Vulnerability record · CVE-2017-9805 · published 15 September 2017
CVE-2017-9805: Apache Struts REST Plugin XStream deserialization RCE
Apache · Struts
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an XStream instance for deserialization without type filtering. Deserializing attacker-supplied XML payloads can therefore lead to remote code execution. This is a well-known, actively exploited flaw with a very high EPSS score.
Description
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityIt is in CISA KEV with a near-maximum EPSS score and public exploit code, and it enables unauthenticated remote code execution.
What it is
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an XStream instance for deserialization without type filtering. Deserializing attacker-supplied XML payloads can therefore lead to remote code execution. This is a well-known, actively exploited flaw with a very high EPSS score.
Impact
An unauthenticated remote attacker can execute arbitrary code in the context of the Struts application, leading to full server compromise. This can result in data theft, persistence, and lateral movement.
Attack surface
Reachable over the network via HTTP requests to Struts REST endpoints that deserialize XML, per the CVSS vector AV:N/PR:N/UI:N. No authentication or user interaction is required.
Exploitation
CVE-2017-9805 is listed in CISA KEV (added 2021-11-03) and has an EPSS 30-day probability of 0.99396 (99.94th percentile). A public Exploit-DB entry (42627) exists, confirming weaponized exploit code is available.
What to do
- Upgrade Apache Struts to 2.3.34 or 2.5.13 or later as directed by the vendor advisory (S2-052).
- Apply vendor patches for affected third-party products (Cisco, NetApp, Oracle) that bundle Struts.
- If immediate upgrade is not possible, disable or restrict the Struts REST plugin and avoid XML deserialization endpoints.
- Follow the S2-052 mitigation guidance to remove or replace the XStreamHandler where feasible.
- Monitor for and block exploit attempts targeting REST endpoints with XML content types.
Detection
- Inspect HTTP requests to Struts REST endpoints for XML bodies containing XStream-style class references or unusual serialized objects.
- Monitor application and web server logs for errors or stack traces related to XStream deserialization.
- Use network IDS/IPS signatures for known CVE-2017-9805 exploit patterns and the public Exploit-DB PoC.
- Alert on unexpected child processes or outbound connections originating from the Java/Struts application server.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2017-9805 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Apache Struts Deserialization of Untrusted Data Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2017-9805 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-9805), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.