CVE-2017-9805: Apache Struts Deserialization of Untrusted Data Vulnerability

High severity, CVSS 8.1. Actively exploited: in CISA KEV since 2021-11-03. EPSS: 99.4% chance of exploitation in the next 30 days.

The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.

Affected products

  • Apache Struts: from 2.1.2, before 2.3.34 (fixed in 2.3.34); from 2.5.0, before 2.5.13 (fixed in 2.5.13)
  • Cisco Digital Media Manager: affected versions not specified
  • Cisco Hosted Collaboration Solution: version 10.5(1) only; version 11.0(1) only; version 11.5(1) only; version 11.6(1) only
  • Cisco Media Experience Engine: version 3.5 only; version 3.5.2 only
  • Cisco Network Performance Analysis: affected versions not specified
  • Cisco Video Distribution Suite For Internet Streaming: affected versions not specified
  • Netapp Oncommand Balance: affected versions not specified

Published 2017-09-15. Last modified 2026-06-17.