struts2: RCE when performing file upload based on Jakarta Multipart parser
Published Mar 11, 2017 ·Due May 3, 2022
9.8
CRITICALCVSS 3.1
EPSS 100.00%
Description
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header, as exploited in the wild in March 2017 with a Content-Type header containing a #cmd= string.
Affected products
-
- Version 2.3.x before 2.3.32StatusaffectedConstraints-
- Version 2.5.x before 2.5.10.1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Apache Software Foundation | Apache Struts | n/a |
|
Configuration 1
Configuration 2
- 7.7.1.6
- 7.8.1.0
Running on/with
- n/a
Configuration 3
- 7.7.1.6
- 7.8.1.0
Running on/with
- n/a
Configuration 4
- 7.7.1.6
- 7.8.1.0
Running on/with
- n/a
Configuration 5
- 7.7.1.6
- 7.8.1.0
Running on/with
- n/a
Configuration 6
- 9.1.0
- 10.0.0
- 10.1.0
- 10.2.0
- 10.5.0
Configuration 7
- 10.3.6.0.0
- 12.1.3.0.0
- 12.2.1.1.0
- 12.2.1.2.0
Configuration 8
- < 6.6.5
Configuration 9
- n/a
No data.
Red Hat JBoss Fuse Service Works 6
struts2-core
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat JBoss Fuse Service Works 6 | struts2-core | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
A previous statement by Red Hat related to this CVE, prior to August 2019, said that Apache Struts 2 is not included in any Red Hat products. This earlier statement was incorrect. While Struts 2 is not actively compiled, shipped, used, or enabled in any Red Hat provided final products, and does not cause any vulnerability in the product, struts2-core jars have been included in some products' source code packages. The inclusion was part of an import of the Google Guice repository, which includes struts2-core. Customers that build artefacts from our source code could be at risk. Red Hat will remove these artefacts from source code in future releases. The products that included the Struts 2 artefacts in their source jars: Fuse Service Works 6.0.0 Single Sign On 7.3.0+ If you have used the source package from one of these products to build artefacts on your system, you should do the following to remove potentially affected jars: 1. Run 'find . -name struts2*.jar' under the source location 2. Remove any files found This will not affect the product, as the jar is included with the source of google-guice, but no functionality requiring struts2 is implemented.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:H
1 other source (Red Hat) ▾
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AV:N/AC:L/Au:N/C:C/I:C/A:C
Date Added
Nov 3, 2021
Patch Due
May 3, 2022
Required Action
Apply updates per vendor instructions.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
YesTechnical Impact
TotalDecision
n/aAssessed Feb 6, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (20 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 100.00% (0.99999) | 99.99th | v5 (v2026.06.15) |
| Jun 15, 2026 | 100.00% (0.99999) | 99.99th | v5 (v2026.06.15) |
| Mar 17, 2025 | 94.34% (0.94341) | 99.95th | v4 (v2025.03.14) |
| Dec 12, 2024 | 96.54% (0.96541) | 99.67th | v3 (v2023.03.01) |
| Aug 21, 2024 | 96.54% (0.96541) | 99.65th | v3 (v2023.03.01) |
| May 3, 2024 | 97.54% (0.97542) | 100.00th | v3 (v2023.03.01) |
| Mar 23, 2024 | 97.53% (0.97529) | 99.99th | v3 (v2023.03.01) |
| Feb 7, 2024 | 97.54% (0.97543) | 100.00th | v3 (v2023.03.01) |
| Nov 8, 2023 | 97.54% (0.97536) | 99.99th | v3 (v2023.03.01) |
| Sep 22, 2023 | 97.55% (0.97554) | 99.99th | v3 (v2023.03.01) |
| Jul 8, 2023 | 97.56% (0.97560) | 99.99th | v3 (v2023.03.01) |
| Jun 14, 2023 | 97.55% (0.97552) | 99.99th | v3 (v2023.03.01) |
| May 8, 2023 | 97.56% (0.97565) | 100.00th | v3 (v2023.03.01) |
| Mar 26, 2023 | 97.55% (0.97548) | 99.99th | v3 (v2023.03.01) |
| Mar 7, 2023 | 97.54% (0.97538) | 99.98th | v3 (v2023.03.01) |
| Mar 6, 2023 | 95.67% (0.95674) | 99.98th | v2 (v2022.01.01) |
| Feb 4, 2022 | 95.67% (0.95674) | 99.98th | v2 (v2022.01.01) |
| Feb 3, 2022 | 94.13% (0.94129) | 99.96th | v1 |
| Sep 1, 2021 | 94.13% (0.94129) | 99.98th | v1 |
| Apr 14, 2021 | 94.13% (0.94129) | 0.00th | v1 |
References (49)
- http://blog.talosintelligence.com/2017/03/apache-0-day-exploited.html x_refsource_MISCExploitThird Party Advisory
- http://blog.trendmicro.com/trendlabs-security-intelligence/cve-2017-5638-apache-struts-vulnerability-remote-code-execution x_refsource_MISCExploitThird Party Advisory
- http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2017-002.txt x_refsource_CONFIRMThird Party Advisory
