CVE-2017-9791: Apache Struts 1 Improper Input Validation Vulnerability.
Apache Struts 1 Improper Input Validation Vulnerability. The Struts 1 plugin in Apache Struts might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.
- CISA KEV-listed (remediation due 2022-08-10)
- EPSS 94.1% (99.9% percentile)