Skip to main content

CVE detail

CVE-2017-9805

The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.

CVSS 8.1 · HighBuzz score 68.0KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 68.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 13.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
30.0
24 evidence mentions in the snapshot
Diversity score
13.0
4 sources across 2 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
24 source links · newest first
  • Active since at least 2023, the hacking group has been targeting the financial, government, IT, logistics, retail, and education sectors.

    newswww.securityweek.comMay 29, 2025, 4:09 PM
  • The GitHub Security Lab audits open source projects for security vulnerabilities and helps maintainers fix them. Recently, we passed the milestone of 500 CVEs disclosed. Let’s take a trip down memory lane with a review of some noteworthy CVEs!

    vendorgithub.blogSep 21, 2023, 8:56 PM
  • Semmle, a company whose software engineering analytics platform is already used by several major companies, on Tuesday announced its global launch, along with a $21 million Series B funding round.

    newswww.securityweek.comAug 21, 2018, 2:58 PM
  • One year after researchers saw the first attempts to exploit a critical remote code execution flaw affecting the Apache Struts 2 framework, hackers continue to scan the Web for vulnerable servers.

    newswww.securityweek.comMar 26, 2018, 3:27 PM
  • Researchers from the ISC SANS group and the Anti-DDoS company Imperva discovered two distinct campaigns targeting Windows Server, Redis and Apache Solr servers online. Last week new mining campaigns targeted unpatched Windows Server, Apache Solr, and Redis servers, attackers attempted to install the cryptocurrency miner Coinminer. Two campaigns were spotted by researchers from the ISC SANS group and the […]

    newssecurityaffairs.comMar 12, 2018, 7:28 AM
  • Vulnerable servers of all kinds are being targeted, compromised and made to mine cryptocurrencies for the attackers. Apache Solr servers under attack SANS ISC handler Renato Marihno warns about an active campaign aimed at compromising Apache Solr servers. The campaign infected 1777 victims from February 28 to March 8. Of those, 1416 are Solr servers. The attackers are exploiting CVE-2017-12629 for gaining access to the vulnerable servers and delivering Monero-mining malware. The flaw dates back … More →

    newswww.helpnetsecurity.comMar 9, 2018, 7:53 PM
  • Oracle on Tuesday released its Critical Patch Update (CPU) for October 2017 to address a total of 252 security vulnerabilities across multiple product families. More than half of the bugs may be remotely exploitable without authentication.

    newswww.securityweek.comOct 18, 2017, 3:44 PM
  • A new round of the weekly SecurityAffairs newsletter arrived! The best news of the week with Security Affairs. Once again thank you! · Authors of Locky Ransomware are big fans Game of Thrones series · Massive HerbaLife spam campaign spreads a variant of Locky ransomware · Passwords and much more for 540,000 SVR Tracking accounts […]

    newssecurityaffairs.comOct 1, 2017, 11:07 AM
  • Oracle fixed several issues in the Apache Struts 2 framework including the flaw CVE-2017-9805 that has been exploited in the wild for the past few weeks. Oracle has released patches for vulnerabilities affecting many of its products, the IT giant has fixed several issues in the Apache Struts 2 framework, including the flaw CVE-2017-9805 that has been exploited […]

    newssecurityaffairs.comSep 26, 2017, 6:34 AM
  • Oracle has released patches for many of its products to address several vulnerabilities in the Apache Struts 2 framework, including one that has been exploited in the wild for the past few weeks.

    newswww.securityweek.comSep 25, 2017, 3:36 PM
  • A new round of the weekly SecurityAffairs newsletter arrived! The best news of the week with Security Affairs. · Crooks leverage Facebook CDN servers to bypass security solutions · Mexican tax refund MoneyBack site exposed 400GB of sensitive customer data · Security Affairs newsletter Round 127 – News of the week · Apache Foundation rejects […]

    newssecurityaffairs.comSep 17, 2017, 10:00 AM
  • Following the massive data breach that was disclosed on September 7, Equifax announced on Friday that Chief Security Officer Susan Mauldin and Chief Information Officer David Webb are retiring from the company effective immediately.

