ZeroHour

CVE-2017-9791

KEVlarge

Unauthenticated RCE via Improper Input Validation in Apache Struts 1 Plugin

CISA: Apache Struts 1 Improper Input Validation Vulnerability

CVSS 3.1
9.8 critical
EPSS
99%p100
Published
()
KEV added
AI analysis

CVE-2017-9791 is an improper input validation flaw (CWE-20) in the Struts 1 plugin shipped with Apache Struts 2.1.x and 2.3.x. When a user-supplied field value is passed as a raw message to ActionMessage, it is evaluated as an expression, allowing an unauthenticated attacker to achieve remote code execution with the privileges of the Java web application. Organizations running Struts 2.1.x/2.3.x applications with the Struts 1 plugin enabled are affected, and Oracle has separately shipped patches for Struts bundled in its products. The flaw is listed in CISA's Known Exploited Vulnerabilities Catalog (added 2022-02-10) and carries a 98.9% EPSS score (100th percentile), indicating active, widespread exploitation, though no public proof-of-concept is catalogued.

What to do: Apply updates per vendor instructions as required by CISA by upgrading Struts 2.1.x/2.3.x to a patched release and, where feasible, disabling or removing the Struts 1 plugin; audit application code for ActionMessage calls that pass unvalidated user input as raw messages. For Oracle products that bundle Struts, apply Oracle's Struts-related security patches. Prioritize internet-facing applications given confirmed in-the-wild exploitation (KEV) and the near-certain near-term exploitation probability (EPSS 98.9%).

Affected
Apache Struts 2 (with Struts 1 plugin enabled)2.1.x, 2.3.x
Apache Struts 1 (legacy framework, per CISA affected listing)
Estimated exposure
largetens of thousands of internet-exposed Struts 2 applications, with a far larger installed base inside enterprise networks — Struts 2.1.x/2.3.x was one of the most widely deployed Java web frameworks and legacy Struts 1 plugin usage persists in long-lived enterprise apps, so public internet scans count exposed Struts endpoints in the tens of thousands, while the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.

CISA Known Exploited Vulnerability
Affected
Apache Struts 1
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
apache
Products
struts
Weakness
CWE-20
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news