CVE-2017-9804 PUBLISHED CVSS 7.5 HIGH

In Apache Struts 2.3.7 through 2.3.33 and 2.5 through 2.5.12, if an application allows entering a URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL. NOTE: this vulnerability exists because of an incomplete fix for S2-047 / CVE-2017-7672.

EPSS 4.62% · 89.2th percentile

Risk Scores

CVSS v3.0
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
4.62%
89.2th percentile

Affected Products

VendorProductVersions
Apache Software FoundationApache Struts2.3.7 - 2.3.33, 2.5 - 2.5.12
apachestruts2.5.12, 2.5.10, 2.5.10.1
Mavenorg.apache.struts:struts2-core2.5.0, 2.3.7

Timeline

References

Open in Interactive Console →