Deserialization of untrusted data in Apache Struts - CVE-2017-9805
Published: September 6, 2017 / Updated: April 6, 2021
Vulnerability identifier: #VU8111
CSH Severity: High
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-9805
CWE-ID: CWE-502
Exploitation vector: Remote access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the server.
The weakness exists due to absent filtration in XStream instance when deserializing XML data within the REST Plugin. A remote attacker can upload a specially crafted XML file to vulnerable Apache Struts installation, trigger the XStreamHandler to process malicious XML payload and execute arbitrary core on the target system.
Successful exploitation of the vulnerability is possible in case the attacker is able to upload XML.
The weakness exists due to absent filtration in XStream instance when deserializing XML data within the REST Plugin. A remote attacker can upload a specially crafted XML file to vulnerable Apache Struts installation, trigger the XStreamHandler to process malicious XML payload and execute arbitrary core on the target system.
Successful exploitation of the vulnerability is possible in case the attacker is able to upload XML.
Affected software
Apache Struts
Cisco Emergency Responder
Cisco Emergency Responder
How to mitigate CVE-2017-9805
Update to version 2.5.13.
Links to Public Exploits and PoC-codes
- Exploit #5268 - CVE-2017-9805-Exploit (Struts 2.5 - 2.5.12 REST Plugin XStream RCE) (April 6, 2021)
- Exploit #4887 - -CVE-2017-9805- (Exploit script for Apache Struts2 REST Plugin XStream RCE (CVE-2017-9805) ) (November 30, 2020)
- Exploit #4657 - S2-052 (CVE-2017-9805 - Exploit) (September 25, 2020)
- Exploit #3457 - CVE-2017-9805-Apache-Struts-Fuzz-N-Sploit (A script to Fuzz and and exploit Apache struts CVE-2017-9805) (July 15, 2020)
- Exploit #2806 - CVE-2017-9805-Exploit (Struts 2.5 - 2.5.12 REST Plugin XStream RCE) (June 2, 2020)
- Exploit #2804 - CVE-2017-9805-Exploit (CVE-2017-9805-Exploit) (June 2, 2020)
- Exploit #2672 - CVE-2017-9805-Exploit (Struts 2.5 - 2.5.12 REST Plugin XStream RCE) (May 18, 2020)
- Exploit #2311 - exphub (Exphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本,最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-10204、CVE-2020-10199、CVE-2020-1938、CVE-2020-2551、CVE-2020-2555、CVE-2020-2883、CVE-2019-17558、CVE-2019-6340) (April 7, 2020)
- Exploit #2297 - Exploits (Containing Self Made Perl Reproducers / PoC Codes) (April 7, 2020)
- Exploit #2265 - CVE-2017-9805-Exploit (Struts 2.5 - 2.5.12 REST Plugin XStream RCE) (April 5, 2020)
- Exploit #2208 - cve5scan (5 CVE scan and exploit) (March 18, 2020)
- Exploit #2097 - -CVE-2017-9805 (Exploit script for Apache Struts2 REST Plugin XStream RCE (CVE-2017-9805)) (March 18, 2020)
- Exploit #1998 - Alien-Framework (Alien-Framework, it is a framework with many CVE exploits and tools to use in pen-testing.) (March 18, 2020)
- Exploit #147 - apache-struts-pwn_CVE-2017-9805 (An exploit for Apache Struts CVE-2017-9805) (March 18, 2020)
- Exploit #1756 - Apache Struts 2 REST Plugin XStream RCE (March 18, 2020)
- Exploit #1300 - Apache Struts 2.5 < 2.5.12 - REST Plugin XStream Remote Code Execution (March 18, 2020)
- Exploit #151 - CVE-in-Ruby (Exploits written & ported to Ruby - no Metasploit) (March 18, 2020)
- Exploit #150 - cve-2017-9805.py (Better Exploit Code For CVE 2017 9805 apache struts) (March 18, 2020)
- Exploit #149 - struts-pwn_CVE-2017-9805 (An exploit for Apache Struts CVE-2017-9805) (March 18, 2020)
- Exploit #148 - S2-052 (CVE-2017-9805 - Exploit) (March 18, 2020)