Skip to main content

CVE detail

CVE-2017-5638

The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header, as exploited in the wild in March 2017 with a Content-Type header containing a #cmd= string.

CVSS 9.8 · CriticalBuzz score 75.0KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 75.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
30.0
76 evidence mentions in the snapshot
Diversity score
20.0
8 sources across 3 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
76 source links · newest first
  • Experts uncovered a new Go-based multi-platform malware, tracked as NKAbuse, which is the first malware abusing NKN technology. Researchers from Kaspersky’s Global Emergency Response Team (GERT) and GReAT uncovered a new multiplatform malware dubbed NKAbuse. The malicious code is written in Go language, it is the first malware that relies on the NKN technology for data exchange […]

    newssecurityaffairs.comDec 16, 2023, 12:43 AM
  • Attackers are attempting to exploit a critical RCE flaw in Apache Struts 2 after researchers publish PoC code.

    newswww.securityweek.comDec 15, 2023, 10:40 AM
  • The GitHub Security Lab audits open source projects for security vulnerabilities and helps maintainers fix them. Recently, we passed the milestone of 500 CVEs disclosed. Let’s take a trip down memory lane with a review of some noteworthy CVEs!

    vendorgithub.blogSep 21, 2023, 8:56 PM
  • Bypassing OGNL sandboxes for fun and charitiesGitHub Security Lab

    Object Graph Notation Language (OGNL) is a popular, Java-based, expression language used in popular frameworks and applications, such as Apache Struts and Atlassian Confluence. Learn more about bypassing certain OGNL injection protection mechanisms including those used by Struts and Atlassian Confluence, as well as different approaches to analyzing this form of protection so you can harden similar systems.

    vendorgithub.blogJan 27, 2023, 4:00 PM
  • The 2022 Unit 42 Network Threat Trends Research Report includes an analysis of the CVEs most commonly exploited in 2021 and predictions for which CVEs attackers will likely focus on in the year to come.

    vendorunit42.paloaltonetworks.comJul 21, 2022, 1:00 PM
  • The last decade has seen its fair share of watershed moments that have had major implications on the cybersecurity landscape. Severe vulnerabilities, mass exploitations, and widespread cyberattacks have reshaped many aspects of modern security. To take stock of the past 10 years, cybersecurity vendor Trustwave has published the Decade Retrospective: The State of Vulnerabilities blog […]

    newswww.csoonline.comJul 19, 2022, 9:00 AM
  • Software firm Atlassian released emergency patches for its popular Confluence Server and Data Center products after reports came to light late last week that attackers were exploiting an unpatched vulnerability in the wild. According to data from Cloudflare’s web application firewall (WAF) service, the attacks started in late May. The vulnerability, now tracked as CVE-2022-26134, […]

    newswww.csoonline.comJul 4, 2022, 9:00 AM
  • On August 25, 2021, Atlassian released a security advisory for CVE-2021-26084, an OGNL injection vulnerability found within a component of Confluence Server and Data Center. This critical vulnerability allows an unauthenticated attacker to execute arbitrary commands on the server. A few days later, on August 31, security researchers @iamnoob and @rootxharsh quickly developed a working proof of concept given the vulnerability […]

    exploithorizon3.aiSep 13, 2021, 6:41 PM
  • File transfer threats can open organizations up to data theft or data loss, but proper controls and network traffic visibility can mitigate them.

    vendorunit42.paloaltonetworks.comMay 5, 2021, 1:00 PM
  • The typical timing of patch releases, exploits and CVE publication underscores the need for timely patching and effective vulnerability management.

