CVE-2017-9791: Apache Struts 1 Improper Input Validation Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2022-02-10. EPSS: 98.9% chance of exploitation in the next 30 days.
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.
Affected products
- Apache Struts: version 2.3.1 only; version 2.3.1.1 only; version 2.3.1.2 only; version 2.3.3 only; version 2.3.4 only; version 2.3.4.1 only; …
Published 2017-07-10. Last modified 2026-06-17.