← Back

CVE-2017-5638

Published: Mar 11, 2017Modified: Apr 21, 2026CISA KEV

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header, as exploited in the wild in March 2017 with a Content-Type header containing a #cmd= string.

Affected (21)

Show all products
1 product
Struts
3 products
Storwize V3500 Firmware
Storwize V5000 Firmware
Storwize V7000 Firmware
1 product
Storage V5030 Firmware
1 product
Server Automation
1 product
Weblogic Server
1 product
Clearpass Policy Manager
1 product
Oncommand Balance
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Apache
From 2.2.3 to 2.3.32
From 2.5.0 to 2.5.10.1
Configuration B
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Ibm
Version 7.7.1.6
Version 7.8.1.0
Running on/withPlatform Versions
Ibm
Storwize V3500
All versions
Configuration C
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Ibm
Version 7.7.1.6
Version 7.8.1.0
Running on/withPlatform Versions
Ibm
Storwize V5000
All versions
Configuration D
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Ibm
Version 7.7.1.6
Version 7.8.1.0
Running on/withPlatform Versions
Ibm
Storwize V7000
All versions
Configuration E
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Lenovo
Version 7.7.1.6
Version 7.8.1.0
Running on/withPlatform Versions
Lenovo
Storage V5030
All versions
Configuration F
5 vulnerable
Vulnerable SoftwareAffected Versions
Hp
Version 10.0.0
Version 10.1.0
Version 10.2.0
Version 10.5.0
Version 9.1.0
Configuration G
4 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 10.3.6.0.0
Version 12.1.3.0.0
Version 12.2.1.1.0
Version 12.2.1.2.0
Configuration H
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 6.6.5
Configuration I
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions

References (67)

Source: security@apache.org
ExploitThird Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Press/Media CoverageThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
Broken LinkThird Party AdvisoryVDB Entry
Source: security@apache.org
Broken LinkThird Party AdvisoryVDB Entry
Source: security@apache.org
MitigationVendor Advisory
Source: security@apache.org
MitigationVendor Advisory
Source: security@apache.org
ExploitThird Party AdvisoryVDB Entry
Source: security@apache.org
Exploit
Source: security@apache.org
ExploitIssue Tracking
Source: security@apache.org
ExploitThird Party Advisory
Source: security@apache.org
ExploitThird Party Advisory
Source: security@apache.org
ExploitThird Party AdvisoryVDB EntryBroken Link
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
MitigationVendor Advisory
Source: security@apache.org
MitigationVendor Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Broken LinkThird Party Advisory
Source: security@apache.org
ExploitThird Party AdvisoryVDB Entry
Source: security@apache.org
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Press/Media CoverageThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB EntryBroken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.