    vendorunit42.paloaltonetworks.comAug 26, 2020, 1:00 PM
  • Have you already updated your Apache Struts 2 to version 2.5.22, released in November 2019? You might want to, and quickly, as information about a potential RCE vulnerability (CVE-2019-0230) and PoC exploits for it have been published. About the vulnerability (CVE-2019-0230) “CVE-2019-0230 is a forced double Object-Graph Navigation Language (OGNL) evaluation vulnerability that occurs when Struts tries to perform an evaluation of raw user input inside of tag attributes. An attacker could exploit this vulnerability … More →

    newswww.helpnetsecurity.comAug 17, 2020, 10:03 AM
  • Security researchers have discovered a PoC exploit code available online that can be used to trigger unpatched security flaws in Apache Struts 2. Security researchers have discovered a PoC code and exploit available on GitHub that that can be used to trigger the security vulnerabilities in Apache Struts 2. The Proof-of-concept exploit code was released […]

    newssecurityaffairs.comAug 15, 2020, 3:52 PM
  • Several Microsoft Office vulnerabilities that were patched years ago continue to be among the security flaws most exploited in attacks, the U.S. government warns.

    newswww.securityweek.comMay 13, 2020, 4:43 PM
  • The US Cybersecurity and Infrastructure Security Agency (CISA) is urging organizations to patch a slew of old and new software vulnerabilities that are routinely exploited by foreign cyber actors and cyber criminals. “Foreign cyber actors continue to exploit publicly known—and often dated—software vulnerabilities against broad target sets, including public and private sector organizations. Exploitation of these vulnerabilities often requires fewer resources as compared with zero-day exploits for which no patches are available,” the agency noted. … More →

    newswww.helpnetsecurity.comMay 13, 2020, 9:49 AM
  • In March 2017, personally identifying data of hundreds of millions of people was stolen from Equifax, one of the credit reporting agencies that assess the financial health of nearly everyone in the United States. As we’ll see, the breach spawned a number of scandals and controversies: Equifax was criticized for everything ranging from their lax […]

    newswww.csoonline.comFeb 12, 2020, 1:09 PM
  • The United States Department of Justice charged 4 Chinese military hackers with hacking into credit reporting agency Equifax. The United States Department of Justice officially charged 4 members of the China’s PLA’s 54th Research Institute, a division of the Chinese military, with hacking into credit reporting agency Equifax. The four members of the Chinese military […]

    newssecurityaffairs.comFeb 10, 2020, 10:46 PM
  • The United States government has officially charged four members of China’s People’s Liberation Army (PLA) with hacking into credit reporting agency Equifax and being responsible for the massive data breach that exposed highly sensitive information on more than 145 million Americans.

    newswww.securityweek.comFeb 10, 2020, 4:03 PM
  • A new threat actor has generated thousands of dollars in the Monero cryptocurrency using remote access tools (RATs) and illicit cryptocurrency mining malware.

    newswww.securityweek.comSep 18, 2019, 6:54 AM
  • A recently detected attack campaign is attempting to ensnare Elasticsearch clusters into a distributed denial of service (DDoS) botnet, Trend Micro reports. The multi-stage attacks leverage scripts to ultimately deliver backdoors to the targeted servers and turn them into DDoS bots.

    newswww.securityweek.comJul 23, 2019, 5:01 PM
  • The Wall Street Journal revealed that Equifax will pay around $700 million to settle with the Federal Trade Commission over the 2017 data breach. According to The Wall Street Journal, Equifax will pay around $700 million to settle with the Federal Trade Commission over the 2017 data breach. The security breach suffered by Equifax in 2017 exposed […]

    newssecurityaffairs.comJul 22, 2019, 1:21 PM
  • Threat actors are targeting Web-based DNA sequencer applications leveraging a still-unpatched zero-day to take over the targeted systems. Starting from June 12, 2019, the researcher Ankit Anubhav from NewSky Security, observed threat actors targeting Web-based DNA sequencer applications. The attackers are leveraging a still-unpatched zero-day vulnerability, tracked as CVE-2017-6526, to gain full control over the […]

    newssecurityaffairs.comJun 17, 2019, 7:29 AM
  • Equifax revealed its earnings release related to the security breach suffered in 2017, the incident has cost about $1.4 billion plus legal fees. Equifax revealed this week its earnings release related to the security breach suffered by the credit bureau back in 2017, the incident has cost about $1.4 billion plus legal fees. In 2017 Equifax confirmed it has suffered […]

    newssecurityaffairs.comMay 12, 2019, 1:27 PM
  • A new cyptojacking campaign targeting enterprises in Asia is leveraging the National Security Agency-linked DoublePulsar backdoor and the EternalBlue exploit for network spreading, Symantec reveals.

