CVE detail
CVE-2017-9805
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 13.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
24 source links · newest first
Active since at least 2023, the hacking group has been targeting the financial, government, IT, logistics, retail, and education sectors.
newswww.securityweek.comMay 29, 2025, 4:09 PMThe GitHub Security Lab audits open source projects for security vulnerabilities and helps maintainers fix them. Recently, we passed the milestone of 500 CVEs disclosed. Let’s take a trip down memory lane with a review of some noteworthy CVEs!
vendorgithub.blogSep 21, 2023, 8:56 PMSemmle, a company whose software engineering analytics platform is already used by several major companies, on Tuesday announced its global launch, along with a $21 million Series B funding round.
newswww.securityweek.comAug 21, 2018, 2:58 PMOne year after researchers saw the first attempts to exploit a critical remote code execution flaw affecting the Apache Struts 2 framework, hackers continue to scan the Web for vulnerable servers.
newswww.securityweek.comMar 26, 2018, 3:27 PM- Cryptocurrency mining operations target Windows Server, Redis and Apache Solr servers onlineSecurity Affairs
Researchers from the ISC SANS group and the Anti-DDoS company Imperva discovered two distinct campaigns targeting Windows Server, Redis and Apache Solr servers online. Last week new mining campaigns targeted unpatched Windows Server, Apache Solr, and Redis servers, attackers attempted to install the cryptocurrency miner Coinminer. Two campaigns were spotted by researchers from the ISC SANS group and the […]
newssecurityaffairs.comMar 12, 2018, 7:28 AM - Vulnerable Apache Solr, Redis, Windows servers hit with cryptominersHelp Net Security
Vulnerable servers of all kinds are being targeted, compromised and made to mine cryptocurrencies for the attackers. Apache Solr servers under attack SANS ISC handler Renato Marihno warns about an active campaign aimed at compromising Apache Solr servers. The campaign infected 1777 victims from February 28 to March 8. Of those, 1416 are Solr servers. The attackers are exploiting CVE-2017-12629 for gaining access to the vulnerable servers and delivering Monero-mining malware. The flaw dates back … More →
newswww.helpnetsecurity.comMar 9, 2018, 7:53 PM Oracle on Tuesday released its Critical Patch Update (CPU) for October 2017 to address a total of 252 security vulnerabilities across multiple product families. More than half of the bugs may be remotely exploitable without authentication.
newswww.securityweek.comOct 18, 2017, 3:44 PM- Security Affairs newsletter Round 130 – News of the weekSecurity Affairs
A new round of the weekly SecurityAffairs newsletter arrived! The best news of the week with Security Affairs. Once again thank you! · Authors of Locky Ransomware are big fans Game of Thrones series · Massive HerbaLife spam campaign spreads a variant of Locky ransomware · Passwords and much more for 540,000 SVR Tracking accounts […]
newssecurityaffairs.comOct 1, 2017, 11:07 AM - Oracle releases security patches for Apache Struts CVE-2017-9805 Flaw exploited in the wildSecurity Affairs
Oracle fixed several issues in the Apache Struts 2 framework including the flaw CVE-2017-9805 that has been exploited in the wild for the past few weeks. Oracle has released patches for vulnerabilities affecting many of its products, the IT giant has fixed several issues in the Apache Struts 2 framework, including the flaw CVE-2017-9805 that has been exploited […]
newssecurityaffairs.comSep 26, 2017, 6:34 AM Oracle has released patches for many of its products to address several vulnerabilities in the Apache Struts 2 framework, including one that has been exploited in the wild for the past few weeks.
newswww.securityweek.comSep 25, 2017, 3:36 PM- Security Affairs newsletter Round 128 – News of the weekSecurity Affairs
A new round of the weekly SecurityAffairs newsletter arrived! The best news of the week with Security Affairs. · Crooks leverage Facebook CDN servers to bypass security solutions · Mexican tax refund MoneyBack site exposed 400GB of sensitive customer data · Security Affairs newsletter Round 127 – News of the week · Apache Foundation rejects […]
newssecurityaffairs.comSep 17, 2017, 10:00 AM Following the massive data breach that was disclosed on September 7, Equifax announced on Friday that Chief Security Officer Susan Mauldin and Chief Information Officer David Webb are retiring from the company effective immediately.
