CVE-2017-5638
11.03.2017, 02:59
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header, as exploited in the wild in March 2017 with a Content-Type header containing a #cmd= string.Enginsight
Vendor | Product | Version |
---|---|---|
apache | struts | 2.2.3 ≤ 𝑥 < 2.3.32 |
apache | struts | 2.5.0 ≤ 𝑥 < 2.5.10.1 |
ibm | storwize_v3500_firmware | 7.7.1.6 |
ibm | storwize_v3500_firmware | 7.8.1.0 |
ibm | storwize_v5000_firmware | 7.7.1.6 |
ibm | storwize_v5000_firmware | 7.8.1.0 |
ibm | storwize_v7000_firmware | 7.7.1.6 |
ibm | storwize_v7000_firmware | 7.8.1.0 |
lenovo | storage_v5030_firmware | 7.7.1.6 |
lenovo | storage_v5030_firmware | 7.8.1.0 |
hp | server_automation | 9.1.0 |
hp | server_automation | 10.0.0 |
hp | server_automation | 10.1.0 |
hp | server_automation | 10.2.0 |
hp | server_automation | 10.5.0 |
oracle | weblogic_server | 10.3.6.0.0 |
oracle | weblogic_server | 12.1.3.0.0 |
oracle | weblogic_server | 12.2.1.1.0 |
oracle | weblogic_server | 12.2.1.2.0 |
arubanetworks | clearpass_policy_manager | 𝑥 < 6.6.5 |
netapp | oncommand_balance | - |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
Vulnerability Media Exposure
References