CVE-2017-9805 is a critical remote code execution vulnerability affecting the REST Plugin in Apache Struts versions 2.1.1 through 2.3.34 and 2.5.x before 2.5.13, as well as products from Cisco and NetApp. This flaw, stemming from insecure deserialization of XML payloads via XStream, carries a high CVSS score of 8.1 due to its network-based attack vector, low attack complexity, and potential for complete compromise of confidentiality, integrity, and availability. The vulnerability is actively exploited, with readily available exploit code in Metasploit and Nuclei, and has garnered significant community discussion and media coverage, notably linked to the Equifax breach.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.1.2, < 2.3.34CPE matchmatch criteria | cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:* | ||
>= 2.5.0, < 2.5.13CPE matchmatch criteria | cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:cisco:digital_media_manager:-:*:*:*:*:*:*:* | ||
10.5\(1\)CPE matchmatch criteria | cpe:2.3:a:cisco:hosted_collaboration_solution:10.5\(1\):*:*:*:*:*:*:* | ||
11.0\(1\)CPE matchmatch criteria | cpe:2.3:a:cisco:hosted_collaboration_solution:11.0\(1\):*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.