← Back to CVE List
Vulnerability Intelligence Report
Apache Struts Remote Code Execution Vulnerability

CVE-2017-5638

The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header, as exploited in the wild in March 2017 with a Content-Type header containing a #cmd= string.

CISA KEV Nuclei Template SSVC: Active Exploitation Automatable
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:100.00%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-755 ↗CWE-755 Improper Handling of Exceptional Conditions

Affected Products & Versions

Vendor Product Affected Versions
Apache Software Foundation Apache Struts 2.3.x before 2.3.32 (affected), 2.5.x before 2.5.10.1 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
99.999%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityApache Software Foundation · Vendor · USA
Reserved2017-01-29T00:00:00
Published2017-03-11T02:11:00
Patch Date2017-03-06
Last Updated2025-10-21T23:55:46

LINK COPIED TO CLIPBOARD