    newswww.securityweek.comApr 26, 2019, 2:14 PM
  • Security experts uncovered a new cryptojacking campaign tracked as Beapy that leverages the NSA’s DoublePulsar backdoor and the EternalBlue exploit. Security experts at Symantec have uncovered a new cryptojacking campaign tracked as Beapy that leverages the NSA’s DoublePulsar backdoor and the EternalBlue exploit to spread a cryptocurrency malware on enterprise networks in Asia. “Beapy is […]

    newssecurityaffairs.comApr 26, 2019, 2:05 PM
  • Check Point has published its latest Global Threat Index for September 2018, revealing a near-400% increase in cryptomining malware attacks against Apple iPhones. These attacks are using the Coinhive mining malware, which continues to occupy the top position in the Index that it has held since December 2017. Coinhive now impacts 19% of organizations worldwide. Check Point’s researchers also observed a significant increase in Coinhive attacks against PCs and devices using the Safari browser, which … More →

    newswww.helpnetsecurity.comOct 16, 2018, 5:30 AM
  • A group of hackers is targeting Drupal vulnerabilities, including Drupalgeddon2, patched earlier this year to install a backdoor on compromised servers. Security experts from IBM are targeting Drupal vulnerabilities, including the CVE-2018-7600 and CVE-2018-7602 flaws, aka Drupalgeddon2 and Drupalgeddon3, to install a backdoor on the infected systems and tack full control of the hosted platforms. According to the IBM experts, this last […]

    newssecurityaffairs.comOct 12, 2018, 11:21 AM
  • A threat actor was observed targeting Drupal vulnerabilities patched earlier this year to install a backdoor on compromised servers, IBM reports.

    newswww.securityweek.comOct 11, 2018, 7:09 PM
  • Check Point revealed a significant increase in attacks using the Ramnit banking trojan. Ramnit has doubled its global impact over the past few months, driven by a large scale campaign that has been converting victim’s machines into malicious proxy servers. Ramnit “black” botnet geography During August 2018, Ramnit became the most prevalent banking Trojan in an upward trend in the use of banking Trojans that has more than doubled since June 2018. “This is the … More →

    newswww.helpnetsecurity.comSep 12, 2018, 5:45 AM
  • A new report from the U.S. Government Accountability Office (GAO) provides detailed information of the Equifax hack. The Equifax hack occurred in May 2017 when attackers exploited the CVE-2017-5638 Apache Struts vulnerability in the Jakarta Multipart parser upload function. The flaw allowed the attacker to make a maliciously crafted request to an Apache web server and gain access […]

    newssecurityaffairs.comSep 10, 2018, 2:22 PM
  • The infamous Mirai and Gafgyt Internet of Things (IoT) botnets are targeting vulnerabilities in Apache Struts and the SonicWall Global Management System (GMS), Palo Alto Networks has discovered.

    newswww.securityweek.comSep 10, 2018, 11:58 AM
  • Unit 42 has uncovered new variants of the well-known IoT botnets Mirai and Gafgyt.

    vendorunit42.paloaltonetworks.comSep 10, 2018, 1:27 AM
  • According to the threat intelligence firm Volexity, the CVE-2018-11776 vulnerability is already being abused in malicious attacks in the wild. Just yesterday I wrote about the availability online of the exploit code for the recently discovered Critical remote code execution vulnerability CVE-2018-11776 in Apache Struts 2. The PoC code was published on GitHub and experts were warning of […]

    newssecurityaffairs.comAug 28, 2018, 4:07 PM
  • The Apache Software Foundation revealed last week the existence of a critical Apache Struts flaw (CVE-2018-11776) similar to the one exploited in the Equifax breach and urged organizations and developers to upgrade their installations to versions 2.3.35 or 2.5.17. The vulnerability was flagged by Semmle security researcher Man Yue Mo and the company joined ASF’s entreaties for speedy mitigation. “Previous disclosures of similarly critical vulnerabilities have resulted in exploits being published within a day, putting … More →

    newswww.helpnetsecurity.comAug 27, 2018, 3:26 PM
  • The Exploit code for the recently discovered Critical remote code execution vulnerability CVE-2018-11776 in Apache Struts 2 was published on GitHub, experts fear massive attacks. The CVE-2018-11776 vulnerability affects Struts 2.3 through 2.3.34, Struts 2.5 through 2.5.16, and potentially unsupported versions of the popular Java framework. “Possible Remote Code Execution when using results with no namespace and […]

    newssecurityaffairs.comAug 27, 2018, 3:12 PM
  • Exploit code for a Critical remote code execution vulnerability in Apache Struts 2 was published on GitHub within days after the bug was addressed last week.

    newswww.securityweek.comAug 27, 2018, 9:52 AM
  • Open source components have been increasingly used by developers, but failure to patch vulnerabilities in this type of software can pose serious risks.

    newswww.securityweek.comMay 15, 2018, 3:29 PM
  • A recently discovered crypto-currency mining malware family is using multiple exploits in an attempt to increase its chances of successfully compromising web servers, AlienVault has discovered.

    newswww.securityweek.comMay 3, 2018, 3:58 PM
  • One year after researchers saw the first attempts to exploit a critical remote code execution flaw affecting the Apache Struts 2 framework, hackers continue to scan the Web for vulnerable servers.

    newswww.securityweek.comMar 26, 2018, 3:27 PM
  • The results of the forensic investigation on the massive Equifax hack revealed additional 2.4 Million identities were involved in the security incident. The massive Equifax hack made the headlines again, new revelations about the security breach emerge in the last hours. The credit bureau company announced this week it identified an additional 2.4 million American consumers affected by […]

    newssecurityaffairs.comMar 2, 2018, 1:25 PM
  • New documents provided by Equifax to senators revealed that the security breach suffered by the firm involved additional data for some customers. In 2017 Equifax confirmed it has suffered a massive data breach, cyber criminals stole sensitive personal records of 145 million belonging to US citizens and hundreds of thousands Canada and in the UK. Attackers exploited the CVE-2017-5638 Apache Struts […]

    newssecurityaffairs.comFeb 13, 2018, 9:30 AM
  • If you’re always scrambling to keep your IT infrastructure updated, you might think that newer is always better when it comes to security: new patches, new and more secure hardware, new crypto techniques, etc. But when it comes to fundamentals, some things are eternal. For instance, according to Jeff Williams, CTO and co-founder of Contrast […]

    newswww.csoonline.comJan 30, 2018, 11:05 AM
  • Cybercriminals and nation state groups were quick to adopt the most effective exploits last year, a new AlienVault report reveals.

    newswww.securityweek.comJan 17, 2018, 3:34 PM
  • A sophisticated multi-staged Apache Struts cyber attack campaign is abusing NSA-linked exploits to target internal networks, researchers from F5 Networks have discovered.

    newswww.securityweek.comDec 18, 2017, 3:47 PM
  • Security researchers spotted a sophisticated malware campaign, tracked as Zealot campaign targeting Linux and Windows servers to install Monero miners. Security researchers from F5 Networks spotted a sophisticated malware campaign, tracked as Zealot campaign (after the name zealot.zip, one of the files dropped on targeted servers), targeting Linux and Windows servers to install Monero cryptocurrency miners. The campaign was detected […]

    newssecurityaffairs.comDec 17, 2017, 4:38 PM
  • Companies turn a blind eye to open source riskHelp Net Security

