CVE-2017-9793
published 2017-09-20CVE-2017-9793: The REST Plugin in Apache Struts 2.1.x, 2.3.7 through 2.3.33 and 2.5 through 2.5.12 is using an outdated XStream library which is vulnerable and allow perform…
PriorityP346high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
9.02%
94.7th percentile
The REST Plugin in Apache Struts 2.1.x, 2.3.7 through 2.3.33 and 2.5 through 2.5.12 is using an outdated XStream library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted XML payload.
Affected
55 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Multiple Vulnerabilities in Apache Struts 2 Affecting Cisco Products: September 2017
vendor_cisco·2017-09-07
CVE-2017-9793 [CRITICAL] CWE-20 Multiple Vulnerabilities in Apache Struts 2 Affecting Cisco Products: September 2017
Multiple Vulnerabilities in Apache Struts 2 Affecting Cisco Products: September 2017
On September 5, 2017, the Apache Software Foundation released security bulletins that disclosed three vulnerabilities in the Apache Struts 2 package. Of these vulnerabilities, the Apache Software Foundation classifies one as Critical Severity, one as Medium Severity, and one as Low Severity. For more information about the vulnerabilities, refer to the Details section of this advisory.
Multiple Cisco products incorporate a version of the Apache Struts 2 package that is affected by these vulnerabilities.
The following Snort rule can be used to detect possible exploitation of this vulnerability: Snort SIDs 44315 and 44327 through 44330.
This advisory is available at the following link:
https://sec.clouda
Red Hat
struts: DoS attack via crafted XML payload processed by REST Plugin using XStream library
vendor_redhat·2017-09-05·CVSS 7.5
CVE-2017-9793 [HIGH] CWE-20 struts: DoS attack via crafted XML payload processed by REST Plugin using XStream library
struts: DoS attack via crafted XML payload processed by REST Plugin using XStream library
The REST Plugin in Apache Struts 2.1.x, 2.3.7 through 2.3.33 and 2.5 through 2.5.12 is using an outdated XStream library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted XML payload.
A flaw was found in the Struts REST plugin when using an outdated XStream library. An attacker could perform a denial of service attack using a malicious request with specially crafted XML payload.
Statement: A previous statement by Red Hat related to this CVE, prior to August 2019, said that Apache Struts 2 is not included in any Red Hat products. This earlier statement was incorrect. While Struts 2 is not actively compiled, shipped, used, or enabled in any Red Hat prov
Cisco
Multiple Vulnerabilities in Apache Struts 2 Affecting Cisco Products: September 2017
vendor_cisco
CVE-2017-9793 Multiple Vulnerabilities in Apache Struts 2 Affecting Cisco Products: September 2017
CVE-2017-9793: Multiple Vulnerabilities in Apache Struts 2 Affecting Cisco Products: September 2017
On September 5, 2017, the Apache Software Foundation released security bulletins that disclosed three vulnerabilities in the Apache Struts 2 package. Of these vulnerabilities, the Apache Software Foundation classifies one as Critical Severity , one as Medium Severity , and one as Low Severity . For more information about the vulnerabilities, refer to the
CWE: CWE-20, CWE-399, CWE-20, CWE-399
Bug IDs: CSCvf86117, CSCvf86119, CSCvf86143, CSCvf86124, CSCvf86134
GHSA
The REST Plugin in Apache Struts is using an outdated XStream library
ghsa·2018-10-16
CVE-2017-9793 [HIGH] CWE-20 The REST Plugin in Apache Struts is using an outdated XStream library
The REST Plugin in Apache Struts is using an outdated XStream library
The REST Plugin in Apache Struts 2.3.7 through 2.3.33 and 2.5 through 2.5.12 is using an outdated XStream library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted XML payload.
OSV
The REST Plugin in Apache Struts is using an outdated XStream library
osv·2018-10-16
CVE-2017-9793 [HIGH] The REST Plugin in Apache Struts is using an outdated XStream library
The REST Plugin in Apache Struts is using an outdated XStream library
The REST Plugin in Apache Struts 2.3.7 through 2.3.33 and 2.5 through 2.5.12 is using an outdated XStream library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted XML payload.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-9793 CVE-2017-9805 struts: various flaws [epel-7]
bugzilla·2017-09-05·CVSS 7.5
CVE-2017-9793 [HIGH] CVE-2017-9793 CVE-2017-9805 struts: various flaws [epel-7]
CVE-2017-9793 CVE-2017-9805 struts: various flaws [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template to for the 'fedpkg update' request
Bugzilla
CVE-2017-9793 CVE-2017-9805 struts: various flaws [fedora-all]
bugzilla·2017-09-05·CVSS 7.5
CVE-2017-9793 [HIGH] CVE-2017-9793 CVE-2017-9805 struts: various flaws [fedora-all]
CVE-2017-9793 CVE-2017-9805 struts: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. Whi
Bugzilla
CVE-2017-9793 struts: DoS attack via crafted XML payload processed by REST Plugin using XStream library
bugzilla·2017-09-05·CVSS 7.5
CVE-2017-9793 [HIGH] CVE-2017-9793 struts: DoS attack via crafted XML payload processed by REST Plugin using XStream library
CVE-2017-9793 struts: DoS attack via crafted XML payload processed by REST Plugin using XStream library
The REST Plugin is using outdated XStream library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted XML payload.
Affected versions:
Struts 2.3.7 - Struts 2.3.33, Struts 2.5 - Struts 2.5.12
External References:
https://struts.apache.org/docs/s2-051.html
Discussion:
Created struts tracking bugs for this issue:
Affects: epel-7 [bug 1488487]
Affects: fedora-all [bug 1488488]
---
Statement:
A previous statement by Red Hat related to this CVE, prior to August 2019, said that Apache Struts 2 is not included in any Red Hat products. This earlier statement was incorrect. While Struts 2 is not actively compiled, shipped, used, or enabled i
http://www.brocade.com/content/dam/common/documents/content-types/security-bulletin/brocade-security-advisory-2017-429.htmhttp://www.oracle.com/technetwork/security-advisory/alert-cve-2017-9805-3889403.htmlhttp://www.securityfocus.com/bid/100611http://www.securitytracker.com/id/1039262https://security.netapp.com/advisory/ntap-20180629-0001/https://struts.apache.org/docs/s2-051.htmlhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170907-struts2http://www.brocade.com/content/dam/common/documents/content-types/security-bulletin/brocade-security-advisory-2017-429.htmhttp://www.oracle.com/technetwork/security-advisory/alert-cve-2017-9805-3889403.htmlhttp://www.securityfocus.com/bid/100611http://www.securitytracker.com/id/1039262https://security.netapp.com/advisory/ntap-20180629-0001/https://struts.apache.org/docs/s2-051.htmlhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170907-struts2
2017-09-20
Published