CVE-2017-9805
Summary
| CVE | CVE-2017-9805 |
|---|---|
| State | PUBLISHED |
| Assigner | apache |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-09-15 19:29:00 UTC |
| Updated | 2026-04-21 16:55:43 UTC |
| Description | The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads. |
Risk And Classification
Primary CVSS: v3.1 8.1 HIGH from [email protected]
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.994610000 probability, percentile 0.999390000 (date 2026-07-21)
CISA KEV: Listed on 2021-11-03; due 2022-05-03; ransomware use Unknown
Problem Types: CWE-502 | RCE | CWE-502 CWE-502 Deserialization of Untrusted Data
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 8.1 | HIGH | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | ADP | DECLARED | 8.1 | HIGH | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 8.1 | HIGH | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 2.0 | [email protected] | Primary | 6.8 | AV:N/AC:M/Au:N/C:P/I:P/A:P |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
HighPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:P/I:P/A:P
CISA Known Exploited Vulnerability
| Vendor | Apache |
|---|---|
| Product | Struts |
| Name | Apache Struts Deserialization of Untrusted Data Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://nvd.nist.gov/vuln/detail/CVE-2017-9805 |
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Apache Software Foundation | Apache Struts | affected Apache Struts before 2.3.34 and 2.5.x before 2.5.13 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Apache Struts 2.5 < 2.5.12 - REST Plugin XStream Remote Code Execution | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | Exploit, Third Party Advisory, VDB Entry |
| Using QL to find a remote code execution vulnerability in Apache Struts (CVE-2017-9805) - Blog - lgtm | af854a3a-2127-422b-91ae-364da2661108 | lgtm.com | Broken Link |
| Oracle Security Alert CVE-2017-9805 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Patch, Third Party Advisory |
| Bug 1488482 – CVE-2017-9805 struts: RCE attack via REST plugin with XStream handler to deserialise XML requests | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Issue Tracking, Third Party Advisory, VDB Entry |
| Multiple Vulnerabilities in Apache Struts 2 Affecting Cisco Products: September 2017 | af854a3a-2127-422b-91ae-364da2661108 | tools.cisco.com | Third Party Advisory |
| Apache Struts Statement on Equifax Security Breach : The Apache Software Foundation Blog | af854a3a-2127-422b-91ae-364da2661108 | blogs.apache.org | Vendor Advisory |
| Apache Struts CVE-2017-9805 Remote Code Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Broken Link, Third Party Advisory, VDB Entry |
| Vulnerability Note VU#112992 - Apache Struts 2 framework REST plugin insecurely deserializes untrusted XML data | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | Third Party Advisory, US Government Resource |
| S2-052 - Apache Struts 2 Documentation - Apache Software Foundation | af854a3a-2127-422b-91ae-364da2661108 | cwiki.apache.org | Mitigation, Vendor Advisory |
| www.cisa.gov/known-exploited-vulnerabilities-catalog | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | www.cisa.gov | US Government Resource |
| CVE-2017-9805 Apache Struts Vulnerability in Multiple NetApp Products | NetApp Product Security | af854a3a-2127-422b-91ae-364da2661108 | security.netapp.com | Third Party Advisory |
| S2-052 - Apache Struts 2 Documentation - Apache Software Foundation | af854a3a-2127-422b-91ae-364da2661108 | struts.apache.org | Mitigation, Vendor Advisory |
| Apache Struts REST Plugin XStream Deserialization Flaw Lets Remote Users Execute Arbitrary Code on the Target System - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Broken Link, Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| ADP | 2021-11-03T00:00:00.000Z | CVE-2017-9805 added to CISA KEV |
Legacy QID Mappings
- 981081 Java (maven) Security Update for org.apache.struts:struts2-rest-plugin (GHSA-gg9m-fj3v-r58c)