HIGH🚩 CISA KEV⚡ EXPLOIT✓ PATCH🇵🇱 Wersja polska

CVE-2017-9805

CVSS 8.1v3.1pub. 2017-09-15upd. 2026-04-21

The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Apache Struts

    APP
    Apache
    2.1.2 – 2.3.34 (excl.)2.5.0 – 2.5.13 (excl.)
  • Cisco Digital Media Manager

    APP
    Cisco
    all versions
  • Cisco Hosted Collaboration Solution

    APP
    Cisco
    10.5\(1\)11.0\(1\)11.5\(1\)11.6\(1\)
  • Cisco Media Experience Engine

    APP
    Cisco
    3.53.5.2
  • Cisco Network Performance Analysis

    APP
    Cisco
    all versions
  • Cisco Video Distribution Suite For Internet Streaming

    APP
    Cisco
    all versions
  • Netapp Oncommand Balance

    APP
    Netapp
    all versions

CISA KEV — detailsi

Vendori
Apache
Producti
Struts
Added to KEVi
November 3, 2021
Remediation deadline (US Federal)i
May 3, 2022(overdue)
Required action (CISA)i

Apply updates per vendor instructions.

CISA descriptioni

Apache Struts REST Plugin uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to remote code execution when deserializing XML payloads.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 3 maja 2022
Tags
RCEDeserialization
CWE
References

Related vulnerabilities

CVE-2020-17530CRITICAL9.8⚠ KEVPL ✓same product

RCE w Apache Struts 2 poprzez wymuszoną ewaluację OGNL

CVE-2017-9791CRITICAL9.8⚠ KEVPL ✓same product

RCE w pluginie Struts 1 dla Apache Struts 2 (S2-048)

CVE-2017-5638CRITICAL9.8⚠ KEVPL ✓same product

RCE w Apache Struts 2 poprzez błędną obsługę nagłówków HTTP (Jakarta Multipart parser)

CVE-2016-3427CRITICAL9.8⚠ KEVPL ✓same product

Krytyczna podatność RCE w Oracle Java SE i JRockit — komponent JMX

CVE-2013-2251CRITICAL9.8⚠ KEVPL ✓same product

Apache Struts 2: RCE przez prefiks action/redirect w parametrach