CVE-2017-5638

critical

Description

The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header, as exploited in the wild in March 2017 with a Content-Type header containing a #cmd= string.

From the Tenable Blog

Apache Struts Jakarta Remote Code Execution (CVE-2017-5638) Detection with Nessus
Apache Struts Jakarta Remote Code Execution (CVE-2017-5638) Detection with Nessus

Published: 2017-03-14

A remote code execution vulnerability (CVE-2017-5638) in the Jakarta Multipart Parser in certain versions of the Apache Struts framework can enable a remote attacker to run arbitrary commands on the web server. Since its initial disclosure, this vulnerability has received significant attention, and is reportedly exploited in the wild. Public exploits are also available for this vulnerability.

References

https://github.com/Sudo-Zaid/cve-poc-writeups

https://github.com/RenatoAntunovic/cve-metasploit-skeniranje

https://github.com/lr-elaina520/cve-analysis

https://github.com/chengbochuan3/CVE-Apache-Ecosystem

https://github.com/Athology0000/cve-lab

https://github.com/HaakimSec/zero2shell-50

https://github.com/sudichai/cve-destroyer

https://github.com/enjoylife96962930-a11y/bug-bounty-series-2026

https://github.com/kokunas/fraud-cve

https://github.com/amitvakk/dark-overlord-threat-intelligence-analysis

https://github.com/kokunas/java-app-cve

https://github.com/Hector-Abarca/realrisk-checks

https://github.com/manahylkhan/cveradar

https://github.com/Lanexus/cve-scanner

https://github.com/heyjerrybecker/seevie-pri

https://github.com/allannjuguna/Exploit-Development

https://github.com/Dungsocool/CVE-2017-5638

https://github.com/flags-alt/abyss-c2

https://github.com/Majaktech/apache-struts-cve-2017-5638-project

https://github.com/wyqsgy/vulnark

https://github.com/guilhermeferreira24/healthcare-cybersecurity-analysis

https://github.com/Kouf320/docker-lab-cve-2017-5638-cve-2021-41773

https://github.com/Kouf320/attacker-lab-cve-2017-5638-cve-2021-41773-paper

https://github.com/AIPEACS/SC3010-Computer-Security

https://github.com/AIPEAC/SC3010-Computer-Security

https://github.com/ericrlessa/java-exploitable-quiz

https://github.com/lizuyi-6/aetherguard-security-dataset

https://github.com/Deloney-code/AI-Powered-Red-Team-Automation

https://github.com/JerryT-cell/Container-Security-Risk-Assessment-Pipeline-using-LLMs

https://github.com/soufiane-benchahyd/vulhub-struts2

https://github.com/ndouglas-cloudsmith/ExploitPwned

https://github.com/CVE-ORG/CVE-ORG

https://github.com/Arthurfert/SecLLM-Gen

https://github.com/0xBentz1/cve-context-knowledge-base

https://github.com/ACharaf06/CVE-2017-5638-Attack-and-Defense

https://github.com/0wn2886/CVE-Web

https://github.com/scthornton/securecode-v2

https://github.com/kaylertee/Computer-Security-Equifax-2017

https://github.com/MuhammadAbdullah192/CVE-2017-5638-Remote-Code-Execution-Apache-Struts2-EXPLOITATION

