CVE-2017-9793: Input Validation
Published Sep 20, 2017
·Updated
The REST Plugin in Apache Struts 2.1.x, 2.3.7 through 2.3.33 and 2.5 through 2.5.12 is using an outdated XStream library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted XML payload.
Affected Software
55 affected components
Apache struts=2.3.7
Apache struts=2.3.8
Apache struts=2.3.9
Apache struts=2.3.10
Apache struts=2.3.11
Apache struts=2.3.12
Apache struts=2.3.13
Apache struts=2.3.14
Apache struts=2.3.14.1
Apache struts=2.3.14.2
Apache struts=2.3.14.3
Apache struts=2.3.15
Apache struts=2.3.15.1
Apache struts=2.3.15.2
Apache struts=2.3.15.3
Apache struts=2.3.16
Apache struts=2.3.16.1
Apache struts=2.3.16.2
Apache struts=2.3.16.3
Apache struts=2.3.17
Apache struts=2.3.19
Apache struts=2.3.20
Apache struts=2.3.20.1
Apache struts=2.3.20.2
Apache struts=2.3.21
Apache struts=2.3.22
Apache struts=2.3.23
Apache struts=2.3.24.2
Apache struts=2.3.24.3
Apache struts=2.3.25
Apache struts=2.3.26
Apache struts=2.3.27
Apache struts=2.3.28
Apache struts=2.3.28.1
Apache struts=2.3.29
Apache struts=2.3.30
Apache struts=2.3.31
Apache struts=2.3.32
Apache struts=2.3.33
Apache struts=2.5
Apache struts=2.5-beta1
Apache struts=2.5-beta2
Apache struts=2.5-beta3
Apache struts=2.5.1
Apache struts=2.5.2
Apache struts=2.5.3
Apache struts=2.5.4
Apache struts=2.5.5
Apache struts=2.5.6
Apache struts=2.5.7
Apache struts=2.5.8
Apache struts=2.5.9
Apache struts=2.5.10
Apache struts=2.5.10.1
Apache struts=2.5.12
Remediation
Patch Available
Event History
Sep 20, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-9793?
CVE-2017-9793 is considered a medium severity vulnerability that allows for a Denial of Service (DoS) attack.
2
How do I fix CVE-2017-9793?
To fix CVE-2017-9793, update Apache Struts to version 2.5.13 or later.
3
What versions of Apache Struts are affected by CVE-2017-9793?
CVE-2017-9793 affects Apache Struts versions 2.1.x, 2.3.7 through 2.3.33, and 2.5 through 2.5.12.
4
What kind of attack can CVE-2017-9793 enable?
CVE-2017-9793 can enable attackers to perform denial-of-service (DoS) attacks using specially crafted XML payloads.
5
Is there a workaround for CVE-2017-9793 if I can't update?
There is no specific workaround for CVE-2017-9793; updating to a secure version is the recommended action.