{"api_version":"1","generated_at":"2026-07-23T05:39:39+00:00","cve":"CVE-2017-9805","urls":{"html":"https://cve.report/CVE-2017-9805","api":"https://cve.report/api/cve/CVE-2017-9805.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-9805","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-9805"},"summary":{"title":"CVE-2017-9805","description":"The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.","state":"PUBLISHED","assigner":"apache","published_at":"2017-09-15 19:29:00","updated_at":"2026-04-21 16:55:43"},"problem_types":["CWE-502","RCE","CWE-502 CWE-502 Deserialization of Untrusted Data"],"metrics":[{"version":"3.1","source":"nvd@nist.gov","type":"Primary","score":"8.1","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"ADP","type":"DECLARED","score":"8.1","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}},{"version":"3.1","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","score":"8.1","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.8","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"https://www.exploit-db.com/exploits/42627/","name":"https://www.exploit-db.com/exploits/42627/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory","VDB Entry"],"title":"Apache Struts 2.5 < 2.5.12 - REST Plugin XStream Remote Code Execution","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lgtm.com/blog/apache_struts_CVE-2017-9805","name":"https://lgtm.com/blog/apache_struts_CVE-2017-9805","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Using QL to find a remote code execution vulnerability in Apache Struts (CVE-2017-9805) - Blog - lgtm","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-9805-3889403.html","name":"http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-9805-3889403.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"],"title":"Oracle Security Alert CVE-2017-9805","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1488482","name":"https://bugzilla.redhat.com/show_bug.cgi?id=1488482","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Third Party Advisory","VDB Entry"],"title":"Bug 1488482 – CVE-2017-9805 struts: RCE attack via REST plugin with XStream handler to deserialise XML requests","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170907-struts2","name":"https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170907-struts2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Multiple Vulnerabilities in Apache Struts 2 Affecting Cisco Products: September 2017","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://blogs.apache.org/foundation/entry/apache-struts-statement-on-equifax","name":"https://blogs.apache.org/foundation/entry/apache-struts-statement-on-equifax","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Apache Struts Statement on Equifax Security Breach : The Apache Software Foundation Blog","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/100609","name":"http://www.securityfocus.com/bid/100609","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"],"title":"Apache Struts CVE-2017-9805 Remote Code Execution Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.kb.cert.org/vuls/id/112992","name":"https://www.kb.cert.org/vuls/id/112992","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"],"title":"Vulnerability Note VU#112992 - Apache Struts 2 framework REST plugin insecurely deserializes untrusted XML data","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://cwiki.apache.org/confluence/display/WW/S2-052","name":"https://cwiki.apache.org/confluence/display/WW/S2-052","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mitigation","Vendor Advisory"],"title":"S2-052 - Apache Struts 2 Documentation - Apache Software Foundation","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-9805","name":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-9805","refsource":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://security.netapp.com/advisory/ntap-20170907-0001/","name":"https://security.netapp.com/advisory/ntap-20170907-0001/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"CVE-2017-9805 Apache Struts Vulnerability in Multiple NetApp Products | NetApp Product Security","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://struts.apache.org/docs/s2-052.html","name":"https://struts.apache.org/docs/s2-052.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mitigation","Vendor Advisory"],"title":"S2-052 - Apache Struts 2 Documentation - Apache Software Foundation","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1039263","name":"http://www.securitytracker.com/id/1039263","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"],"title":"Apache Struts REST Plugin XStream Deserialization Flaw Lets Remote Users Execute Arbitrary Code on the Target System - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-9805","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-9805","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Apache Software Foundation","product":"Apache Struts","version":"affected Apache Struts before 2.3.34 and 2.5.x before 2.5.13","platforms":[]}],"timeline":[{"source":"ADP","time":"2021-11-03T00:00:00.000Z","lang":"en","value":"CVE-2017-9805 added