Lucene search

K
cvelistApacheCVELIST:CVE-2017-9793
HistorySep 05, 2017 - 12:00 a.m.

CVE-2017-9793

2017-09-0500:00:00
apache
www.cve.org
1

7.7 High

AI Score

Confidence

High

0.932 High

EPSS

Percentile

99.1%

The REST Plugin in Apache Struts 2.1.x, 2.3.7 through 2.3.33 and 2.5 through 2.5.12 is using an outdated XStream library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted XML payload.

CNA Affected

[
  {
    "product": "Apache Struts",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "status": "affected",
        "version": "2.3.7 - 2.3.33"
      },
      {
        "status": "affected",
        "version": "2.5 - 2.5.12"
      },
      {
        "status": "affected",
        "version": "2.1.x series"
      }
    ]
  }
]

7.7 High

AI Score

Confidence

High

0.932 High

EPSS

Percentile

99.1%