CVE-2017-9805

The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.1 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
apacheCNA
---
---
CVEADP
---
---
CISA-ADPADP
8.1 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
VendorProductVersion
apachestruts
2.1.2 ≤
𝑥
< 2.3.34
apachestruts
2.5.0 ≤
𝑥
< 2.5.13
ciscodigital_media_manager
-
ciscohosted_collaboration_solution
10.5\(1\)
ciscohosted_collaboration_solution
11.0\(1\)
ciscohosted_collaboration_solution
11.5\(1\)
ciscohosted_collaboration_solution
11.6\(1\)
ciscomedia_experience_engine
3.5
ciscomedia_experience_engine
3.5.2
cisconetwork_performance_analysis
-
ciscovideo_distribution_suite_for_internet_streaming
-
netapponcommand_balance
-
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libstruts1.2-java
cosmic
dne
bionic
dne
artful
dne
zesty
dne
xenial
dne
trusty
dne