Assessment
Why it matters
CISA lists this vulnerability as known to be exploited; exploitation is confirmed; EPSS is 99.4%; technical severity is CVSS 8.1.
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.
Who should care
- Teams operating Struts, Digital Media Manager, Hosted Collaboration Solution +4 more
- Vulnerability and exposure management teams
- Security operations teams monitoring exploitation activity
Response plan
What I would do
- Confirm whether Struts, Digital Media Manager, Hosted Collaboration Solution +4 more is present in the environment.
- Identify affected versions and establish whether vulnerable services are exposed or reachable.
- Oracle Security patch CVE-2017-9805
- Review relevant security telemetry for evidence of attempted or successful exploitation.
- Document the remediation decision and track it to verified completion.
Treatment intelligence
Remediation intelligence
Vendor sources are listed before government and third-party guidance. Confirm product applicability and change prerequisites before deployment.
Advisory
Technical details
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- CWE
- CWE-502
- Affected versions
- Apache Struts (Start Including 2.1.2, End Excluding 2.3.34 | Start Including 2.5.0, End Excluding 2.5.13); Cisco Digital Media Manager (Version -); Cisco Hosted Collaboration Solution (Version 10.5(1) | Version 11.0(1) | Version 11.5(1) | Version 11.6(1)); Cisco Media Experience Engine (Version 3.5 | Version 3.5.2); Cisco Network Performance Analysis (Version -); Cisco Video Distribution Suite For Internet Streaming (Version -); Netapp Oncommand Balance (Version -)
- Fixed versions
- Apache Struts (Fixed from 2.3.34, 2.5.13)
- Published
- 15 September 2017
- Attack vector
- Network
- Privileges required
- None
- User interaction
- None
Signal timeline
- CVE published
- Added to CISA KEV
- Latest EPSS score: 99.4%
- Signal calculated at 83
External references
- Red Hat Third-party advisory Show Bug.cgi
- CERT/CC Government advisory 112992
- CISA Government advisory CVE-2017-9805
- Securityfocus Third-party advisory 100609
- Securitytracker Third-party advisory 1039263
- Blogs Apache Technical reference Apache Struts Statement On Equifax
- Cwiki Apache Technical reference S2 052
- Lgtm Technical reference Apache Struts CVE 2017 9805
- Security Netapp Third-party advisory Ntap 20170907 0001
- Struts Apache Technical reference S2 052
- Exploit information from www.exploit-db.com