CVE Database
/

CVE-2017-9791

Back to search

CVE-2017-9791

Published: Jul 10, 2017

Modified: Oct 21, 2025

PUBLISHED

Description

The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.

VendorProductVersions

Apache Software Foundation

Apache Struts

affected
2.1.x series
affected
2.3.x series

References

99484
vdb-entry
x_refsource_BID
42324
exploit
x_refsource_EXPLOIT-DB
1038838
vdb-entry
x_refsource_SECTRACK
44643
exploit
x_refsource_EXPLOIT-DB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now