SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2017-9805

Apache Struts Deserialization of Untrusted Data Vulnerability

KEVHIGH 8.1EPSS 99.4%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 3 May 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.

CVSS 3.1
8.1 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
99.40% probability · 100th percentile
CISA KEV
Listed 3 November 2021 · due 3 May 2022
Weakness
CWE-502
Affected
apache/struts · cisco/digital media manager · cisco/hosted collaboration solution · cisco/media experience engine · cisco/network performance analysis · cisco/video distribution suite for internet streaming · netapp/oncommand balance
Source
security@apache.org

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2017-9805

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.