CVE-2017-9805
CVE Published | 2017-09-15 |
---|---|
Related CWE(s) | CWE-502: Deserialization of Untrusted Data |
Related Vendor(s) | netapp, cisco, apache |
Related Product(s) | video_distribution_suite_for_internet_streaming, hosted_collaboration_solution, struts, digital_media_manager, network_performance_analysis, oncommand_balance, media_experience_engine |
Exploitation Reported (CISA KEV) | 2021-11-03 |
CVSS 3 Base Score | 8.1 (HIGH) |
CVSS 3 Attack Complexity | HIGH |
CVSS 3 Attack Vector | NETWORK |
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.
Cyber Threat Graph Context
Explore how this CVE relates to the wider threat graph