to CISA KEV"}],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"9805","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apache","cpe5":"struts","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":{"cve_year":"2017","cve_id":"9805","cve":"CVE-2017-9805","vendorProject":"Apache","product":"Struts","vulnerabilityName":"Apache Struts Deserialization of Untrusted Data Vulnerability","dateAdded":"2021-11-03","shortDescription":"Apache Struts REST Plugin uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to remote code execution when deserializing XML payloads.","requiredAction":"Apply updates per vendor instructions.","dueDate":"2022-05-03","knownRansomwareCampaignUse":"Unknown","notes":"https://nvd.nist.gov/vuln/detail/CVE-2017-9805","cwes":"CWE-502","catalogVersion":"2026.07.22","updated_at":"2026-07-22 20:07:16"},"epss":{"cve_year":"2017","cve_id":"9805","cve":"CVE-2017-9805","epss":"0.994610000","percentile":"0.999390000","score_date":"2026-07-22","updated_at":"2026-07-23 00:09:33"},"legacy_qids":[{"cve":"CVE-2017-9805","qid":"981081","title":"Java (maven) Security Update for org.apache.struts:struts2-rest-plugin (GHSA-gg9m-fj3v-r58c)"}]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-05T17:18:01.942Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-9805-3889403.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://struts.apache.org/docs/s2-052.html"},{"name":"1039263","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1039263"},{"name":"100609","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/100609"},{"name":"20170907 Multiple Vulnerabilities in Apache Struts 2 Affecting Cisco Products: September 2017","tags":["vendor-advisory","x_refsource_CISCO","x_transferred"],"url":"https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170907-struts2"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1488482"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://blogs.apache.org/foundation/entry/apache-struts-statement-on-equifax"},{"name":"42627","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"https://www.exploit-db.com/exploits/42627/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://lgtm.com/blog/apache_struts_CVE-2017-9805"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://cwiki.apache.org/confluence/display/WW/S2-052"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://security.netapp.com/advisory/ntap-20170907-0001/"},{"name":"VU#112992","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"https://www.kb.cert.org/vuls/id/112992"}],"title":"CVE Program Container"},{"metrics":[{"cvssV3_1":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}},{"other":{"content":{"id":"CVE-2017-9805","options":[{"Exploitation":"active"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2025-02-06T21:07:51.564352Z","version":"2.0.3"},"type":"ssvc"}},{"other":{"content":{"dateAdded":"2021-11-03","reference":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-9805"},"type":"kev"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-502","description":"CWE-502 Deserialization of Untrusted Data","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2025-10-21T23:55:34.589Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"references":[{"tags":["government-resource"],"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-9805"}],"timeline":[{"lang":"en","time":"2021-11-03T00:00:00.000Z","value":"CVE-2017-9805 added to CISA KEV"}],"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"product":"Apache Struts","vendor":"Apache Software Foundation","versions":[{"status":"affected","version":"Apache Struts before 2.3.34 and 2.5.x before 2.5.13"}]}],"datePublic":"2017-09-15T00:00:00.000Z","descriptions":[{"lang":"en","value":"The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads."}],"problemTypes":[{"descriptions":[{"description":"RCE","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2019-08-12T20:45:53.000Z","orgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","shortName":"apache"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-9805-3889403.html"},{"tags":["x_refsource_CONFIRM"],"url":"https://struts.apache.org/docs/s2-052.html"},{"name":"1039263","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1039263"},{"name":"100609","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/100609"},{"name":"20170907 Multiple Vulnerabilities in Apache Struts 2 Affecting Cisco Products: September 2017","tags":["vendor-advisory","x_refsource_CISCO"],"url":"https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170907-struts2"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1488482"},{"tags":["x_refsource_CONFIRM"],"url":"https://blogs.apache.org/foundation/entry/apache-struts-statement-on-equifax"},{"name":"42627","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"https://www.exploit-db.com/exploits/42627/"},{"tags":["x_refsource_MISC"],"url":"https://lgtm.com/blog/apache_struts_CVE-2017-9805"},{"tags":["x_refsource_CONFIRM"],"url":"https://cwiki.apache.org/confluence/display/WW/S2-052"},{"tags":["x_refsource_CONFIRM"],"url":"https://security.netapp.com/advisory/ntap-20170907-0001/"},{"name":"VU#112992","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"https://www.kb.cert.org/vuls/id/112992"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"security@apache.org","ID":"CVE-2017-9805","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Apache