    Though open source software (OSS) helps software suppliers be nimble and build products faster, there are hidden software supply chain risks all software suppliers and IoT manufacturers should know about. For instance, criminals who potentially gained access to the personal data of the Equifax customers exploited an Apache Struts CVE-2017-5638 vulnerability. Apache Struts is a widely used open source component – a framework for Web servers – used by companies in commercial and in-house systems … More →

    newswww.helpnetsecurity.comOct 17, 2017, 2:17 PM
  • Equifax data breach may affect 2.5 million more customers than originally stated, the overall number of exposed individuals reached 145.5 million. Earlier this week, Equifax announced that additional 2.5 million U.S. consumers were exposed as a result of the massive data breach that affected the company in September. The credit reporting agency confirmed that a total of […]

    newssecurityaffairs.comOct 3, 2017, 12:57 PM
  • Oracle fixed several issues in the Apache Struts 2 framework including the flaw CVE-2017-9805 that has been exploited in the wild for the past few weeks. Oracle has released patches for vulnerabilities affecting many of its products, the IT giant has fixed several issues in the Apache Struts 2 framework, including the flaw CVE-2017-9805 that has been exploited […]

    newssecurityaffairs.comSep 26, 2017, 6:34 AM
  • Oracle has released patches for many of its products to address several vulnerabilities in the Apache Struts 2 framework, including one that has been exploited in the wild for the past few weeks.

    newswww.securityweek.comSep 25, 2017, 3:36 PM
  • Equifax has shared more details about the recent breach that affects roughly 143 million U.S. consumers, including how it discovered the unauthorized access and the number of individuals impacted by the incident in the United Kingdom.

    newswww.securityweek.comSep 18, 2017, 9:40 AM
  • Here’s an overview of some of last week’s most interesting news, articles and podcasts: Equifax breach happened because of a missed patch The attackers who breached Equifax managed to do so by exploiting a vulnerability in its US website, the company has finally confirmed. The vulnerability – CVE-2017-5638 – affects Apache Struts 2. Organizations struggle to maximize the value of threat intelligence Amidst growing concerns of large-scale cyber attacks, 84 percent of organizations participating in … More →

    newswww.helpnetsecurity.comSep 18, 2017, 1:30 AM
  • A new round of the weekly SecurityAffairs newsletter arrived! The best news of the week with Security Affairs. · Crooks leverage Facebook CDN servers to bypass security solutions · Mexican tax refund MoneyBack site exposed 400GB of sensitive customer data · Security Affairs newsletter Round 127 – News of the week · Apache Foundation rejects […]

    newssecurityaffairs.comSep 17, 2017, 10:00 AM
  • About 400,000 Britons may have had their information stolen following the Equifax data breach, the news was reported by the UK division of the company. More details are emerging from the recent Equifax data breach that impacted approximately 143 million U.S. consumers. The attackers exploited the CVE-2017-5638 Apache Struts vulnerability that was fixed back in March, but the company […]

    newssecurityaffairs.comSep 17, 2017, 7:54 AM
  • Following the massive data breach that was disclosed on September 7, Equifax announced on Friday that Chief Security Officer Susan Mauldin and Chief Information Officer David Webb are retiring from the company effective immediately.

    newswww.securityweek.comSep 15, 2017, 10:09 PM
  • It’s official, the Equifax data breach case was caused by the exploitation of the CVE-2017-5638 Apache Struts vulnerability. The Equifax data breach case was solved, that incident was caused by the exploitation of the CVE-2017-5638 Apache Struts vulnerability. The vulnerability affects the Jakarta Multipart parser upload function in Apache and could be exploited by an […]

    newssecurityaffairs.comSep 15, 2017, 11:37 AM
  • Equifax breach happened because of a missed patchHelp Net Security

    The attackers who breached Equifax managed to do so by exploiting a vulnerability in its US website, the company has finally confirmed. The vulnerability – CVE-2017-5638 – affects Apache Struts 2. A failure to implement available patch CVE-2017-5638 was flagged in March 2017. It was discovered and reported by Chinese developer Nike Zheng. It was quickly patched by the Apache Struts team, but the disclosure was followed by active attacks via two very reliable exploits … More →

    newswww.helpnetsecurity.comSep 14, 2017, 5:14 PM
  • U.S. credit reporting agency Equifax confirmed on Wednesday that an Apache Struts vulnerability exploited in the wild since March was used to breach its systems.

    newswww.securityweek.comSep 14, 2017, 11:12 AM
  • Have the attackers responsible for the Equifax data breach exploited a vulnerability in Apache Struts, a popular open source framework for developing web applications, to compromise the company’s networks? Equifax has yet to share more details about how the attack was pulled off, but a report by financial services firm Robert W. Baird & Co. says the company’s “understanding” is that it was an Apache Struts flaw that did the trick. Which flaw was it … More →

    newswww.helpnetsecurity.comSep 12, 2017, 2:59 PM
  • Security firm Imperva has detected thousands of attacks attempting to exploit a recently patched remote code execution vulnerability affecting the Apache Struts 2 open source development framework.

    newswww.securityweek.comSep 12, 2017, 9:04 AM
  • Media and experts speculate Equifax Hack was the result of the exploitation of the recently discovered critical vulnerability CVE-2017-9805 in Apache Struts. Last week Equifax reported a huge data breach, hackers accessed its systems between mid-May and late July. The incident affected roughly 143 million U.S. consumers and some customers in the U.K. and Canada. […]

    newssecurityaffairs.comSep 11, 2017, 3:51 PM
  • A vulnerability affecting the Apache Struts 2 open-source development framework was reportedly used to breach U.S. credit reporting agency Equifax and gain access to customer data.

    newswww.securityweek.comSep 11, 2017, 6:16 AM
  • A critical remote code execution vulnerability patched earlier this week in the Apache Struts 2 open-source development framework is already being exploited in the wild.

    newswww.securityweek.comSep 8, 2017, 9:04 AM
  • Equifax breach: What you need to know [updated]Malwarebytes Labs

    [updates 9/14/2017]Equifax has released information and confirmed the vulnerability (CVE-2017-5638) that was used in this breach after several days of intense…

    newswww.malwarebytes.comSep 7, 2017, 5:00 PM
  • The latest version of Apache Struts 2 addresses several vulnerabilities, including a critical remote code execution flaw for which an exploit was created within hours after the release of a patch.

    newswww.securityweek.comSep 6, 2017, 8:12 AM
  • Oracle has pushed out a record-breaking 299 fixes for vulnerabilities in its many, many products, and among them is a Solaris 10 bug whose existence has been revealed through Shadow Brokers’ latest data dump. The Oracle Critical Patch Update for April 2017, detailed in this advisory, addresses vulnerabilities in Oracle Database Server, Fusion Middleware, PeopleSoft Enterprise, Financial Services Applications, MySQL Product Suite, Java, and many other offerings. “The patch update contains 40 vulnerabilities assessed critical … More →

    newswww.helpnetsecurity.comApr 19, 2017, 8:46 PM
  • Cisco issued two “critical” security advisories, one for Cisco IOS and Cisco IOS XE Software, another for a flaw affecting Apache Struts 2. Today Cisco issued two “critical” security advisories, the first one for Cisco IOS and Cisco IOS XE Software, the second one for the recently discovered flaw affecting Apache Struts 2. The vulnerability […]

