CVE-2017-9793 is a Denial of Service (DoS) vulnerability affecting Apache Struts 2.1.x, 2.3.7-2.3.33, and 2.5-2.5.12, stemming from an outdated XStream library in its REST Plugin. This flaw allows an unauthenticated attacker to trigger a DoS by sending a specially crafted XML payload. Rated with a CVSS score of 7.5 (High), it presents a low-complexity network attack vector with a high impact on availability. While there is no known public exploit code or Metasploit module, the vulnerability has garnered significant community discussion and media coverage, indicating substantial awareness and concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.3.7CPE matchmatch criteria | cpe:2.3:a:apache:struts:2.3.7:*:*:*:*:*:*:* | ||
2.3.8CPE matchmatch criteria | cpe:2.3:a:apache:struts:2.3.8:*:*:*:*:*:*:* | ||
2.3.9CPE matchmatch criteria | cpe:2.3:a:apache:struts:2.3.9:*:*:*:*:*:*:* | ||
2.3.10CPE matchmatch criteria | cpe:2.3:a:apache:struts:2.3.10:*:*:*:*:*:*:* | ||
2.3.11CPE matchmatch criteria | cpe:2.3:a:apache:struts:2.3.11:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.