EXPOSURES › CVE-2017-9805
CVE-2017-9805
HIGH ⌖ ON CISA KEV · EXPLOITEDApache Struts REST Plugin allowed remote code execution via unfiltered XML deserialization in CVE-2017-9805.
The Apache Struts REST Plugin used XStream for deserialization without type filtering, enabling attackers to execute arbitrary code remotely. DIB organizations must care because this unpatched vulnerability was actively exploited in the wild, leading to potential data breaches and ransomware entry points. Organizations should ensure all Apache Struts versions are patched and monitor for exploitation attempts.
Shame score — A known, unpatched vulnerability that enabled remote code execution and was actively exploited in the wild, representing a severe avoidable failure in software security.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Apache Struts REST Plugin uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to remote code execution when deserializing XML payloads.
"Apache Struts REST Plugin uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to remote code execution when deserializing XML payloads."
"Apache CVEs and Security Vulnerabilities - OpenCVE"
"Database CVE, CWE, CISA KEV & Vulnerability Intelligence | CVE Find"
"TruStage shuts down network following cybersecurity incident"
"Latest Cybersecurity Vulnerabilities | Real-Time CVE Database"
"ransomware .live"