- http://www.eweek.com/security/apache-struts-vulnerability-under-attack.html x_refsource_MISCPress/Media CoverageThird Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html x_refsource_CONFIRMPatchThird Party Advisory
- http://www.securityfocus.com/bid/96729 vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1037973 vdb-entryx_refsource_SECTRACKBroken LinkThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2017-5638 Vendor Advisory
- https://arstechnica.com/security/2017/03/critical-vulnerability-under-massive-attack-imperils-high-impact-sites x_refsource_MISCExploitPress/Media Coverage
- https://bugzilla.redhat.com/show_bug.cgi?id=1430326 Issue Tracking
- https://cwiki.apache.org/confluence/display/WW/S2-045 x_refsource_CONFIRMMitigationVendor Advisory
- https://cwiki.apache.org/confluence/display/WW/S2-046 x_refsource_CONFIRMMitigationVendor Advisory
- https://exploit-db.com/exploits/41570 exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
- https://git1-us-west.apache.org/repos/asf?p=struts.git%3Ba=commit%3Bh=352306493971e7d5a756d61780d57a76eb1f519a x_refsource_CONFIRMBroken Link
- https://git1-us-west.apache.org/repos/asf?p=struts.git%3Ba=commit%3Bh=6b8272ce47160036ed120a48345d9aa884477228 x_refsource_CONFIRMBroken Link
- https://git1-us-west.apache.org/repos/asf?p=struts.git;a=commit;h=352306493971e7d5a756d61780d57a76eb1f519a
- https://git1-us-west.apache.org/repos/asf?p=struts.git;a=commit;h=6b8272ce47160036ed120a48345d9aa884477228
- https://github.com/advisories/GHSA-j77q-2qqg-6989 Advisory
- https://github.com/apache/struts/commit/352306493971e7d5a756d61780d57a76eb1f519a
- https://github.com/apache/struts/commit/b06dd50af2a3319dd896bf5c2f4972d2b772cf2b
- https://github.com/mazen160/struts-pwn x_refsource_MISCExploit
- https://github.com/rapid7/metasploit-framework/issues/8064 x_refsource_MISCExploitIssue Tracking
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbgn03733en_us x_refsource_CONFIRMBroken Link
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbgn03749en_us x_refsource_CONFIRMThird Party Advisory
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03723en_us x_refsource_CONFIRMThird Party Advisory
- https://isc.sans.edu/diary/22169 x_refsource_MISCExploitThird Party Advisory
- https://lists.apache.org/thread.html/r1125f3044a0946d1e7e6f125a6170b58d413ebd4a95157e4608041c7%40%3Cannounce.apache.org%3E mailing-listx_refsource_MLISTMailing List
- https://lists.apache.org/thread.html/r1125f3044a0946d1e7e6f125a6170b58d413ebd4a95157e4608041c7@%3Cannounce.apache.org%3E
- https://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c%40%3Cannounce.apache.org%3E mailing-listx_refsource_MLISTMailing List
- https://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c@%3Cannounce.apache.org%3E
- https://lists.apache.org/thread.html/r90890afea72a9571d666820b2fe5942a0a5f86be406fa31da3dd0922%40%3Cannounce.apache.org%3E mailing-listx_refsource_MLISTMailing List
- https://lists.apache.org/thread.html/r90890afea72a9571d666820b2fe5942a0a5f86be406fa31da3dd0922@%3Cannounce.apache.org%3E
- https://nmap.org/nsedoc/scripts/http-vuln-cve2017-5638.html x_refsource_MISCExploitThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-5638
- https://packetstormsecurity.com/files/141494/S2-45-poc.py.txt x_refsource_MISCBroken LinkExploitThird Party AdvisoryVDB Entry
- https://security.netapp.com/advisory/ntap-20170310-0001 x_refsource_CONFIRMThird Party Advisory
- https://struts.apache.org/docs/s2-045.html x_refsource_CONFIRMMitigationVendor Advisory
- https://struts.apache.org/docs/s2-046.html x_refsource_CONFIRMMitigationVendor Advisory
- https://support.lenovo.com/us/en/product_security/len-14200 x_refsource_CONFIRMThird Party Advisory
- https://twitter.com/theog150/status/841146956135124993 x_refsource_MISCBroken LinkThird Party Advisory
- https://web.archive.org/web/20170311203630/http://www.securityfocus.com/bid/96729
- https://web.archive.org/web/20170921030226/http://www.securitytracker.com/id/1037973
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-5638 government-resourceUS Government Resource
- https://www.cve.org/CVERecord?id=CVE-2017-5638
- https://www.exploit-db.com/exploits/41614 exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
- https://www.imperva.com/blog/2017/03/cve-2017-5638-new-remote-code-execution-rce-vulnerability-in-apache-struts-2 x_refsource_MISCThird Party Advisory
- https://www.kb.cert.org/vuls/id/834067 third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource
- https://www.symantec.com/security-center/network-protection-security-advisories/SA145 x_refsource_CONFIRMBroken Link
Change history (0)
No recorded changes yet.