CVE-2017-9805

EUVD-2018-0602
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.1 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
8.1 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
Affected Products (NVD)
VendorProductVersion
apachestruts
2.1.2 ≤
𝑥
< 2.3.34
apachestruts
2.5.0 ≤
𝑥
< 2.5.13
ciscodigital_media_manager
-
ciscohosted_collaboration_solution
10.5\(1\)
ciscohosted_collaboration_solution
11.0\(1\)
ciscohosted_collaboration_solution
11.5\(1\)
ciscohosted_collaboration_solution
11.6\(1\)
ciscomedia_experience_engine
3.5
ciscomedia_experience_engine
3.5.2
cisconetwork_performance_analysis
-
ciscovideo_distribution_suite_for_internet_streaming
-
netapponcommand_balance
-
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libstruts1.2-java
artful
dne
bionic
dne
cosmic
dne
trusty
dne
xenial
dne
zesty
dne