CVE-2017-9805
גבוהה 8.1 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Apache Struts Deserialization of Untrusted Data Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.
מדדים
- CVSS 3.1
-
8.1 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 99% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-502
מוצרים מושפעים
apache: struts; cisco: digital media manager; cisco: hosted collaboration solution; cisco: media experience engine; cisco: network performance analysis; cisco: video distribution suite for internet streaming; netapp: oncommand balance
קישורים
- https://blogs.apache.org/foundation/entry/apache-struts-statement-on-equifax Vendor Advisory
- https://cwiki.apache.org/confluence/display/WW/S2-052 MitigationVendor Advisory
- https://struts.apache.org/docs/s2-052.html MitigationVendor Advisory
- https://blogs.apache.org/foundation/entry/apache-struts-statement-on-equifax Vendor Advisory
- https://cwiki.apache.org/confluence/display/WW/S2-052 MitigationVendor Advisory
- https://struts.apache.org/docs/s2-052.html MitigationVendor Advisory
- http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-9805-388940… PatchThird Party Advisory
- http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-9805-388940… PatchThird Party Advisory
- https://www.exploit-db.com/exploits/42627/ ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/42627/ ExploitThird Party AdvisoryVDB Entry