Code injection in Apache Struts - CVE-2017-5638
Published: March 9, 2017 / Updated: May 11, 2023
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to input validation error in the Jakarta based file upload Multipart parser when processing Content-Type HTTP header. A remote attacker can send a specially crafted HTTP POST request containing malicious Content-Type header and execute arbitrary code on the target system with privileges of the Apache Struts user.
Successful exploitation of this vulnerability may allow an attacker to compromise vulnerable system.
Note: this vulnerability is being actively exploited in the wild.
Affected software
FlashSystem 900 9840-AE2 and 9843-AE2
iVMS-5200
FlashSystem 840 9840-AE1 & 9843-AE1
Sterling Selling and Fulfillment Foundation
IBM Storwize V3500
IBM Storwize V3700
IBM Storwize V5000
IBM Storwize V7000
IBM FlashSystem V9000
How to mitigate CVE-2017-5638
IBM Storwize V3700 - addressed in versions 7.6.1.8, 7.7.1.6, 7.8.1.0
IBM Storwize V5000 - addressed in versions 7.6.1.8, 7.7.1.6, 7.8.1.0
IBM Storwize V7000 - addressed in versions 7.6.1.8, 7.7.1.6, 7.8.1.0
IBM FlashSystem V9000 - addressed in versions 7.6.1.8, 7.7.1.6, 7.8.1.0
Sterling Selling and Fulfillment Foundation - addressed in versions 9.1.0- SFP6, 9.2.0- SFP6, 9.2.1- SFP6, 9.3.0-SFP5, 9.4.0-SFP3, 9.5.0-SFP2
Links to Public Exploits and PoC-codes
- Exploit #9065 - CVE-2017-5638-ApacheStruts2.3.5 (A exploit for CVE-2017-5638. This exploit works on versions 2.3.5-2.3.31 and 2.5 – 2.5.10) (May 11, 2023)
- Exploit #5208 - Apache-Struts-2-CVE-2017-5638-Exploit () (March 12, 2021)
- Exploit #2805 - Apache-Struts2-RCE-Exploit-v2-CVE-2017-5638 () (June 2, 2020)
- Exploit #2673 - Apache-Struts ( An exploit for Apache Struts CVE-2017-5638) (May 18, 2020)
- Exploit #2631 - Apache-Struts ( An exploit for Apache Struts CVE-2017-5638) (May 7, 2020)
- Exploit #2377 - CVE-2018-11776-Python-PoC (Working Python test and PoC for CVE-2018-11776, includes Docker lab) (April 7, 2020)
- Exploit #2337 - struts2_cve-2017-5638 (This is a sort of Java porting of the Python exploit at: https://www.exploit-db.com/exploits/41570/.) (April 7, 2020)
- Exploit #2273 - cve-2017-5638 (Example PoC Code for CVE-2017-5638 | Apache Struts Exploit ) (April 7, 2020)
- Exploit #2272 - Struts-Apache-ExploitPack (These are just some script which you can use to detect and exploit the Apache Struts Vulnerability (CVE-2017-5638)) (April 7, 2020)
- Exploit #2209 - cve5scan (5 CVE scan and exploit) (March 18, 2020)
- Exploit #1992 - Alien-Framework (Alien-Framework, it is a framework with many CVE exploits and tools to use in pen-testing.) (March 18, 2020)
- Exploit #2151 - strutsy (Strutsy - Mass exploitation of Apache Struts (CVE-2017-5638) vulnerability) (March 18, 2020)
- Exploit #2138 - Common-Vulnerability-and-Exploit (This is the Apache Struts CVE-2017-5638 struts 2 vulnerability. The same CVE that resulted in the equifax database breach.) (March 18, 2020)
- Exploit #2137 - S2-045 (CVE-2017-5638 - Exploit) (March 18, 2020)
- Exploit #2131 - Struts2Shell (An exploit (and library) for CVE-2017-5638 - Apache Struts2 S2-045 bug.) (March 18, 2020)
- Exploit #2129 - Apache-Struts ( An exploit for Apache Struts CVE-2017-5638) (March 18, 2020)
- Exploit #2088 - Stutsfi (An exploit for CVE-2017-5638 Remote Code Execution (RCE) Vulnerability in Apache Struts 2) (March 18, 2020)
- Exploit #2058 - struts2-rce (Exploitable target to CVE-2017-5638) (March 18, 2020)
- Exploit #1988 - CVE-2017-5638 (CVE-2017-5638 (PoC Exploits)) (March 18, 2020)
- Exploit #1974 - cybersecurity-struts2 (Struts2 Application Vulnerable to CVE-2017-5638. Explains how the exploit of the vulnerability works in relation to OGNL and the JakartaMultiPart parser.) (March 18, 2020)
- Exploit #1958 - CVE-2017-5638-Mass-Exploit () (March 18, 2020)
- Exploit #1903 - CVE-2017-5638-Apache-Struts2 (Example PHP Exploiter for CVE-2017-5638) (March 18, 2020)
- Exploit #1898 - Struts-Apache-ExploitPack (These are just some script which you can use to detect and exploit the Apache Struts Vulnerability (CVE-2017-5638)) (March 18, 2020)
- Exploit #1899 - ExpStruts (A php based exploiter for CVE-2017-5638.) (March 18, 2020)
- Exploit #1900 - apache-struts2-CVE-2017-5638 (Demo Application and Exploit) (March 18, 2020)
- Exploit #1911 - CVE-2017-5638 (Struts02 s2-045 exploit program) (March 18, 2020)
- Exploit #1921 - struts2-jakarta-inject (Golang exploit for CVE-2017-5638) (March 18, 2020)
- Exploit #1922 - struts-rce (Apache Struts CVE-2017-5638 RCE exploitation) (March 18, 2020)
- Exploit #1944 - struts-pwn (An exploit for Apache Struts CVE-2017-5638) (March 18, 2020)
- Exploit #126 - Apache-Struts2-RCE-Exploit-v2-CVE-2017-5638 () (March 18, 2020)
- Exploit #1758 - Apache Struts Jakarta Multipart Parser OGNL Injection (March 18, 2020)
- Exploit #1060 - Apache Struts Jakarta - Multipart Parser OGNL Injection (Metasploit) (March 18, 2020)
- Exploit #1059 - Apache Struts 2.3.5 < 2.3.31 / 2.5 < 2.5.10 - Remote Code Execution (March 18, 2020)
- Exploit #128 - labs (Vulnerability Labs for security analysis) (March 18, 2020)
- Exploit #127 - Apache-Struts-2-CVE-2017-5638-Exploit- (Exploit created by: R4v3nBl4ck end Pacman) (March 18, 2020)