VulnerabilityAnalyzed
CVE-2017-9805
Apache Struts Deserialization of Untrusted Data Vulnerability
KEVHIGH 8.1EPSS 99.4%
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 3 May 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.
- CVSS 3.1
- 8.1 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 99.40% probability · 100th percentile
- CISA KEV
- Listed 3 November 2021 · due 3 May 2022
- Weakness
- CWE-502
- Affected
- apache/struts · cisco/digital media manager · cisco/hosted collaboration solution · cisco/media experience engine · cisco/network performance analysis · cisco/video distribution suite for internet streaming · netapp/oncommand balance
- Source
- security@apache.org
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2017-9805
References
- http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-9805-3889403.htmlPatch, Third Party Advisory
- http://www.securityfocus.com/bid/100609Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039263Broken Link, Third Party Advisory, VDB Entry
- https://blogs.apache.org/foundation/entry/apache-struts-statement-on-equifaxVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1488482Issue Tracking, Third Party Advisory, VDB Entry
- https://cwiki.apache.org/confluence/display/WW/S2-052Mitigation, Vendor Advisory
- https://lgtm.com/blog/apache_struts_CVE-2017-9805Broken Link
- https://security.netapp.com/advisory/ntap-20170907-0001/Third Party Advisory
- https://struts.apache.org/docs/s2-052.htmlMitigation, Vendor Advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170907-struts2Third Party Advisory
- https://www.exploit-db.com/exploits/42627/Exploit, Third Party Advisory, VDB Entry
- https://www.kb.cert.org/vuls/id/112992Third Party Advisory, US Government Resource
- http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-9805-3889403.htmlPatch, Third Party Advisory
- http://www.securityfocus.com/bid/100609Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039263Broken Link, Third Party Advisory, VDB Entry
- https://blogs.apache.org/foundation/entry/apache-struts-statement-on-equifaxVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1488482Issue Tracking, Third Party Advisory, VDB Entry
- https://cwiki.apache.org/confluence/display/WW/S2-052Mitigation, Vendor Advisory
- https://lgtm.com/blog/apache_struts_CVE-2017-9805Broken Link
- https://security.netapp.com/advisory/ntap-20170907-0001/Third Party Advisory
- https://struts.apache.org/docs/s2-052.htmlMitigation, Vendor Advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170907-struts2Third Party Advisory
- https://www.exploit-db.com/exploits/42627/Exploit, Third Party Advisory, VDB Entry
- https://www.kb.cert.org/vuls/id/112992Third Party Advisory, US Government Resource
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-9805US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.