Vulnerability record · CVE-2017-5638 · published 11 March 2017
CVE-2017-5638: Apache Struts 2 Jakarta Multipart parser remote code execution
Apache · Struts
The Jakarta Multipart parser in Apache Struts 2 mishandles exceptions and error messages during file-upload attempts, letting a crafted Content-Type, Content-Disposition, or Content-Length header inject and execute commands. It was exploited in the wild in March 2017 and affects widely deployed Struts-based applications and products that embed Struts.
Description
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header, as exploited in the wild in March 2017 with a Content-Type header containing a #cmd= string.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, unauthenticated network RCE, confirmed in-the-wild exploitation, KEV listing with ransomware use, and EPSS near 1.0 make this an urgent patch-first issue.
What it is
The Jakarta Multipart parser in Apache Struts 2 mishandles exceptions and error messages during file-upload attempts, letting a crafted Content-Type, Content-Disposition, or Content-Length header inject and execute commands. It was exploited in the wild in March 2017 and affects widely deployed Struts-based applications and products that embed Struts.
Impact
An unauthenticated remote attacker can execute arbitrary commands on the server, leading to full compromise of the application and its host. This can result in data theft, lateral movement, and ransomware deployment.
Attack surface
Reachable over the network via HTTP requests to a Struts 2 file-upload endpoint; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
Exploitation is confirmed: CISA KEV lists it with known ransomware campaign use, EPSS is near 1.0, and multiple references are tagged Exploit including public PoCs and Metasploit.
What to do
- Upgrade Apache Struts 2 to 2.3.32 or 2.5.10.1 or later, or apply the vendor patches referenced in S2-045/S2-046.
- If immediate upgrade is not possible, apply the Jakarta Multipart parser mitigation described in the Apache S2-045/S2-046 advisories.
- Inventory applications and embedded products that bundle Struts 2 (including listed vendors) and patch them via their own vendor advisories.
- Restrict or monitor external exposure of Struts file-upload endpoints until patched.
- Treat any unpatched internet-facing Struts 2 instance as compromised and perform incident response.
Detection
- Inspect HTTP requests for suspicious Content-Type, Content-Disposition, or Content-Length headers containing OGNL expressions or '#cmd=' strings.
- Monitor web server and application logs for malformed multipart upload errors followed by process execution.
- Use the Nmap http-vuln-cve2017-5638 script or equivalent scanner to identify exposed vulnerable instances.
- Alert on outbound connections or child processes spawned by the Java/Struts application server.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2017-5638 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Apache Struts Remote Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2017-5638 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-5638), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.