CVE-2017-5638 Details
Description
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header, as exploited in the wild in March 2017 with a Content-Type header containing a #cmd= string.
A remote code execution vulnerability has been identified in Apache Struts 2 versions 2.3.x prior to 2.3.32 and 2.5.x prior to 2.5.10.1. The issue arises in the Jakarta Multipart parser, which improperly handles exceptions and error messages during file upload attempts. This flaw allows remote attackers to execute arbitrary commands by crafting the Content-Type, Content-Disposition, or Content-Length HTTP headers. The vulnerability was actively exploited in March 2017, using a Content-Type header that included a '#cmd=' string.
Upgrade to Apache Struts versions 2.3.32 or 2.5.10.1. If an immediate upgrade is not possible, consider switching to a different implementation of the Multipart parser or removing the File Upload Interceptor from the stack.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 6, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Apache Struts Remote Code Execution Vulnerability | Nov 3, 2021 | May 3, 2022 | Apply updates per vendor instructions. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-755 | Improper Handling of Exceptional Conditions | [email protected] |
| CWE-755 | Improper Handling of Exceptional Conditions | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| apache struts | >= 2.2.3, < 2.3.32 >= 2.5.0, < 2.5.10.1 |
CPE
Remediation
| |
| ibm storwize v3500 firmware | 7.7.1.6 7.8.1.0 |
CPE
Remediation
| |
| ibm storwize v3500 | All versions |
CPE
Remediation
| |
| ibm storwize v5000 firmware | 7.7.1.6 7.8.1.0 |
CPE
Remediation
| |
| ibm storwize v5000 | All versions |
CPE
Remediation
| |
| ibm storwize v7000 firmware | 7.7.1.6 7.8.1.0 |
CPE
Remediation
| |
| ibm storwize v7000 | All versions |
CPE
Remediation
| |
| lenovo storage v5030 firmware | 7.7.1.6 7.8.1.0 |
CPE
Remediation
| |
| lenovo storage v5030 | All versions |
CPE
Remediation
| |
| hp server automation | 9.1.0 10.0.0 10.1.0 10.2.0 10.5.0 |
CPE
Remediation
| |
| oracle weblogic server | 10.3.6.0.0 12.1.3.0.0 12.2.1.1.0 12.2.1.2.0 |
CPE
Remediation
| |
| arubanetworks clearpass policy manager | < 6.6.5 |
CPE
Remediation
| |
| netapp oncommand balance | All versions |
CPE
Remediation
| |
Change History
33 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Apr 21, 2026 | Modified Analysis | [email protected] |
| Oct 22, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Mar 21, 2025 | Modified Analysis | [email protected] |
| Feb 6, 2025 | CVE Modified | CISA-ADP |
| Jan 23, 2025 | Modified Analysis | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| Jul 25, 2024 | Modified Analysis | [email protected] |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Feb 24, 2021 | CVE Modified | [email protected] |
| Jan 26, 2021 | CVE Modified | [email protected] |
| Jan 31, 2020 | CVE Modified | [email protected] |
| Mar 4, 2018 | CVE Modified | [email protected] |
| Nov 10, 2017 | CVE Modified | [email protected] |
| Oct 10, 2017 | CVE Modified | [email protected] |
| Sep 23, 2017 | CVE Modified | [email protected] |
| Sep 22, 2017 | CVE Modified | [email protected] |
| Aug 16, 2017 | CVE Modified | [email protected] |
| Aug 9, 2017 | CVE Modified | [email protected] |
| Jul 17, 2017 | CVE Modified | [email protected] |
| May 27, 2017 | CVE Modified | [email protected] |
| May 10, 2017 | CVE Modified | [email protected] |
| Mar 30, 2017 | CVE Modified | [email protected] |
| Mar 27, 2017 | Reanalysis | [email protected] |
| Mar 15, 2017 | Reanalysis | [email protected] |
| Mar 14, 2017 | Reanalysis | [email protected] |
| Mar 14, 2017 | Initial Analysis | [email protected] |
| Mar 14, 2017 | CVE Modified | [email protected] |
| Mar 13, 2017 | CVE Modified | [email protected] |