Struts","version":{"version_data":[{"version_value":"Apache Struts before 2.3.34 and 2.5.x before 2.5.13"}]}}]},"vendor_name":"Apache Software Foundation"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"RCE"}]}]},"references":{"reference_data":[{"name":"http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-9805-3889403.html","refsource":"CONFIRM","url":"http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-9805-3889403.html"},{"name":"https://struts.apache.org/docs/s2-052.html","refsource":"CONFIRM","url":"https://struts.apache.org/docs/s2-052.html"},{"name":"1039263","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1039263"},{"name":"100609","refsource":"BID","url":"http://www.securityfocus.com/bid/100609"},{"name":"20170907 Multiple Vulnerabilities in Apache Struts 2 Affecting Cisco Products: September 2017","refsource":"CISCO","url":"https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170907-struts2"},{"name":"https://bugzilla.redhat.com/show_bug.cgi?id=1488482","refsource":"CONFIRM","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1488482"},{"name":"https://blogs.apache.org/foundation/entry/apache-struts-statement-on-equifax","refsource":"CONFIRM","url":"https://blogs.apache.org/foundation/entry/apache-struts-statement-on-equifax"},{"name":"42627","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/42627/"},{"name":"https://lgtm.com/blog/apache_struts_CVE-2017-9805","refsource":"MISC","url":"https://lgtm.com/blog/apache_struts_CVE-2017-9805"},{"name":"https://cwiki.apache.org/confluence/display/WW/S2-052","refsource":"CONFIRM","url":"https://cwiki.apache.org/confluence/display/WW/S2-052"},{"name":"https://security.netapp.com/advisory/ntap-20170907-0001/","refsource":"CONFIRM","url":"https://security.netapp.com/advisory/ntap-20170907-0001/"},{"name":"VU#112992","refsource":"CERT-VN","url":"https://www.kb.cert.org/vuls/id/112992"}]}}}},"cveMetadata":{"assignerOrgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","assignerShortName":"apache","cveId":"CVE-2017-9805","datePublished":"2017-09-15T19:00:00.000Z","dateReserved":"2017-06-21T00:00:00.000Z","dateUpdated":"2025-10-21T23:55:34.589Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-09-15 19:29:00","lastModifiedDate":"2026-04-21 16:55:43","problem_types":["CWE-502","RCE","CWE-502 CWE-502 Deserialization of Untrusted Data"],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.2,"impactScore":5.9},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.2,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:*","versionStartIncluding":"2.1.2","versionEndExcluding":"2.3.34","matchCriteriaId":"13744BE3-2443-4640-BDB4-722C4D393B65"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:*","versionStartIncluding":"2.5.0","versionEndExcluding":"2.5.13","matchCriteriaId":"6B45E858-E783-4D6E-AFD3-97E9963EB05B"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:digital_media_manager:-:*:*:*:*:*:*:*","matchCriteriaId":"E0B1E953-33EF-498D-AB75-4A0A7733BC54"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:hosted_collaboration_solution:10.5\\(1\\):*:*:*:*:*:*:*","matchCriteriaId":"CF4C9089-0F27-4C66-8E12-2BCAC148B7C9"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:hosted_collaboration_solution:11.0\\(1\\):*:*:*:*:*:*:*","matchCriteriaId":"7FCC3E9D-4D39-4530-A5FC-7E9A4E395D60"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:hosted_collaboration_solution:11.5\\(1\\):*:*:*:*:*:*:*","matchCriteriaId":"F972A2A1-3002-4086-8FA2-F231D4ED0B00"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:hosted_collaboration_solution:11.6\\(1\\):*:*:*:*:*:*:*","matchCriteriaId":"D52C5D91-33D1-4C90-BEC9-90D955AA5883"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:media_experience_engine:3.5:*:*:*:*:*:*:*","matchCriteriaId":"93C3A3B2-B346-47F4-B987-0098AB95F939"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:media_experience_engine:3.5.2:*:*:*:*:*:*:*","matchCriteriaId":"87CCEC7F-058D-4202-88B3-F06372DFFA99"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:network_performance_analysis:-:*:*:*:*:*:*:*","matchCriteriaId":"76D400A4-9918-494E-89B7-EAA57B2830D2"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:video_distribution_suite_for_internet_streaming:-:*:*:*:*:*:*:*","matchCriteriaId":"912F9C5E-AA5F-4746-AC49-D33C2495C73B"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:netapp:oncommand_balance:-:*:*:*:*:*:*:*","matchCriteriaId":"7DCBCC5D-C396-47A8-ADF4-D3A2C4377FB1"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"9805","Ordinal":"1","Title":"CVE-2017-9805","CVE":"CVE-2017-9805","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"9805","Ordinal":"1","NoteData":"The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.","Type":"Description","Title":"CVE-2017-9805"},{"CveYear":"2017","CveId":"9805","Ordinal":"2","NoteData":"2017-09-15","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"9805","Ordinal":"3","NoteData":"2019-08-12","Type":"Other","Title":"Modified"}]}}}