CVE-2017-9805

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
15/09/2017
Last modified:
22/10/2025

Description

The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:* 2.1.2 (including) 2.3.34 (excluding)
cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:* 2.5.0 (including) 2.5.13 (excluding)
cpe:2.3:a:cisco:digital_media_manager:-:*:*:*:*:*:*:*
cpe:2.3:a:cisco:hosted_collaboration_solution:10.5\(1\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:hosted_collaboration_solution:11.0\(1\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:hosted_collaboration_solution:11.5\(1\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:hosted_collaboration_solution:11.6\(1\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:media_experience_engine:3.5:*:*:*:*:*:*:*
cpe:2.3:a:cisco:media_experience_engine:3.5.2:*:*:*:*:*:*:*
cpe:2.3:a:cisco:network_performance_analysis:-:*:*:*:*:*:*:*
cpe:2.3:a:cisco:video_distribution_suite_for_internet_streaming:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:oncommand_balance:-:*:*:*:*:*:*:*