'; } else{ echo ''; } echo '
|
|
|||
Release Date:2025/9/15
Rule Name:CVE-2017-5638: Apache Struts Jakarta Multipart Parser Remote Code Execution Vulnerability
Severity:critical
CVE ID:CVE-2017-5638
| Descripiton:
|
A code execution vulnerability exists in Apache Struts. The vulnerability is due to a design weakness in the way Content-Type headers are processed by the Jakarta Multipart Parser component of Apache Struts. A remote attacker could exploit this vulnerability by sending a crafted request to the target server. Successful exploitation will allow an attacker to execute arbitrary code with the privileges of the server. This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021.
Other reference:None
| Solution:
|
Update vendor patches.