446
VMScore

CVE-2017-9793

Published: 20/09/2017 Updated: 12/08/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 446
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The REST Plugin in Apache Struts 2.1.x, 2.3.7 up to and including 2.3.33 and 2.5 up to and including 2.5.12 is using an outdated XStream library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted XML payload.

Vulnerable Product Search on Vulmon Subscribe to Product

apache struts 2.5.10.1

apache struts 2.3.12

apache struts 2.3.13

apache struts 2.3.15.2

apache struts 2.3.15.3

apache struts 2.3.16

apache struts 2.3.20.1

apache struts 2.3.20.2

apache struts 2.3.26

apache struts 2.3.27

apache struts 2.5

apache struts 2.5.5

apache struts 2.5.6

apache struts 2.3.8

apache struts 2.3.9

apache struts 2.3.14.2

apache struts 2.3.14.3

apache struts 2.3.16.3

apache struts 2.3.17

apache struts 2.3.23

apache struts 2.3.24.2

apache struts 2.3.29

apache struts 2.3.30

apache struts 2.5.1

apache struts 2.5.2

apache struts 2.5.9

apache struts 2.5.10

apache struts 2.5.12

apache struts 2.3.7

apache struts 2.3.14

apache struts 2.3.14.1

apache struts 2.3.16.1

apache struts 2.3.16.2

apache struts 2.3.21

apache struts 2.3.22

apache struts 2.3.28

apache struts 2.3.28.1

apache struts 2.5.7

apache struts 2.5.8

apache struts 2.3.10

apache struts 2.3.11

apache struts 2.3.15

apache struts 2.3.15.1

apache struts 2.3.19

apache struts 2.3.20

apache struts 2.3.24.3

apache struts 2.3.25

apache struts 2.3.31

apache struts 2.3.32

apache struts 2.3.33

apache struts 2.5.3

apache struts 2.5.4

Vendor Advisories

A flaw was found in the Struts REST plugin when using an outdated XStream library An attacker could perform a denial of service attack using a malicious request with specially crafted XML payload ...
On September 5, 2017, the Apache Software Foundation released security bulletins that disclosed three vulnerabilities in the Apache Struts 2 package Of these vulnerabilities, the Apache Software Foundation classifies one as Critical Severity, one as Medium Severity, and one as Low Severity For more information about the vulnerabilities, refer to ...

Github Repositories

CVE-2017-5638 and CVE-2017-9793 S2-045-and-S2-052-Struts-2-in-1 Author: (m4ud) Struts pwning tool! Options: -h, --help show this help message and exit -p RPORT, --rport=RPORT RPORT, -t TARGET, --target=TARGET Vulnerable Target, -d DIRECTORY, --dir=DIRECTORY Struts Application directory,

CVE-2017-5638 and CVE-2017-9793 S2-045-and-S2-052-Struts-2-in-1 Author: (m4ud) Struts pwning tool! Options: -h, --help show this help message and exit -p RPORT, --rport=RPORT RPORT, -t TARGET, --target=TARGET Vulnerable Target, -d DIRECTORY, --dir=DIRECTORY Struts Application directory,

CVE-2017-5638 and CVE-2017-9793 S2-045-and-S2-052-Struts-2-in-1 Author: (m4ud) Struts pwning tool! Options: -h, --help show this help message and exit -p RPORT, --rport=RPORT RPORT, -t TARGET, --target=TARGET Vulnerable Target, -d DIRECTORY, --dir=DIRECTORY Struts Application directory,

Recent Articles

Oracle corrals and patches Struts 2 vulnerabilities
The Register • Richard Chirgwin • 27 Sep 2017

Big Red issues out-of-band patch for Apache and a few other urgent issues

Oracle has stepped outside its usual quarterly security fix cycle to address the latest Apache Struts 2 vulnerability. Ever since it emerged at the start of September, CVE-2017-9805 has been (in the words of a former Australian prime minister) “a shiver looking for a spine to crawl up”, because so many vendors use Apache to build Web interfaces and bake Struts 2 into their their Web application framework. Big Red's sprawling product set meant fixes had to be deployed across more than 20 prod...