    newssecurityaffairs.comApr 14, 2017, 1:01 PM
  • Cyber criminals exploited the recently patched Apache Struts 2 vulnerability CVE-2017-5638 in the wild to deliver the Cerber ransomware. A recently patched Apache Struts 2 vulnerability, tracked as CVE-2017-5638, has been exploited by crooks in the wild to deliver the Cerber ransomware. The remote code execution vulnerability affected the Jakarta-based file upload Multipart parser under Apache […]

    newssecurityaffairs.comApr 7, 2017, 6:57 AM
  • Attackers are exploiting a vulnerability patched last month in the Apache Struts web development framework to install ransomware on servers. The SANS Internet Storm Center issued an alert Thursday, saying an attack campaign is compromising Windows servers through a vulnerability tracked as CVE-2017-5638. The flaw is located in the Jakarta Multipart parser in Apache Struts […]

    newswww.csoonline.comApr 6, 2017, 9:14 PM
  • A recently patched Apache Struts 2 vulnerability has been exploited by cybercriminals to deliver Cerber ransomware to Windows systems, researchers warned.

    newswww.securityweek.comApr 6, 2017, 3:08 PM
  • A new round of the weekly SecurityAffairs newsletter arrived! The best news of the week with Security Affairs. First of all, let me inform you that at the #infosec16 SecurityAffairs was awarded as The Best European Personal Security Blog http://securityaffairs.co/wordpress/48202/breaking-news/securityaffairs-best-european-personal-security-blog.html · ELF_IMEIJ, a new Linux malware is spreading in the wild · Security Affairs newsletter Round 103 […]

    newssecurityaffairs.comMar 19, 2017, 7:16 AM
  • Canada Revenue Agency confirmed it shut down its website for filing federal taxes due to a cyber attack leveraging the CVE-2017-5638 flaw in Apache Struts 2 The Canada Revenue Agency (CRA) confirmed it shut down its website for filing federal taxes after hackers broke into the server at the nation’s statistics bureau. The security breach occurred […]

    newssecurityaffairs.comMar 14, 2017, 3:51 PM
  • VMware informed customers on Monday that the recently disclosed Apache Struts2 vulnerability, which has been exploited in the wild over the past week, affects several of its products.

    newswww.securityweek.comMar 14, 2017, 9:48 AM
  • On Friday, Cisco confirmed that at least some of its products are affected by an Apache Struts 2 command execution vulnerability tracked as CVE-2017-5638. The CVE-2017-5638 remote code execution zero-day has been exploiting by attackers in the wild, it affects Struts 2.3.5 through 2.3.31 and Struts 2.5 through 2.5.10. According to the experts from Cisco Talos, the […]

    newssecurityaffairs.comMar 13, 2017, 11:55 AM
  • Cisco informed customers on Friday that at least some of its products are affected by an Apache Struts2 command execution vulnerability that has been exploited in the wild over the past days.

    newswww.securityweek.comMar 13, 2017, 8:48 AM
  • A critical vulnerability in Apache Struts 2 is being actively and heavily exploited, even though the patch for it has been released on Monday. System administrators are encouraged to upgrade to version 2.3.32 or 2.5.10.1 as soon as possible to avoid compromise. What is Apache Struts 2, and how is the vulnerability exploited? Apache Struts 2 is an open source web application framework for developing Java EE web applications. The vulnerability (CVE-2017-5638), discovered and reported … More →

    newswww.helpnetsecurity.comMar 9, 2017, 4:23 PM
  • Researchers have spotted a remote code execution zero-day in Apache Struts 2, the flaw has being exploiting by that threat actors in the wild. Security researchers have spotted a remote code execution zero-day, tracked as CVE-2017-5638, in Apache Struts 2, and the bad news is that threat actors in the wild are already exploiting it. According to […]

    newssecurityaffairs.comMar 9, 2017, 9:05 AM
  • A high severity remote code execution (RCE) vulnerability affecting the Apache Struts 2 framework has been exploited in the wild, warns Cisco’s Talos intelligence and research group.

    newswww.securityweek.comMar 9, 2017, 7:44 AM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence