RULE(RULE ID:322272)

Rule General Information
Release Date: 2019-07-04
Rule Name: Apache Struts2 REST Plugin XStream DoS Vulnerability (CVE-2017-9793)
Severity:
CVE ID:
Rule Protection Details
Description: The REST Plugin in Apache Struts 2.3.7 through 2.3.33 and 2.5 through 2.5.12 is using an outdated XStream library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted XML payload.
Impact: An attacker can launch a denial of service attack by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others
Reference: SecurityFocusBID:100611
SecurityTrackerID:1039262
https://struts.apache.org/docs/s2-051.html
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://struts.apache.org/docs/s2-051.html