{"id":"CVE-2017-9805","details":"The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.","aliases":["GHSA-gg9m-fj3v-r58c"],"modified":"2026-07-08T05:51:52.780573698Z","published":"2017-09-15T19:29:00.237Z","database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:a:cisco:hosted_collaboration_solution:10.5\\(1\\):*:*:*:*:*:*:*","cpe:2.3:a:cisco:hosted_collaboration_solution:11.0\\(1\\):*:*:*:*:*:*:*","cpe:2.3:a:cisco:hosted_collaboration_solution:11.5\\(1\\):*:*:*:*:*:*:*","cpe:2.3:a:cisco:hosted_collaboration_solution:11.6\\(1\\):*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"10.5(1)"},{"last_affected":"10.5(1)"},{"introduced":"11.0(1)"},{"last_affected":"11.0(1)"},{"introduced":"11.5(1)"},{"last_affected":"11.5(1)"},{"introduced":"11.6(1)"},{"last_affected":"11.6(1)"}],"source":"CPE_STRING","vendor_product":"cisco:hosted_collaboration_solution"},{"extracted_events":[{"introduced":"3.5"},{"last_affected":"3.5"},{"introduced":"3.5.2"},{"last_affected":"3.5.2"}],"source":"CPE_STRING","vendor_product":"cisco:media_experience_engine","cpes":["cpe:2.3:a:cisco:media_experience_engine:3.5.2:*:*:*:*:*:*:*","cpe:2.3:a:cisco:media_experience_engine:3.5:*:*:*:*:*:*:*"]}]},"references":[{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-9805"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/100609"},{"type":"ADVISORY","url":"http://www.securitytracker.com/id/1039263"},{"type":"ADVISORY","url":"https://blogs.apache.org/foundation/entry/apache-struts-statement-on-equifax"},{"type":"ADVISORY","url":"https://cwiki.apache.org/confluence/display/WW/S2-052"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20170907-0001/"},{"type":"ADVISORY","url":"https://struts.apache.org/docs/s2-052.html"},{"type":"ADVISORY","url":"https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170907-struts2"},{"type":"ADVISORY","url":"https://www.kb.cert.org/vuls/id/112992"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1488482"},{"type":"FIX","url":"http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-9805-3889403.html"},{"type":"ARTICLE","url":"https://lgtm.com/blog/apache_struts_CVE-2017-9805"},{"type":"EVIDENCE","url":"https://www.exploit-db.com/exploits/42627/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/struts","events":[{"introduced":"f633bb8270ea52b8d168ade14b8721d8739ceab1"},{"fixed":"f0b3a1d213d0018931c8ee85bbddb767f852f539"},{"introduced":"0"},{"fixed":"9f5082615ede714618c8694c418210d43338daf6"}],"database_specific":{"extracted_events":[{"introduced":"2.1.2"},{"fixed":"2.3.34"},{"introduced":"2.5.0"},{"fixed":"2.5.13"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:*"}}],"versions":["STRUTS_2_3_33","STRUTS_2_5_12","STRUTS_2_5_11","STRUTS_2_3_32","STRUTS_2_5_10","STRUTS_2_5_9","STRUTS_2_5_8","STRUTS_2_5_7","STRUTS_2_5_6","STRUTS_2_5_5","STRUTS_2_5_4","STRUTS_2_3_31","STRUTS_2_5_3","STRUTS_2_3_30","STRUTS_2_3_29","STRUTS_2_3_28","STRUTS_2_3_24_1","STRUTS_2_3_27","STRUTS_2_3_26","STRUTS_2_3_25","STRUTS_2_5_BETA2","STRUTS_2_3_24","STRUTS_2_5_BETA1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-9805.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}