CVE-2017-9787: Apache Struts

High severity, CVSS 7.5. EPSS: 10.6% chance of exploitation in the next 30 days.

When using a Spring AOP functionality to secure Struts actions it is possible to perform a DoS attack. Solution is to upgrade to Apache Struts version 2.5.12 or 2.3.33.

Affected products

  • Apache Struts: version 2.3.7 only; version 2.3.8 only; version 2.3.9 only; version 2.3.10 only; version 2.3.11 only; version 2.3.12 only; …

Published 2017-07-13. Last modified 2026-06-17.