CVE-2017-9805
KEVHIGH 8.1EPSS 99.4%
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.
- CVSS v3.1
- 8.1 HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 8.1 HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.0
- 8.1 HIGH
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H - CVSS v2.0
- 6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P - EPSS
- 99.40% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2021-11-03
- Nuclei
- high · CWE-502
- Published
- 2017-09-15
- Updated
- 2025-10-21
Proof-of-concept exploits (25)
- 0x00-0x00/-CVE-2017-980515★ · 2020-11-26
- 0xd3vil/CVE-2017-9805-Exploit1★ · 2021-04-04
- AvishkaSenadheera/CVE-2017-9805---Documentation---IT191433780★ · 2020-05-12
- BeyondCy/S2-0521★ · 2017-10-20
- Lone-Ranger/apache-struts-pwn_CVE-2017-98055★ · 2017-09-10
- RayScri/Struts2-052-POC3★ · 2019-04-10
- SavoBit/apache-exploit-demo0★ · 2019-01-30
- Shakun8/CVE-2017-98053★ · 2022-10-03
- UbuntuStrike/CVE-2017-9805-Apache-Struts-Fuzz-N-Sploit0★ · 2019-09-02
- UbuntuStrike/struts_rest_rce_fuzz-CVE-2017-9805-1★ · 2019-08-31
- Vancir/s2-052-reproducing20★ · 2019-05-20
- chrisjd20/cve-2017-9805.py21★ · 2017-12-23
- hahwul/struts2-rce-cve-2017-9805-ruby3★ · 2017-09-07
- jongmartinez/-CVE-2017-9805-1★ · 2020-11-28
- luc10/struts-rce-cve-2017-980560★ · 2020-08-31
- mazen160/struts-pwn_CVE-2017-9805247★ · 2017-11-07
- rvermeulen/apache-struts-cve-2017-98050★ · 2020-11-13
- samqbush/struts-rest-showcase0★ · 2021-06-14
- sujithvaddi/apache_struts_cve_2017_98050★ · 2021-08-20
- wifido/CVE-2017-9805-Exploit0★ · 2020-05-17
- z3bd/CVE-2017-98050★ · 2021-03-05
- 7s26simon/CVE-2017-9805-S2-052
- Fl5xia/CVE-2017-9805
- NoSpaceAvailable/CVE-2017-9805_example_build
- agent3137/CVE-2017-9805-Exploit