Vulnerability Details CVE-2017-9804
In Apache Struts 2.3.7 through 2.3.33 and 2.5 through 2.5.12, if an application allows entering a URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL. NOTE: this vulnerability exists because of an incomplete fix for S2-047 / CVE-2017-7672.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.121
EPSS Ranking 93.4%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2017-9804
-
cpe:2.3:a:apache:struts:2.3.10
-
cpe:2.3:a:apache:struts:2.3.11
-
cpe:2.3:a:apache:struts:2.3.12
-
cpe:2.3:a:apache:struts:2.3.13
-
cpe:2.3:a:apache:struts:2.3.14
-
cpe:2.3:a:apache:struts:2.3.14.1
-
cpe:2.3:a:apache:struts:2.3.14.2
-
cpe:2.3:a:apache:struts:2.3.14.3
-
cpe:2.3:a:apache:struts:2.3.15
-
cpe:2.3:a:apache:struts:2.3.15.1
-
cpe:2.3:a:apache:struts:2.3.15.2
-
cpe:2.3:a:apache:struts:2.3.15.3
-
cpe:2.3:a:apache:struts:2.3.16
-
cpe:2.3:a:apache:struts:2.3.16.1
-
cpe:2.3:a:apache:struts:2.3.16.2
-
cpe:2.3:a:apache:struts:2.3.16.3
-
cpe:2.3:a:apache:struts:2.3.17
-
cpe:2.3:a:apache:struts:2.3.19
-
cpe:2.3:a:apache:struts:2.3.20
-
cpe:2.3:a:apache:struts:2.3.20.1
-
cpe:2.3:a:apache:struts:2.3.20.2
-
cpe:2.3:a:apache:struts:2.3.21
-
cpe:2.3:a:apache:struts:2.3.22
-
cpe:2.3:a:apache:struts:2.3.23
-
cpe:2.3:a:apache:struts:2.3.24.2
-
cpe:2.3:a:apache:struts:2.3.24.3
-
cpe:2.3:a:apache:struts:2.3.25
-
cpe:2.3:a:apache:struts:2.3.26
-
cpe:2.3:a:apache:struts:2.3.27
-
cpe:2.3:a:apache:struts:2.3.28
-
cpe:2.3:a:apache:struts:2.3.28.1
-
cpe:2.3:a:apache:struts:2.3.29
-
cpe:2.3:a:apache:struts:2.3.30
-
cpe:2.3:a:apache:struts:2.3.31
-
cpe:2.3:a:apache:struts:2.3.32
-
cpe:2.3:a:apache:struts:2.3.33
-
cpe:2.3:a:apache:struts:2.3.7
-
cpe:2.3:a:apache:struts:2.3.8
-
cpe:2.3:a:apache:struts:2.3.9
-
cpe:2.3:a:apache:struts:2.5
-
cpe:2.3:a:apache:struts:2.5.1
-
cpe:2.3:a:apache:struts:2.5.10
-
cpe:2.3:a:apache:struts:2.5.10.1
-
cpe:2.3:a:apache:struts:2.5.12
-
cpe:2.3:a:apache:struts:2.5.2
-
cpe:2.3:a:apache:struts:2.5.3
-
cpe:2.3:a:apache:struts:2.5.4
-
cpe:2.3:a:apache:struts:2.5.5
-
cpe:2.3:a:apache:struts:2.5.6
-
cpe:2.3:a:apache:struts:2.5.7
-
cpe:2.3:a:apache:struts:2.5.8
-
cpe:2.3:a:apache:struts:2.5.9