Skip to content
COOEY

EXPOSURES › CVE-2017-9805

CVE-2017-9805

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2017-9805 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildunpatched

Apache Struts REST Plugin allowed remote code execution via unfiltered XML deserialization in CVE-2017-9805.

The Apache Struts REST Plugin used XStream for deserialization without type filtering, enabling attackers to execute arbitrary code remotely. DIB organizations must care because this unpatched vulnerability was actively exploited in the wild, leading to potential data breaches and ransomware entry points. Organizations should ensure all Apache Struts versions are patched and monitor for exploitation attempts.

Shame score — A known, unpatched vulnerability that enabled remote code execution and was actively exploited in the wild, representing a severe avoidable failure in software security.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Apache Struts REST Plugin uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to remote code execution when deserializing XML payloads.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Apache faced severe fallout due to a critical RCE vulnerability in Struts, widely condemned for lack of type filtering in XML deserialization.
cooey ↗ severe-fallout -0.80
Severe condemnation for critical RCE flaw in Struts REST Plugin.
"Apache Struts REST Plugin uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to remote code execution when deserializing XML payloads."
app.opencve.io ↗ severe-fallout +0.00
Neutral listing of CVEs without specific commentary on Apache's handling.
"Apache CVEs and Security Vulnerabilities - OpenCVE"
www.cvefind.com ↗ severe-fallout +0.00
Neutral database entry with no vendor-specific sentiment.
"Database CVE, CWE, CISA KEV & Vulnerability Intelligence | CVE Find"
coverager.com ↗ severe-fallout +0.00
Irrelevant coverage of unrelated vendor TruStage.
"TruStage shuts down network following cybersecurity incident"
cve.akaoma.com ↗ severe-fallout +0.00
Neutral real-time CVE database with no specific vendor sentiment.
"Latest Cybersecurity Vulnerabilities | Real-Time CVE Database"
sam.gov ↗ severe-fallout +0.00
Irrelevant government procurement site.
"Sam Acquisition 360"
www.ransomware.live ↗ severe-fallout +0.00
Irrelevant ransomware monitoring site.
"ransomware .live"
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.