CVE-2017-5638: Apache Struts Remote Code Execution Vulnerability. Apache
Apache Struts Remote Code Execution Vulnerability. Apache Struts Jakarta Multipart parser allows for malicious file upload using the Content-Type value, leading to remote code execution.
- CISA KEV-listed (remediation due 2022-05-03)
- used in ransomware campaigns
- EPSS 100.0% (100.0% percentile)
- CVSS 9.8 critical