Threat intelligence report · CISA KEV

CVE-2017-9805: Apache Struts Deserialization of Untrusted Data Vulnerability

Apache Struts REST Plugin uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to remote code execution when deserializing XML payloads. Required action: Apply updates per vendor instructions.

· high severity · unattributed attribution

Evidence and provenance

Original source
CISA KEV report ↗
Published
2021-11-03T00:00:00Z
Confidence basis
No actor match
Record ID
a0093baa40b1df4c33ab

Vulnerabilities

CVE-2017-9805

Use and citation

Verify the original report before making operational decisions. Cite this permanent page together with the original source, publication date, confidence level, and review status.