CVE-2017-9791
Apache Struts 1
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.
- CVSS
- 9.8
- EPSS
- 98.8% 99.9% percentile
- CISA KEV
- Listed
- Published
- 2017.07.11