VDB

CVE-2017-9804

CVE-2017-9804 PUBLISHED CVSS 7.5 HIGH

In Apache Struts 2.3.7 through 2.3.33 and 2.5 through 2.5.12, if an application allows entering a URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL. NOTE: this vulnerability exists because of an incomplete fix for S2-047 / CVE-2017-7672.

EPSS 4.62% · 89.5th percentile

Risk Scores

CVSS 3.0
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
4.62%
89.5th percentile

Affected Products

VendorProductVersions
Apache Software FoundationApache Struts2.3.7 - 2.3.33, 2.5 - 2.5.12
apachestruts2.3.8, 2.3.9, 2.3.10
Mavenorg.apache.struts:struts2-core2.5.0, 2.3.7

Timeline

  • Sep 20, 2017 CVE Published
  • Oct 3, 2019 CVE Updated
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Feb 28, 2022 EPSS Score
  • May 2, 2022 EPSS Score
  • Sep 5, 2022 EPSS Score
  • Nov 6, 2022 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Mar 11, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›