← Back

CVE-2017-9804

nvd nist
Published: Sep 20, 2017Modified: May 13, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

In Apache Struts 2.3.7 through 2.3.33 and 2.5 through 2.5.12, if an application allows entering a URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL. NOTE: this vulnerability exists because of an incomplete fix for S2-047 / CVE-2017-7672.

Affected (55)

Products: Apache: Struts
1 product
Struts
Configuration A
55 vulnerable
Vulnerable SoftwareAffected Versions
Apache
Version 2.3.10
Version 2.3.11
Version 2.3.12
Version 2.3.13
Version 2.3.14.1
Version 2.3.14.2
Version 2.3.14.3
Version 2.3.14
Version 2.3.15.1
Version 2.3.15.2
Version 2.3.15.3
Version 2.3.15
Version 2.3.16.1
Version 2.3.16.2
Version 2.3.16.3
Version 2.3.16
Version 2.3.17
Version 2.3.19
Version 2.3.20.1
Version 2.3.20.2
Version 2.3.20
Version 2.3.21
Version 2.3.22
Version 2.3.23
Version 2.3.24.2
Version 2.3.24.3
Version 2.3.25
Version 2.3.26
Version 2.3.27
Version 2.3.28.1
Version 2.3.28
Version 2.3.29
Version 2.3.30
Version 2.3.31
Version 2.3.32
Version 2.3.33
Version 2.3.7
Version 2.3.8
Version 2.3.9
Version 2.5.10.1
Version 2.5.10
Version 2.5.12
Version 2.5.1
Version 2.5.2
Version 2.5.3
Version 2.5.4
Version 2.5.5
Version 2.5.6
Version 2.5.7
Version 2.5.8
Version 2.5.9
Version 2.5
Version 2.5 beta1
Version 2.5 beta2
Version 2.5 beta3

References (14)

Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party AdvisoryVDB Entry
Source: security@apache.org
Third Party AdvisoryVDB Entry
Source: security@apache.org
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.