CVE-2017-5638

CRITICAL(9.8)KEVRansomwareLikely Exploited

Apache Struts Remote Code Execution Vulnerability

Description

CVE-2017-5638 is a CRITICAL vulnerability affecting Apache Struts, carrying a CVSS 3.1 score of 9.8. Apache Struts Jakarta Multipart parser allows for malicious file upload using the Content-Type value, leading to remote code execution. Affected products include Apache Struts (>= 2.2.3, < 2.3.32; >= 2.5.0, < 2.5.10.1), Oracle WebLogic Server (10.3.6.0.0; 12.1.3.0.0; 12.2.1.1.0; 12.2.1.2.0). This CVE is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog with a remediation deadline of 2022-05-03. With an EPSS score of 0.94267 (99.93th percentile), this vulnerability demonstrates significant real-world exploitation activity and should be prioritized for immediate remediation.

KEV Information

Vendor
Apache
Product
Struts
Date Added
November 3, 2021
Due Date
May 3, 2022
Required Action
Apply updates per vendor instructions.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9

CWEs

Affected Products

VendorProductVersion
apachestruts>= 2.2.3, < 2.3.32; >= 2.5.0, < 2.5.10.1
ibmstorwize v3500 firmware7.7.1.6; 7.8.1.0
ibmstorwize v5000 firmware7.7.1.6; 7.8.1.0
ibmstorwize v7000 firmware7.7.1.6; 7.8.1.0
lenovostorage v5030 firmware7.7.1.6; 7.8.1.0
hpserver automation9.1.0; 10.0.0; 10.1.0; 10.2.0; 10.5.0
oracleweblogic server10.3.6.0.0; 12.1.3.0.0; 12.2.1.1.0; 12.2.1.2.0
arubanetworksclearpass policy manager< 6.6.5
netapponcommand balance-

Multiple CVSS Assessments

Source: [email protected](Primary)
9.8
CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
9.8
CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

Weakness Type

CWE-755: Improper Handling of Exceptional Conditions

CVE-2017-5638 is classified under CWE-755 — Improper Handling of Exceptional Conditions. Improper Handling of Exceptional Conditions occurs when software does not properly handle errors, exceptions, or unusual conditions during processing. When exception handling is flawed, error messages, stack traces, or other diagnostic information may be exposed to users, or the application may enter an insecure state. In more severe cases, improper exception handling can expose internal evaluation mechanisms to attacker-controlled input, enabling code injection or remote code execution.

In the context of Apache Struts, this weakness is critically dangerous because the Jakarta Multipart parser's flawed exception handling exposes OGNL evaluation to attacker-controlled Content-Type headers. When the parser encounters a malformed multipart request, the error message processing path evaluates user input as OGNL expressions, enabling full remote code execution. This vulnerability was exploited massively in the wild and is considered one of the most impactful Apache Struts vulnerabilities ever discovered.

Learn more: CWE-755 — Improper Handling of Exceptional Conditions

Impact Analysis

CVE-2017-5638 carries a CVSS 3.1 score of 9.8 (CRITICAL) with Unchanged Scope.

Confidentiality (HIGH): Successful exploitation grants the attacker extensive access to sensitive data processed by Apache Struts, including configuration files, credentials, and potentially data from connected systems.

Integrity (HIGH): Attackers can modify critical system files, install backdoors, alter configurations, or deploy malware on affected systems running Apache Struts.

Availability (HIGH): Complete disruption of the affected service or system is possible, including denial of service, system crashes, or rendering the product inoperable.

Scope Unchanged: The vulnerability's scope is Unchanged (U), meaning exploitation is contained within the vulnerable component. The impact, while significant, is limited to the Apache Struts environment itself.

With an EPSS score of 0.94267 (99.93th percentile), this vulnerability ranks among the most likely to be exploited in real-world attacks, underscoring the urgency of remediation.

Exploit Maturity

CVE-2017-5638 has confirmed active exploitation in the wild and is listed in CISA's Known Exploited Vulnerabilities catalog.

Exploit status: This vulnerability has been actively exploited, as confirmed by its inclusion in the KEV catalog. The EPSS score of 0.94267 (99.93th percentile) places it among the most exploited vulnerabilities tracked.

Ransomware association: CVE-2017-5638 has been associated with ransomware campaigns. This significantly elevates the risk profile, as ransomware operators actively target this vulnerability for initial access or lateral movement within compromised environments.

