CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2017-9805

Known Exploited (CISA KEV)HIGH
8.1
CVSS Severity Score
EPSS Score61.7490%
EPSS Percentile94.33th
Published2017年9月15日
Last Modified2026年4月21日

Vulnerability Description

The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.

Affected Platforms (CPE)

📦
Apache

Struts

>= 2.1.2 and < 2.3.34
📦
Apache

Struts

>= 2.5.0 and < 2.5.13
📦
Cisco

Digital Media Manager

All versions
📦
Cisco

Hosted Collaboration Solution

= 10.5\(1\)
📦
Cisco

Hosted Collaboration Solution

= 11.0\(1\)
📦
Cisco

Hosted Collaboration Solution

= 11.5\(1\)
📦
Cisco

Hosted Collaboration Solution

= 11.6\(1\)
📦
Cisco

Media Experience Engine

= 3.5
📦
Cisco

Media Experience Engine

= 3.5.2
📦
Cisco

Network Performance Analysis

All versions
📦
Cisco

Video Distribution Suite For Internet Streaming

All versions
📦
Netapp

Oncommand Balance

All versions

References & Advisories

相關漏洞威脅