← Browse

CVE-2017-9805

Act now ● On CISA KEV — actively exploited

Actively exploited — on the CISA KEV list.

CVSS base
EPSS — probability of exploitation (30 days)
99.4%
99.9th percentile
CISA KEV
Listed
Added 2021-11-03 · patch by 2022-05-03
Weakness / dates
Published — · modified —

Description

Apache Struts REST Plugin uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to remote code execution when deserializing XML payloads.

Official: NVD · CVE.org