CVE-2017-9805
Apache Struts Deserialization of Untrusted Data Vulnerability
- Published
- Sep 15, 2017
- Updated
- Oct 21, 2025
- Assigning CNA
- apache
- Evidence observed
- Sep 6, 2017
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HHigh · next 30 days
- Percentile
- 99.9%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.
Sources
23- -CVE-2017-9805Exploit
Exploit script for Apache Struts2 REST Plugin XStream RCE (CVE-2017-9805)
CVE-2017-9805 S2-052 PoC
- CVE-2017-9805---Documentation---IT19143378Informational
Documentation and analysis of CVE-2017-9805, providing technical details and context for understanding this vulnerability.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.