newswww.securityweek.comSep 15, 2017, 10:09 PM- CVE-2017-5638 Apache Struts vulnerability is the root cause behind Equifax data breachSecurity Affairs
It’s official, the Equifax data breach case was caused by the exploitation of the CVE-2017-5638 Apache Struts vulnerability. The Equifax data breach case was solved, that incident was caused by the exploitation of the CVE-2017-5638 Apache Struts vulnerability. The vulnerability affects the Jakarta Multipart parser upload function in Apache and could be exploited by an […]
newssecurityaffairs.comSep 15, 2017, 11:37 AM - Equifax Confirms Apache Struts Flaw Used in HackSecurityWeek
U.S. credit reporting agency Equifax confirmed on Wednesday that an Apache Struts vulnerability exploited in the wild since March was used to breach its systems.
newswww.securityweek.comSep 14, 2017, 11:12 AM - Equifax attackers got in through an Apache Struts flaw?Help Net Security
Have the attackers responsible for the Equifax data breach exploited a vulnerability in Apache Struts, a popular open source framework for developing web applications, to compromise the company’s networks? Equifax has yet to share more details about how the attack was pulled off, but a report by financial services firm Robert W. Baird & Co. says the company’s “understanding” is that it was an Apache Struts flaw that did the trick. Which flaw was it … More →
newswww.helpnetsecurity.comSep 12, 2017, 2:59 PM Security firm Imperva has detected thousands of attacks attempting to exploit a recently patched remote code execution vulnerability affecting the Apache Struts 2 open source development framework.
newswww.securityweek.comSep 12, 2017, 9:04 AM- Apache Foundation rejects allegation Equifax hackers exploited CVE-2017-9805 in StrutsSecurity Affairs
Media and experts speculate Equifax Hack was the result of the exploitation of the recently discovered critical vulnerability CVE-2017-9805 in Apache Struts. Last week Equifax reported a huge data breach, hackers accessed its systems between mid-May and late July. The incident affected roughly 143 million U.S. consumers and some customers in the U.K. and Canada. […]
newssecurityaffairs.comSep 11, 2017, 3:51 PM A vulnerability affecting the Apache Struts 2 open-source development framework was reportedly used to breach U.S. credit reporting agency Equifax and gain access to customer data.
newswww.securityweek.comSep 11, 2017, 6:16 AM- Security Affairs newsletter Round 127 – News of the weekSecurity Affairs
A new round of the weekly SecurityAffairs newsletter arrived! The best news of the week with Security Affairs. · FICO reports a 39 Percent Rise in Debit Cards Compromised in US · Google removed almost 300 Android apps involved in DDoS attack · Security Affairs newsletter Round 126 – News of the week · US […]
newssecurityaffairs.comSep 10, 2017, 10:07 AM Hackers are exploiting in the wild a critical remote code execution vulnerability in Apache Struts 2, tracked as CVE-2017-9805, that was patched a few days ago. The vulnerability tracked as CVE-2017-9805 is related to the way Struts deserializes untrusted data, it affects all versions of Apache Struts since 2008, from Struts 2.5 to Struts 2.5.12. The experts warn that […]
newssecurityaffairs.comSep 9, 2017, 7:28 AMA critical remote code execution vulnerability patched earlier this week in the Apache Struts 2 open-source development framework is already being exploited in the wild.
newswww.securityweek.comSep 8, 2017, 9:04 AMA critical vulnerability in Apache Struts, a popular open source framework for developing web applications, opens any server running an app built using it to remote attackers. It can be exploited easily, by sending a specially crafted web request to the application and, according to SANS ISC handler Adrien de Beaupre, a working exploit has already been spotted. About the vulnerability The flaw (CVE-2017-9805) was spotted during a static code analysis by researchers with software … More →
newswww.helpnetsecurity.comSep 6, 2017, 5:11 PMThe latest version of Apache Struts 2 addresses several vulnerabilities, including a critical remote code execution flaw for which an exploit was created within hours after the release of a patch.
newswww.securityweek.comSep 6, 2017, 8:12 AMCritical vulnerability CVE-2017-9805 in Apache Struts could be exploited by attackers to take over affected web servers. Security researchers at LGTM (lgtm.com) have discovered a critical remote code execution vulnerability in the Apache Struts that could be exploited by a remote attacker to run malicious code on the vulnerable servers. “Security researchers at lgtm.com have discovered a critical […]
newssecurityaffairs.comSep 6, 2017, 7:08 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2017-7525CVSS 9.8 · Critical
A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by s…
- CVE-2017-15095CVSS 9.8 · Critical
A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending t…
- CVE-2017-15707CVSS 6.2 · Medium
In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malicious request with specially cra…
- CVE-2016-4461CVSS 8.8 · High
Apache Struts 2.x before 2.3.29 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribute, aka forced double OGNL evaluation. NOTE: this vulnerabi…
- CVE-2017-5638CVSS 9.8 · Critical
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload atte…
- CVE-2026-65883CVSS 10.0 · Critical
Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP objection injection and thereby…