Attack surface: The vulnerability's high EPSS score and KEV listing confirm that threat actors have developed and used working exploits. Public proof-of-concept code and exploitation tools are available, making this vulnerability accessible to a wide range of attackers. Organizations should assume that automated scanning and exploitation tools targeting this vulnerability are in active use.

KEV deadline: CISA required federal agencies to remediate this vulnerability by 2022-05-03. All organizations should treat this deadline as a strong recommendation for their own remediation timelines.

Remediation

  1. Apply vendor patches immediately. Apply updates per vendor instructions. Upgrade Apache Struts to the latest patched version that addresses this vulnerability. Consult the official vendor advisory for specific patch guidance and release notes.
  2. Verify affected product versions in your environment. Identify all instances of Apache Struts in your infrastructure (affected versions: Apache Struts (>= 2.2.3, < 2.3.32; >= 2.5.0, < 2.5.10.1), Oracle WebLogic Server (10.3.6.0.0; 12.1.3.0.0; 12.2.1.1.0; 12.2.1.2.0)). Use asset inventory and vulnerability scanning tools to ensure no instances are missed.
  3. Implement interim mitigations if patching is delayed. If immediate patching is not feasible, apply network-level controls such as restricting access to the affected component, enabling enhanced logging, and monitoring for indicators of compromise.
  4. Scan for signs of prior exploitation. Given the confirmed active exploitation of this vulnerability, review system logs and security monitoring data for evidence of compromise. Conduct a thorough investigation if any suspicious activity is detected.
  5. Update detection signatures and monitoring rules. Ensure intrusion detection and prevention systems, endpoint detection tools, and SIEM rules are updated to detect exploitation attempts targeting CVE-2017-5638.
  6. Conduct a post-remediation review. After patching, verify the fix is effective and document the remediation actions taken. Update your vulnerability management records and assess whether any additional hardening measures are warranted.

Technical Details

CVE-2017-5638 is a CRITICAL-severity vulnerability in Apache Struts that can be exploited remotely over the network without physical access. The attack complexity is low, meaning no specialized conditions or preparation are required beyond the attack prerequisites. No prior authentication or privileges are needed to initiate the attack. No user interaction is required, allowing fully automated exploitation.

Technical mechanism: The Jakarta Multipart parser in Apache Struts 2 has incorrect exception handling during file-upload attempts, allowing remote code execution via crafted Content-Type header. The underlying flaw relates to improper handling of exceptional conditions, which allows attackers to manipulate the application's processing logic in unintended ways. Successful exploitation enables arbitrary code execution on the target system, potentially leading to full system compromise.

CVSS 3.1 vector analysis: The vector reflects an Attack Vector of NETWORK, Attack Complexity of LOW, Privileges Required of NONE, User Interaction of NONE, Scope UNCHANGED, and impact ratings of HIGH/HIGH/HIGH for Confidentiality/Integrity/Availability respectively. The Unchanged scope means impact is contained within the vulnerable component itself.

Frequently Asked Questions

Is CVE-2017-5638 being actively exploited?

Yes. CVE-2017-5638 is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild. With an EPSS score of 0.94267 (99.93th percentile), it ranks among the most exploited vulnerabilities tracked globally. This vulnerability has also been linked to ransomware campaigns, further confirming its active use by threat actors.

What products are affected by CVE-2017-5638?

The affected products include Apache Struts (>= 2.2.3, < 2.3.32; >= 2.5.0, < 2.5.10.1), Oracle WebLogic Server (10.3.6.0.0; 12.1.3.0.0; 12.2.1.1.0; 12.2.1.2.0). Organizations running any of these versions should verify their exposure and prioritize remediation. Check vendor advisories for the complete and most current list of affected versions.

How do I fix CVE-2017-5638?

Apply updates per vendor instructions. Ensure all affected instances of Apache Struts are identified using vulnerability scanning and asset management tools. If immediate patching is not possible, implement network-level mitigations and enhanced monitoring. After patching, verify the fix and scan for indicators of prior compromise.

How severe is CVE-2017-5638?

CVE-2017-5638 is rated CRITICAL with a CVSS 3.1 score of 9.8. Its EPSS score of 0.94267 places it in the 99.93th percentile for exploitation likelihood. The vulnerability has confirmed active exploitation in the wild and was required to be remediated by federal agencies by 2022-05-03 per CISA's KEV directive.

CVSS Score

9.8
CRITICAL(9.8)

EPSS Score

EPSS Score100.00%
EPSS Percentile100.0%

Dates

PublishedMarch 11, 2017
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.