CVE-2017-5638 is a critical remote code execution vulnerability in the Jakarta Multipart parser of Apache Struts 2 (versions 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1), affecting numerous products from vendors like Oracle, IBM, and HP. This flaw allows unauthenticated attackers to execute arbitrary commands by crafting malicious HTTP headers during file upload attempts. With a CVSS score of 9.8 (CRITICAL) and a FAUCET Risk Score of 100/100, it poses a severe risk due to its network-based attack vector, low complexity, and complete compromise of confidentiality, integrity, and availability. The vulnerability is actively exploited in the wild, including in known ransomware campaigns, with public exploit code readily available in Metasploit and ExploitDB, and has garnered significant community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.2.3, < 2.3.32CPE matchmatch criteria | cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:* | ||
>= 2.5.0, < 2.5.10.1CPE matchmatch criteria | cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:* | ||
7.7.1.6CPE matchmatch criteria | cpe:2.3:o:ibm:storwize_v3500_firmware:7.7.1.6:*:*:*:*:*:*:* | ||
7.8.1.0CPE matchmatch criteria | cpe:2.3:o:ibm:storwize_v3500_firmware:7.8.1.0:*:*:*:*:*:*:* | ||
7.7.1.6CPE matchmatch criteria | cpe:2.3:o:ibm:storwize_v5000_firmware:7.7.1.6:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.