CVE-2017-9787: High severity Apache struts vulnerability
Published Jul 13, 2017
·Updated
When using a Spring AOP functionality to secure Struts actions it is possible to perform a DoS attack. Solution is to upgrade to Apache Struts version 2.5.12 or 2.3.33.
Affected Software
55 affected componentsFixes available
maven/org.apache.struts:struts2-core>=2.3.7<2.3.33
2.3.33
maven/org.apache.struts:struts2-core>=2.5.0<2.5.12
2.5.12
Apache struts=2.3.7
Apache struts=2.3.8
Apache struts=2.3.9
Apache struts=2.3.10
Apache struts=2.3.11
Apache struts=2.3.12
Apache struts=2.3.13
Apache struts=2.3.14
Apache struts=2.3.14.1
Apache struts=2.3.14.2
Apache struts=2.3.14.3
Apache struts=2.3.15
Apache struts=2.3.15.1
Apache struts=2.3.15.2
Apache struts=2.3.15.3
Apache struts=2.3.16
Apache struts=2.3.16.1
Apache struts=2.3.16.2
Apache struts=2.3.16.3
Apache struts=2.3.17
Apache struts=2.3.19
Apache struts=2.3.20
Apache struts=2.3.20.1
Apache struts=2.3.20.2
Apache struts=2.3.20.3
Apache struts=2.3.21
Apache struts=2.3.22
Apache struts=2.3.23
Apache struts=2.3.24
Apache struts=2.3.24.1
Apache struts=2.3.24.2
Apache struts=2.3.24.3
Apache struts=2.3.25
Apache struts=2.3.26
Apache struts=2.3.27
Apache struts=2.3.28
Apache struts=2.3.28.1
Apache struts=2.3.29
Apache struts=2.3.30
Apache struts=2.3.31
Apache struts=2.3.32
Apache struts=2.5
Apache struts=2.5.1
Apache struts=2.5.2
Apache struts=2.5.3
Apache struts=2.5.4
Apache struts=2.5.5
Apache struts=2.5.6
Apache struts=2.5.7
Apache struts=2.5.8
Apache struts=2.5.9
Apache struts=2.5.10
Apache struts=2.5.10.1
Event History
Jul 13, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionWeakness
Oct 16, 2018
Advisory Published
07:37 PM
Frequently Asked Questions
1
What is the severity of CVE-2017-9787?
CVE-2017-9787 has a medium severity rating of CVSS v3.0, making it a notable concern for affected systems.
2
How do I fix CVE-2017-9787?
To mitigate CVE-2017-9787, upgrade your Apache Struts installation to version 2.5.12 or 2.3.33.
3
Which applications are affected by CVE-2017-9787?
CVE-2017-9787 affects multiple versions of Apache Struts, specifically those prior to 2.5.12 and 2.3.33.
4
What type of attack can CVE-2017-9787 allow?
CVE-2017-9787 can be exploited to conduct a denial of service (DoS) attack.
5
Is CVE-2017-9787 related to Spring AOP?
Yes, CVE-2017-9787 is a vulnerability that specifically involves Spring AOP in securing Struts actions.