← Vulnerability feed

Vulnerability record · CVE-2017-5638 · published 11 March 2017

CVE-2017-5638: Apache Struts 2 Jakarta Multipart parser remote code execution

Apache · Struts

The Jakarta Multipart parser in Apache Struts 2 mishandles exceptions and error messages during file-upload attempts, letting a crafted Content-Type, Content-Disposition, or Content-Length header inject and execute commands. It was exploited in the wild in March 2017 and affects widely deployed Struts-based applications and products that embed Struts.

9.8 CVSS 3.1 Critical CISA KEV since 3 Nov 2021 Known ransomware use EPSS 100% · top 0.1% CWE-755 · CWE-755
9.8CVSS 3.1 base score, v2 10.0
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
9Affected product versions listed by NVD
67References, 20 tagged exploit
17 Jun 2026Last modified by NVD

Description

The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header, as exploited in the wild in March 2017 with a Content-Type header containing a #cmd= string.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityCVSS 9.8, unauthenticated network RCE, confirmed in-the-wild exploitation, KEV listing with ransomware use, and EPSS near 1.0 make this an urgent patch-first issue.

What it is

The Jakarta Multipart parser in Apache Struts 2 mishandles exceptions and error messages during file-upload attempts, letting a crafted Content-Type, Content-Disposition, or Content-Length header inject and execute commands. It was exploited in the wild in March 2017 and affects widely deployed Struts-based applications and products that embed Struts.

Impact

An unauthenticated remote attacker can execute arbitrary commands on the server, leading to full compromise of the application and its host. This can result in data theft, lateral movement, and ransomware deployment.

Attack surface

Reachable over the network via HTTP requests to a Struts 2 file-upload endpoint; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).

Exploitation

Exploitation is confirmed: CISA KEV lists it with known ransomware campaign use, EPSS is near 1.0, and multiple references are tagged Exploit including public PoCs and Metasploit.

What to do

  • Upgrade Apache Struts 2 to 2.3.32 or 2.5.10.1 or later, or apply the vendor patches referenced in S2-045/S2-046.
  • If immediate upgrade is not possible, apply the Jakarta Multipart parser mitigation described in the Apache S2-045/S2-046 advisories.
  • Inventory applications and embedded products that bundle Struts 2 (including listed vendors) and patch them via their own vendor advisories.
  • Restrict or monitor external exposure of Struts file-upload endpoints until patched.
  • Treat any unpatched internet-facing Struts 2 instance as compromised and perform incident response.