https://github.com/abdullah89255/Bug-bounty-pentesting-and-CVE-trends

https://github.com/root6790/security-research

https://github.com/joidiego/Detection-struts-cve-2017-5638-detector

https://github.com/cyberleelawat/LeelawatX-CVE-Hunter

https://github.com/haxerr9/CVE-2017-5638

https://github.com/Nithylesh/web-application-firewall-

https://github.com/FredBrave/CVE-2017-5638-ApacheStruts2.3.5

https://github.com/mritunjay-k/CVE-2017-5638

https://github.com/mfdev-solution/Exploit-CVE-2017-5638

https://github.com/testpilot031/vulnerability_struts-2.3.31

https://github.com/jptr218/struts_hack

https://github.com/sonatype-workshops/struts2-rce

https://github.com/ludy-dev/XworkStruts-RCE

https://github.com/pasannirmana/Aspire

https://github.com/colorblindpentester/CVE-2017-5638

https://github.com/advisories/GHSA-j77q-2qqg-6989

https://github.com/andypitcher/check_struts

https://github.com/Iletee/struts2-rce

https://github.com/ggolawski/struts-rce

https://github.com/pr0x1ma-byte/cybersecurity-struts2

https://github.com/donaldashdown/Common-Vulnerability-and-Exploit

https://github.com/c002/Apache-Struts

https://github.com/evolvesecurity/vuln-struts2-vm

https://github.com/invisiblethreat/strutser

https://github.com/mike-williams/Struts2Vuln

https://github.com/eeehit/CVE-2017-5638

https://github.com/riyazwalikar/struts-rce-cve-2017-5638

https://github.com/jpacora/Struts2Shell

https://github.com/SpiderMate/Stutsfi

https://github.com/Aasron/Struts2-045-Exp

https://github.com/tahmed11/strutsy

https://github.com/opt9/Strutscli

https://github.com/gsfish/S2-Reaper

https://github.com/KarzsGHR/S2-046_S2-045_POC

https://github.com/jas502n/st2-046-poc

https://github.com/falcon-lnhg/StrutsShell

https://github.com/opt9/Strutshock

https://github.com/lolwaleet/ExpStruts

https://github.com/ret2jazzy/Struts-Apache-ExploitPack

https://github.com/mazen160/struts-pwn

https://github.com/sjitech/test_struts2_vulnerability_CVE-2017-5638

https://github.com/Masahiro-Yamada/OgnlContentTypeRejectorValve

https://github.com/mthbernardes/strutszeiro

https://github.com/jas502n/S2-045-EXP-POC-TOOLS

https://github.com/Flyteas/Struts2-045-Exp

https://github.com/PolarisLab/S2-045

https://www.symantec.com/security-center/network-protection-security-advisories/SA145

https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-5638

https://twitter.com/theog150/status/841146956135124993

https://struts.apache.org/docs/s2-046.html

https://struts.apache.org/docs/s2-045.html

https://packetstormsecurity.com/files/141494/S2-45-poc.py.txt

https://nmap.org/nsedoc/scripts/http-vuln-cve2017-5638.html

https://lists.apache.org/thread.html/r90890afea72a9571d666820b2fe5942a0a5f86be406fa31da3dd0922%40%3Cannounce.apache.org%3E

https://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c%40%3Cannounce.apache.org%3E

https://lists.apache.org/thread.html/r1125f3044a0946d1e7e6f125a6170b58d413ebd4a95157e4608041c7%40%3Cannounce.apache.org%3E

https://isc.sans.edu/diary/22169

https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbgn03733en_us

https://github.com/rapid7/metasploit-framework/issues/8064

https://git1-us-west.apache.org/repos/asf?p=struts.git%3Ba=commit%3Bh=6b8272ce47160036ed120a48345d9aa884477228

https://git1-us-west.apache.org/repos/asf?p=struts.git%3Ba=commit%3Bh=352306493971e7d5a756d61780d57a76eb1f519a

https://cwiki.apache.org/confluence/display/WW/S2-046

https://cwiki.apache.org/confluence/display/WW/S2-045

https://arstechnica.com/security/2017/03/critical-vulnerability-under-massive-attack-imperils-high-impact-sites/

http://www.securitytracker.com/id/1037973

http://www.securityfocus.com/bid/96729

http://blog.trendmicro.com/trendlabs-security-intelligence/cve-2017-5638-apache-struts-vulnerability-remote-code-execution/

http://blog.talosintelligence.com/2017/03/apache-0-day-exploited.html

Details

Source: Mitre, NVD

Published: 2017-03-11

Updated: 2026-06-17

Known Exploited Vulnerability (KEV)

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.99999