CVE-2017-9805

CVE Published 2017-09-15
Related CWE(s) CWE-502: Deserialization of Untrusted Data
Related Vendor(s) netapp, cisco, apache
Related Product(s) video_distribution_suite_for_internet_streaming, hosted_collaboration_solution, struts, digital_media_manager, network_performance_analysis, oncommand_balance, media_experience_engine
Exploitation Reported (CISA KEV) 2021-11-03
CVSS 3 Base Score 8.1 (HIGH)
CVSS 3 Attack Complexity HIGH
CVSS 3 Attack Vector NETWORK

The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References