CISA Known Exploited Vulnerability

CVE-2017-5638 Ransomware

Apache · Struts

Apache Struts Remote Code Execution Vulnerability

Date added
BOD 22-01 due date
CWE CWE-20
Ransomware Known

CISA description

Apache Struts Jakarta Multipart parser allows for malicious file upload using the Content-Type value, leading to remote code execution.

Required action

Apply updates per vendor instructions.