    newswww.securityweek.comSep 15, 2017, 10:09 PM
  • It’s official, the Equifax data breach case was caused by the exploitation of the CVE-2017-5638 Apache Struts vulnerability. The Equifax data breach case was solved, that incident was caused by the exploitation of the CVE-2017-5638 Apache Struts vulnerability. The vulnerability affects the Jakarta Multipart parser upload function in Apache and could be exploited by an […]

    newssecurityaffairs.comSep 15, 2017, 11:37 AM
  • U.S. credit reporting agency Equifax confirmed on Wednesday that an Apache Struts vulnerability exploited in the wild since March was used to breach its systems.

    newswww.securityweek.comSep 14, 2017, 11:12 AM
  • Have the attackers responsible for the Equifax data breach exploited a vulnerability in Apache Struts, a popular open source framework for developing web applications, to compromise the company’s networks? Equifax has yet to share more details about how the attack was pulled off, but a report by financial services firm Robert W. Baird & Co. says the company’s “understanding” is that it was an Apache Struts flaw that did the trick. Which flaw was it … More →

    newswww.helpnetsecurity.comSep 12, 2017, 2:59 PM
  • Security firm Imperva has detected thousands of attacks attempting to exploit a recently patched remote code execution vulnerability affecting the Apache Struts 2 open source development framework.

    newswww.securityweek.comSep 12, 2017, 9:04 AM
  • Media and experts speculate Equifax Hack was the result of the exploitation of the recently discovered critical vulnerability CVE-2017-9805 in Apache Struts. Last week Equifax reported a huge data breach, hackers accessed its systems between mid-May and late July. The incident affected roughly 143 million U.S. consumers and some customers in the U.K. and Canada. […]

    newssecurityaffairs.comSep 11, 2017, 3:51 PM
  • A vulnerability affecting the Apache Struts 2 open-source development framework was reportedly used to breach U.S. credit reporting agency Equifax and gain access to customer data.

    newswww.securityweek.comSep 11, 2017, 6:16 AM
  • A new round of the weekly SecurityAffairs newsletter arrived! The best news of the week with Security Affairs. · FICO reports a 39 Percent Rise in Debit Cards Compromised in US · Google removed almost 300 Android apps involved in DDoS attack · Security Affairs newsletter Round 126 – News of the week · US […]

    newssecurityaffairs.comSep 10, 2017, 10:07 AM
  • Hackers are exploiting in the wild a critical remote code execution vulnerability in Apache Struts 2, tracked as CVE-2017-9805, that was patched a few days ago. The vulnerability tracked as CVE-2017-9805 is related to the way Struts deserializes untrusted data, it affects all versions of Apache Struts since 2008, from Struts 2.5 to Struts 2.5.12. The experts warn that […]

    newssecurityaffairs.comSep 9, 2017, 7:28 AM
  • A critical remote code execution vulnerability patched earlier this week in the Apache Struts 2 open-source development framework is already being exploited in the wild.

    newswww.securityweek.comSep 8, 2017, 9:04 AM
  • A critical vulnerability in Apache Struts, a popular open source framework for developing web applications, opens any server running an app built using it to remote attackers. It can be exploited easily, by sending a specially crafted web request to the application and, according to SANS ISC handler Adrien de Beaupre, a working exploit has already been spotted. About the vulnerability The flaw (CVE-2017-9805) was spotted during a static code analysis by researchers with software … More →

    newswww.helpnetsecurity.comSep 6, 2017, 5:11 PM
  • The latest version of Apache Struts 2 addresses several vulnerabilities, including a critical remote code execution flaw for which an exploit was created within hours after the release of a patch.

    newswww.securityweek.comSep 6, 2017, 8:12 AM
  • Critical vulnerability CVE-2017-9805 in Apache Struts could be exploited by attackers to take over affected web servers. Security researchers at LGTM (lgtm.com) have discovered a critical remote code execution vulnerability in the Apache Struts that could be exploited by a remote attacker to run malicious code on the vulnerable servers. “Security researchers at lgtm.com have discovered a critical […]

    newssecurityaffairs.comSep 6, 2017, 7:08 AM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence