CVE-2017-5638

Related Vulnerabilities: CVE-2017-5638  

A flaw was reported in Apache Struts 2 that could allow an attacker to perform remote code execution with a malicious Content-Type value.

A flaw was reported in Apache Struts 2 that could allow an attacker to perform remote code execution with a malicious Content-Type value.

Find out more about CVE-2017-5638 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

This issue did not affect any of the Red Hat products as they did not include the Apache Struts 2 package. Additionally it does not appear that struts 1 is affected by this vulnerability (the affected code does not appear to be present in struts 1). Additionally it does not appear that Red Hat has backported any code from struts 2 to struts 1 as the code bases are quite different and backporting any significant code would be a major effort with questionable results due to compatibility issues.

CVSS v3 metrics

NOTE: The following CVSS v3 metrics and score provided are preliminary and subject to review.

CVSS3 Base Score 9.8
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality High
Integrity Impact High
Availability Impact High

Affected Packages State

Platform Package State
Red Hat JBoss Fuse Service Works 6 struts2-core Not affected

External References