CVE-2017-9805

Description

The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.

Risk Information

Base Score
8.1
MODERATE
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
94.322

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2017-9805,CVE-2017-9793 are fixed in Apache-struts2-rest-plugin 2.5.13Windows
Vulnerabilities CVE-2017-9805,CVE-2017-9793 are fixed in Apache-struts2-rest-plugin 2.3.34Windows
Multiple Vulnerabilities are affected in Netapp Oncommand Balance 2.3Windows
Vulnerabilities CVE-2017-9805,CVE-2017-9793 are fixed in Apache-struts2-rest-plugin for Linux 2.5.13Linux
Vulnerabilities CVE-2017-9805,CVE-2017-9793 are fixed in Apache-struts2-rest-plugin for Linux 2.3.34Linux
Deserialization of Untrusted Data Vulnerability (CVE-2017-9805)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234