CVE-2017-5638: Apache Struts Remote Code Execution Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2021-11-03. EPSS: 100% chance of exploitation in the next 30 days.

The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header, as exploited in the wild in March 2017 with a Content-Type header containing a #cmd= string.

Affected products

  • Apache Struts: from 2.2.3, before 2.3.32 (fixed in 2.3.32); from 2.5.0, before 2.5.10.1 (fixed in 2.5.10.1)
  • Arubanetworks Clearpass Policy Manager: before 6.6.5 (fixed in 6.6.5)
  • HP Server Automation: version 9.1.0 only; version 10.0.0 only; version 10.1.0 only; version 10.2.0 only; version 10.5.0 only
  • IBM Storwize v3500 Firmware: version 7.7.1.6 only; version 7.8.1.0 only
  • IBM Storwize v5000 Firmware: version 7.7.1.6 only; version 7.8.1.0 only
  • IBM Storwize v7000 Firmware: version 7.7.1.6 only; version 7.8.1.0 only
  • Lenovo Storage v5030 Firmware: version 7.7.1.6 only; version 7.8.1.0 only
  • Netapp Oncommand Balance: affected versions not specified
  • Oracle WebLogic Server: version 10.3.6.0.0 only; version 12.1.3.0.0 only; version 12.2.1.1.0 only; version 12.2.1.2.0 only

Published 2017-03-11. Last modified 2026-06-17.