CVE-2017-9791
Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
Vulnerability Description
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.
Affected Platforms (CPE)
π¦
Apache
Struts
= 2.3.1π¦
Apache
Struts
= 2.3.1.1π¦
Apache
Struts
= 2.3.1.2π¦
Apache
Struts
= 2.3.3π¦
Apache
Struts
= 2.3.4π¦
Apache
Struts
= 2.3.4.1π¦
Apache
Struts
= 2.3.7π¦
Apache
Struts
= 2.3.8π¦
Apache
Struts
= 2.3.12π¦
Apache
Struts
= 2.3.14π¦
Apache
Struts
= 2.3.14.1π¦
Apache
Struts
= 2.3.14.2π¦
Apache
Struts
= 2.3.14.3π¦
Apache
Struts
= 2.3.15π¦
Apache
Struts
= 2.3.15.1π¦
Apache
Struts
= 2.3.15.2π¦
Apache
Struts
= 2.3.15.3π¦
Apache
Struts
= 2.3.16π¦
Apache
Struts
= 2.3.16.1π¦
Apache
Struts
= 2.3.16.2π¦
Apache
Struts
= 2.3.16.3π¦
Apache
Struts
= 2.3.20π¦
Apache
Struts
= 2.3.20.1π¦
Apache
Struts
= 2.3.20.3π¦
Apache
Struts
= 2.3.24π¦
Apache
Struts
= 2.3.24.1π¦
Apache
Struts
= 2.3.24.3π¦
Apache
Struts
= 2.3.28π¦
Apache
Struts
= 2.3.28.1π¦
Apache
Struts
= 2.3.29π¦
Apache
Struts
= 2.3.30π¦
Apache
Struts
= 2.3.31π¦
Apache
