence.com/2017/03/apache-0-day-exploited.htmlExploit, Third Party Advisory
- http://blog.trendmicro.com/trendlabs-security-intelligence/cve-2017-5638-apache-struts-vulnerability-remote-code-execution/Exploit, Third Party Advisory
- http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2017-002.txtThird Party Advisory
- http://www.eweek.com/security/apache-struts-vulnerability-under-attack.htmlPress/Media Coverage, Third Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.htmlPatch, Third Party Advisory
- http://www.securityfocus.com/bid/96729Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037973Broken Link, Third Party Advisory, VDB Entry
- https://arstechnica.com/security/2017/03/critical-vulnerability-under-massive-attack-imperils-high-impact-sites/Exploit, Press/Media Coverage
- https://cwiki.apache.org/confluence/display/WW/S2-045Mitigation, Vendor Advisory
- https://cwiki.apache.org/confluence/display/WW/S2-046Mitigation, Vendor Advisory
- https://exploit-db.com/exploits/41570Exploit, Third Party Advisory, VDB Entry
- https://git1-us-west.apache.org/repos/asf?p=struts.git%3Ba=commit%3Bh=352306493971e7d5a756d61780d57a76eb1f519aBroken Link
- https://git1-us-west.apache.org/repos/asf?p=struts.git%3Ba=commit%3Bh=6b8272ce47160036ed120a48345d9aa884477228Broken Link
- https://github.com/mazen160/struts-pwnExploit
- https://github.com/rapid7/metasploit-framework/issues/8064Exploit, Issue Tracking
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbgn03733en_usBroken Link
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbgn03749en_usThird Party Advisory
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03723en_usThird Party Advisory
- https://isc.sans.edu/diary/22169Exploit, Third Party Advisory
- https://lists.apache.org/thread.html/r1125f3044a0946d1e7e6f125a6170b58d413ebd4a95157e4608041c7%40%3Cannounce.apache.org%3EMailing List
- https://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c%40%3Cannounce.apache.org%3EMailing List
- https://lists.apache.org/thread.html/r90890afea72a9571d666820b2fe5942a0a5f86be406fa31da3dd0922%40%3Cannounce.apache.org%3EMailing List
- https://nmap.org/nsedoc/scripts/http-vuln-cve2017-5638.htmlExploit, Third Party Advisory
- https://packetstormsecurity.com/files/141494/S2-45-poc.py.txtBroken Link, Exploit, Third Party Advisory, VDB Entry
- https://security.netapp.com/advisory/ntap-20170310-0001/Third Party Advisory
- https://struts.apache.org/docs/s2-045.htmlMitigation, Vendor Advisory
- https://struts.apache.org/docs/s2-046.htmlMitigation, Vendor Advisory
- https://support.lenovo.com/us/en/product_security/len-14200Third Party Advisory
- https://twitter.com/theog150/status/841146956135124993Broken Link, Third Party Advisory
- https://www.exploit-db.com/exploits/41614/Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.