← לוח פגיעויות

CVE-2017-5638

קריטית 9.8 מנוצלת בשטח (KEV) בשימוש בכופרה

ניצול פעיל מאומת — קטלוג CISA KEV

שם
Apache Struts Remote Code Execution Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply updates per vendor instructions.

תיאור (מקור, אנגלית)

The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header, as exploited in the wild in March 2017 with a Content-Type header containing a #cmd= string.

מדדים

CVSS 3.1
9.8 (CRITICAL) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS — סבירות ניצול
100% (אחוזון 100) נכון ל-24/7/2026
CWE
CWE-755

מוצרים מושפעים

apache: struts; ibm: storwize v3500 firmware; ibm: storwize v3500; ibm: storwize v5000 firmware; ibm: storwize v5000; ibm: storwize v7000 firmware; ibm: storwize v7000; lenovo: storage v5030 firmware; lenovo: storage v5030; hp: server automation; oracle: weblogic server; arubanetworks: clearpass policy manager; netapp: oncommand balance

קישורים