CVE-2017-9805
Last modified
CVE-2017-9805 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.. CISA has confirmed active exploitation in the wild. EPSS estimates a 99.46% chance of exploitation in the next 30 days.
Description
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Struts | >= 2.1.2, < 2.3.34 |
| Apache | Struts | >= 2.5.0, < 2.5.13 |
| Cisco | Digital Media Manager | All versions |
| Cisco | Hosted Collaboration Solution | 10.5\(1\) |
| Cisco | Hosted Collaboration Solution | 11.0\(1\) |
| Cisco | Hosted Collaboration Solution | 11.5\(1\) |
| Cisco | Hosted Collaboration Solution | 11.6\(1\) |
| Cisco | Media Experience Engine | 3.5 |
| Cisco | Media Experience Engine | 3.5.2 |
| Cisco | Network Performance Analysis | All versions |
| Cisco | Video Distribution Suite For Internet Streaming | All versions |
| Netapp | Oncommand Balance | All versions |
References
- http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-9805-3889403.htmlPatch, Third Party Advisory
- http://www.securityfocus.com/bid/100609Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039263Broken Link, Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1488482Issue Tracking, Third Party Advisory, VDB Entry
- https://cwiki.apache.org/confluence/display/WW/S2-052Mitigation, Vendor Advisory
- https://security.netapp.com/advisory/ntap-20170907-0001/Third Party Advisory
- https://struts.apache.org/docs/s2-052.htmlMitigation, Vendor Advisory
- https://www.exploit-db.com/exploits/42627/Exploit, Third Party Advisory, VDB Entry
- https://www.kb.cert.org/vuls/id/112992Third Party Advisory, US Government Resource
- http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-9805-3889403.htmlPatch, Third Party Advisory
- http://www.securityfocus.com/bid/100609Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039263Broken Link, Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1488482Issue Tracking, Third Party Advisory, VDB Entry
- https://cwiki.apache.org/confluence/display/WW/S2-052Mitigation, Vendor Advisory
- https://security.netapp.com/advisory/ntap-20170907-0001/Third Party Advisory
- https://struts.apache.org/docs/s2-052.htmlMitigation, Vendor Advisory
- https://www.exploit-db.com/exploits/42627/Exploit, Third Party Advisory, VDB Entry
- https://www.kb.cert.org/vuls/id/112992Third Party Advisory, US Government Resource
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-9805US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2017-9805?
How severe is CVE-2017-9805?
How do I fix CVE-2017-9805?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-9799It was found that under some situations and configurations o…
- CVE-2017-9800A maliciously constructed svn+ssh:// URL would cause Subvers…
- CVE-2017-9801When a call-site passes a subject for an email that contains…
- CVE-2017-9802The Javascript method Sling.evalString() in Apache Sling Ser…
- CVE-2017-9803Apache Solr's Kerberos plugin can be configured to use deleg…
- CVE-2017-9804In Apache Struts 2.3.7 through 2.3.33 and 2.5 through 2.5.12…
- CVE-2017-9806A vulnerability in the OpenOffice Writer DOC file parser bef…7.8
- CVE-2017-9807An issue was discovered in the OpenWebif plugin through 1.2.…
- CVE-2017-9808OX Software GmbH OX App Suite 7.8.4 and earlier is affected …
- CVE-2017-9809OX Software GmbH OX App Suite 7.8.4 and earlier is affected …
- CVE-2017-9810There are no Anti-CSRF tokens in any forms on the web interf…
- CVE-2017-9811The kluser is able to interact with the kav4fs-control binar…
Are you affected by CVE-2017-9805?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
