EXPOSURES › CVE-2017-5638
CVE-2017-5638
CRITICAL ⌖ ON CISA KEV · EXPLOITEDApache Struts' file upload parser allowed attackers to execute arbitrary code remotely, actively exploited and linked to ransomware attacks.
A vulnerability in Apache Struts allowed malicious file uploads via Content-Type manipulation, resulting in remote code execution. DIB organizations using Struts are at risk of compromise, potentially impacting CMMC compliance and leading to data breaches. Immediate patching and vulnerability scanning are critical.
Shame score — The vulnerability's exploitation in ransomware attacks highlights a severe and avoidable security failure with significant operational impact.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Apache Struts Jakarta Multipart parser allows for malicious file upload using the Content-Type value, leading to remote code execution.
"Apache Struts Jakarta Multipart parser allows for malicious file upload using the Content-Type value, leading to remote code execution."