Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2017-9805 Details

Description

The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-9805 CISA-ADPUS Government Resource
https://blogs.apache.org/foundation/entry/apache-struts-statement-on-equifax CVEVendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1488482 CVEIssue TrackingThird Party AdvisoryVDB Entry
https://cwiki.apache.org/confluence/display/WW/S2-052 CVEMitigationVendor Advisory
https://lgtm.com/blog/apache_struts_CVE-2017-9805 CVEBroken Link

see all 25 references

This CVE is in CISA's Known Exploited Vulnerabilities Catalog

Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.

Vulnerability NameDate AddedDue DateRequired Action
Apache Struts Deserialization of Untrusted Data VulnerabilityNov 3, 2021May 3, 2022Apply updates per vendor instructions.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-502Deserialization of Untrusted Data[email protected]
CWE-502Deserialization of Untrusted DataCISA-ADP

Affected Products

ProductVersions

Change History

20 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2017-9805
NVD Published Date:
Sep 15, 2017
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2017-9805 Details - Not Deferred