RULE(RULE ID:320439)

Rule General Information
Release Date: 2017-09-06
Rule Name: WEB-SERVER Apache Struts 2 Struts 1 Plugin Remote Code Execution Vulnerability -3 (CVE-2017-9791)
Severity:
CVE ID:
Rule Protection Details
Description: The Struts 1 plugin in Apache Struts 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.
Impact: An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Mac OS, Other Unix, FreeBSD, Linux
Reference: SecurityFocusBID:99484
SecurityTrackerID:1038838
Solutions
More advisories have been published on the website, please visit for more suggestions:
http://struts.apache.org/docs/s2-048.html