5
CVSSv2

CVE-2017-9787

Published: 13/07/2017 Updated: 03/10/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

When using a Spring AOP functionality to secure Struts actions it is possible to perform a DoS attack. Solution is to upgrade to Apache Struts version 2.5.12 or 2.3.33.

Most Upvoted Vulmon Research Post

There is no Researcher post for this vulnerability
Would you like to share something about it? Sign up now to share your knowledge with the community.
Vulnerable Product Search on Vulmon Subscribe to Product

apache struts 2.3.12

apache struts 2.3.13

apache struts 2.3.15.2

apache struts 2.3.15.3

apache struts 2.3.20.1

apache struts 2.3.20.2

apache struts 2.3.24.2

apache struts 2.3.24.3

apache struts 2.3.30

apache struts 2.3.31

apache struts 2.3.32

apache struts 2.5.6

apache struts 2.5.7

apache struts 2.3.14

apache struts 2.3.14.1

apache struts 2.3.16

apache struts 2.3.16.1

apache struts 2.3.16.2

apache struts 2.3.20.3

apache struts 2.3.21

apache struts 2.3.25

apache struts 2.3.26

apache struts 2.5

apache struts 2.5.1

apache struts 2.5.8

apache struts 2.5.9

apache struts 2.3.10

apache struts 2.3.11

apache struts 2.3.15

apache struts 2.3.15.1

apache struts 2.3.19

apache struts 2.3.20

apache struts 2.3.24

apache struts 2.3.24.1

apache struts 2.3.28.1

apache struts 2.3.29

apache struts 2.5.4

apache struts 2.5.5

apache struts 2.3.7

apache struts 2.3.8

apache struts 2.3.9

apache struts 2.3.14.2

apache struts 2.3.14.3

apache struts 2.3.16.3

apache struts 2.3.17

apache struts 2.3.22

apache struts 2.3.23

apache struts 2.3.27

apache struts 2.3.28

apache struts 2.5.2

apache struts 2.5.3

apache struts 2.5.10

apache struts 2.5.10.1

Vendor Advisories

When using a Spring AOP functionality to secure Struts actions it is possible to perform a DoS attack Solution is to upgrade to Apache Struts version 2512 or 2333 ...
Oracle Security Alert Advisory - CVE-2017-9805DescriptionThe Apache Foundation’s fixes for CVE-2017-5638, an Apache Struts 2 vulnerability identified by Equifax in relation to Equifax’s recent security incident, were distributed by Oracle to its customers in the April 2017 Critical Patch Update, and should have already been applied to customer ...

Github Repositories

Vulnerable dummy-application for checking different SCA tools

Приложение для обзора технических средств по компонентному анализу Приложение разработано в рамках разработки дипломной работы на тему "Аналитическое исследование программной защиты приложений от ата

Приложение для обзора технических средств по компонентному анализу Приложение разработано в рамках разработки дипломной работы на тему "Аналитическое исследование программной защиты приложений от ата

Recent Articles

Oracle corrals and patches Struts 2 vulnerabilities
The Register • Richard Chirgwin • 27 Sep 2017

Big Red issues out-of-band patch for Apache and a few other urgent issues

Oracle has stepped outside its usual quarterly security fix cycle to address the latest Apache Struts 2 vulnerability.
Ever since it emerged at the start of September, CVE-2017-9805 has been (in the words of a former Australian prime minister) “a shiver looking for a spine to crawl up”, because so many vendors use Apache to build Web interfaces and bake Struts 2 into their their Web application framework.
Big Red's sprawling product set meant fixes had to be deployed across more ...

Oracle corrals and patches Struts 2 vulnerabilities
The Register • Richard Chirgwin • 27 Sep 2017

Big Red issues out-of-band patch for Apache and a few other urgent issues

Oracle has stepped outside its usual quarterly security fix cycle to address the latest Apache Struts 2 vulnerability.
Ever since it emerged at the start of September, CVE-2017-9805 has been (in the words of a former Australian prime minister) “a shiver looking for a spine to crawl up”, because so many vendors use Apache to build Web interfaces and bake Struts 2 into their their Web application framework.
Big Red's sprawling product set meant fixes had to be deployed across more ...

Oracle Patches Apache Struts, Reminds Users to Update Equifax Bug
Threatpost • Chris Brook • 26 Sep 2017

Oracle released fixes for a handful of recently patched Apache Struts 2 vulnerabilities, including a critical remote code execution vulnerability (CVE-2017-9805) that could let an attacker take control of an affected system, late last week.
The Apache Software Foundation patched the RCE vulnerability, which affects servers running apps built using the Struts framework and its REST communication plugin, earlier this month.
Scores of Oracle products, roughly two dozen in total, are aff...