Detection

  • Inspect HTTP requests for suspicious Content-Type, Content-Disposition, or Content-Length headers containing OGNL expressions or '#cmd=' strings.
  • Monitor web server and application logs for malformed multipart upload errors followed by process execution.
  • Use the Nmap http-vuln-cve2017-5638 script or equivalent scanner to identify exposed vulnerable instances.
  • Alert on outbound connections or child processes spawned by the Java/Struts application server.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2017-5638 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Apache Struts Remote Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://blog.talosintelligence.com/2017/03/apache-0-day-exploited.html ExploitThird Party Advisory
http://blog.trendmicro.com/trendlabs-security-intelligence/cve-2017-5638-apache-struts-vulnerability-remote-code-executi ExploitThird Party Advisory
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2017-002.txt Third Party Advisory
http://www.eweek.com/security/apache-struts-vulnerability-under-attack.html Press/Media CoverageThird Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html PatchThird Party Advisory
http://www.securityfocus.com/bid/96729 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1037973 Broken LinkThird Party AdvisoryVDB Entry
https://arstechnica.com/security/2017/03/critical-vulnerability-under-massive-attack-imperils-high-impact-sites/ ExploitPress/Media Coverage
https://cwiki.apache.org/confluence/display/WW/S2-045 MitigationVendor Advisory
https://cwiki.apache.org/confluence/display/WW/S2-046 MitigationVendor Advisory
https://exploit-db.com/exploits/41570 ExploitThird Party AdvisoryVDB Entry
https://git1-us-west.apache.org/repos/asf?p=struts.git%3Ba=commit%3Bh=352306493971e7d5a756d61780d57a76eb1f519a Broken Link
https://git1-us-west.apache.org/repos/asf?p=struts.git%3Ba=commit%3Bh=6b8272ce47160036ed120a48345d9aa884477228 Broken Link
https://github.com/mazen160/struts-pwn Exploit
https://github.com/rapid7/metasploit-framework/issues/8064 ExploitIssue Tracking
https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbgn03733en_us Broken Link
https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbgn03749en_us Third Party Advisory
https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03723en_us Third Party Advisory
https://isc.sans.edu/diary/22169 ExploitThird Party Advisory
https://lists.apache.org/thread.html/r1125f3044a0946d1e7e6f125a6170b58d413ebd4a95157e4608041c7%40%3Cannounce.apache.org% Mailing List
https://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c%40%3Cannounce.apache.org% Mailing List
https://lists.apache.org/thread.html/r90890afea72a9571d666820b2fe5942a0a5f86be406fa31da3dd0922%40%3Cannounce.apache.org% Mailing List
https://nmap.org/nsedoc/scripts/http-vuln-cve2017-5638.html ExploitThird Party Advisory
https://packetstormsecurity.com/files/141494/S2-45-poc.py.txt Broken LinkExploitThird Party AdvisoryVDB Entry
https://security.netapp.com/advisory/ntap-20170310-0001/ Third Party Advisory
https://struts.apache.org/docs/s2-045.html MitigationVendor Advisory
https://struts.apache.org/docs/s2-046.html MitigationVendor Advisory
https://support.lenovo.com/us/en/product_security/len-14200 Third Party Advisory
https://twitter.com/theog150/status/841146956135124993 Broken LinkThird Party Advisory
https://www.exploit-db.com/exploits/41614/ ExploitThird Party AdvisoryVDB Entry
https://www.imperva.com/blog/2017/03/cve-2017-5638-new-remote-code-execution-rce-vulnerability-in-apache-struts-2/ Third Party Advisory
https://www.kb.cert.org/vuls/id/834067 Third Party AdvisoryUS Government Resource
https://www.symantec.com/security-center/network-protection-security-advisories/SA145 Broken Link
http://blog.talosintelligence.com/2017/03/apache-0-day-exploited.html ExploitThird Party Advisory
http://blog.trendmicro.com/trendlabs-security-intelligence/cve-2017-5638-apache-struts-vulnerability-remote-code-executi ExploitThird Party Advisory
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2017-002.txt Third Party Advisory
http://www.eweek.com/security/apache-struts-vulnerability-under-attack.html Press/Media CoverageThird Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html PatchThird Party Advisory
http://www.securityfocus.com/bid/96729 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1037973 Broken LinkThird Party AdvisoryVDB Entry

Track CVE-2017-5638 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-17530Apache Struts forced OGNL evaluation enables remote code executionApache Struts 2.0.0 through 2.5.25 performs forced OGNL evaluation on raw user input placed in tag attributes, allowing expression language injection…KEVEPSS 96%analysed9.8CVE-2017-9791Apache Struts 1 plugin input validation flaw enables remote code executionThe Struts 1 plugin in Apache Struts 2.1.x and 2.3.x may allow remote code execution when a malicious field value is passed in a raw message to the A…KEVEPSS 99%analysed9.8CVE-2014-7169GNU Bash environment variable function parsing command injection (Shellshock variant)GNU Bash through 4.3 bash43-025 processes trailing strings after malformed function definitions in environment variable values, allowing command inje…KEVEPSS 100%analysed9.8CVE-2014-6271GNU Bash environment variable command injection (ShellShock)GNU Bash through 4.3 processes trailing strings after function definitions in environment variable values, allowing injected commands to run when Bas…KEVEPSS 100%analysed9.8CVE-2013-2251Apache Struts 2 OGNL injection enables remote code executionApache Struts 2.0.0 through 2.3.15 fails to properly validate request parameters, allowing crafted action:, redirect:, or redirectAction: prefixes to…KEVEPSS 100%analysed9.8CVE-2012-0391Apache Struts ExceptionDelegator OGNL injection enables remote code executionApache Struts before 2.2.3.1 evaluates parameter values as OGNL expressions in the ExceptionDelegator component during exception handling for mismatc…KEVEPSS 76%analysed8.1CVE-2018-11776Apache Struts namespace handling flaw enables remote code executionApache Struts 2.3 through 2.3.34 and 2.5 through 2.5.16 can execute remote code when alwaysSelectFullNamespace is enabled and results or url tags are…KEVEPSS 100%analysed8.1CVE-2017-9805Apache Struts REST Plugin XStream deserialization RCEThe REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an XStream instance for deseri…KEVEPSS 99%analysed

Source: NIST National Vulnerability Database (record CVE-2017-5638), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.