CVE-2017-9805 Details
Description
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.
A remote code execution vulnerability exists in the Apache Struts 2 REST Plugin, affecting versions 2.1.1 through 2.3.x prior to 2.3.34 and 2.5.x prior to 2.5.13. The vulnerability arises because the REST Plugin uses an XStreamHandler to deserialize XML payloads without any type filtering. This lack of validation can be exploited by an attacker to execute arbitrary code on the server.
Upgrade to Apache Struts versions 2.5.13 or 2.3.34. If the REST Plugin is not needed, consider removing it. If it must be retained, limit its functionality to serve only standard pages and JSON by adjusting the 'struts.action.extension' constant in the 'struts.xml' configuration file.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 6, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Apache Struts Deserialization of Untrusted Data Vulnerability | Nov 3, 2021 | May 3, 2022 | Apply updates per vendor instructions. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-502 | Deserialization of Untrusted Data | [email protected] |
| CWE-502 | Deserialization of Untrusted Data | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| apache struts | >= 2.1.2, < 2.3.34 >= 2.5.0, < 2.5.13 |
CPE
Remediation
| |
| cisco digital media manager | All versions |
CPE
Remediation
| |
| cisco hosted collaboration solution | 10.5(1) 11.0(1) 11.5(1) 11.6(1) |
CPE
Remediation
| |
| cisco media experience engine | 3.5 3.5.2 |
CPE
Remediation
| |
| cisco network performance analysis | All versions |
CPE
Remediation
| |
| cisco video distribution suite for internet streaming | All versions |
CPE
Remediation
| |
| netapp oncommand balance | All versions |
CPE
Remediation
| |
Change History
20 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Apr 21, 2026 | Modified Analysis | [email protected] |
| Oct 22, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Mar 6, 2025 | Modified Analysis | [email protected] |
| Feb 6, 2025 | CVE Modified | CISA-ADP |
| Jan 23, 2025 | Modified Analysis | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| Jul 25, 2024 | Modified Analysis | [email protected] |
| May 14, 2024 | CVE Modified | [email protected] |
| Aug 12, 2019 | CVE Modified | [email protected] |
| Nov 10, 2017 | CVE Modified | [email protected] |
| Oct 31, 2017 | CVE Modified | [email protected] |
| Oct 4, 2017 | Reanalysis | [email protected] |
| Sep 29, 2017 | Initial Analysis | [email protected] |
| Sep 28, 2017 | CVE Modified | [email protected] |
| Sep 22, 2017 | CVE Modified | [email protected] |
| Sep 17, 2017 | CVE Modified | [email protected] |