7.5
CVSSv3

CVE-2017-9804

Published: 20/09/2017 Updated: 03/10/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

In Apache Struts 2.3.7 up to and including 2.3.33 and 2.5 up to and including 2.5.12, if an application allows entering a URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL. NOTE: this vulnerability exists because of an incomplete fix for S2-047 / CVE-2017-7672.

Vulnerable Product Search on Vulmon Subscribe to Product

apache struts 2.5.9

apache struts 2.3.28

apache struts 2.3.20.2

apache struts 2.5

apache struts 2.3.15

apache struts 2.3.25

apache struts 2.5.2

apache struts 2.3.14

apache struts 2.3.32

apache struts 2.3.13

apache struts 2.3.16

apache struts 2.3.24.2

apache struts 2.3.17

apache struts 2.5.10

apache struts 2.3.22

apache struts 2.5.6

apache struts 2.3.9

apache struts 2.3.16.3

apache struts 2.3.23

apache struts 2.3.24.3

apache struts 2.3.15.2

apache struts 2.3.29

apache struts 2.3.14.3

apache struts 2.3.19

apache struts 2.3.20.1

apache struts 2.3.8

apache struts 2.3.30

apache struts 2.3.7

apache struts 2.5.1

apache struts 2.3.28.1

apache struts 2.5.4

apache struts 2.3.14.2

apache struts 2.5.7

apache struts 2.5.5

apache struts 2.3.10

apache struts 2.3.15.1

apache struts 2.3.16.2

apache struts 2.5.3

apache struts 2.3.26

apache struts 2.3.12

apache struts 2.3.27

apache struts 2.3.31

apache struts 2.3.21

apache struts 2.3.20

apache struts 2.3.11

apache struts 2.3.15.3

apache struts 2.5.10.1

apache struts 2.3.16.1

apache struts 2.5.8

apache struts 2.3.14.1

apache struts 2.3.33

apache struts 2.5.12

Vendor Advisories

In Apache Struts 237 through 2333 and 25 through 2512, if an application allows entering a URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL NOTE: this vulnerability exists because of an incomplete fix for S2-047 ...
On September 5, 2017, the Apache Software Foundation released security bulletins that disclosed three vulnerabilities in the Apache Struts 2 package Of these vulnerabilities, the Apache Software Foundation classifies one as Critical Severity, one as Medium Severity, and one as Low Severity For more information about the vulnerabilities, refer to ...

Github Repositories

图书推荐系统

WsylibBookRS 主要内容: 解决目前学校图书管理系统不能由学生推荐图书到图书馆的问题,经过使用测试,符合生产使用环境 使用技术 spring 4318 spring jdbc 4318 struts 2518 mysql 57 开发环境 eclipse    maven 35 建议及其pull 如果你对本项目感兴趣,请动一动的你尊贵的小手,fork

Recent Articles

Oracle corrals and patches Struts 2 vulnerabilities
The Register • Richard Chirgwin • 27 Sep 2017

Big Red issues out-of-band patch for Apache and a few other urgent issues

Oracle has stepped outside its usual quarterly security fix cycle to address the latest Apache Struts 2 vulnerability. Ever since it emerged at the start of September, CVE-2017-9805 has been (in the words of a former Australian prime minister) “a shiver looking for a spine to crawl up”, because so many vendors use Apache to build Web interfaces and bake Struts 2 into their their Web application framework. Big Red's sprawling product set meant fixes had to be deployed across more than 20 prod...