CVE-2017-12611observed exploitation

CVE-2017-12611: vulnerability in Apache Struts

Published · Updated

84Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 87%
from disclosure to weapon0 days
Published on NVDSep 20
1st PoCSep 8
VulnCheck+2399d
exploitation probability
87%top 1% of all CVEs
observed exploitation
yesVulnCheck
7 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Not affected
5 products — because the vulnerable code is not present in the product
Red Hat Enterprise Linux 5 · Red Hat JBoss Data Virtualization 6 · Red Hat JBoss Fuse Service Works 6 · Red Hat JBoss Operations Network 3 · Red Hat Satellite 5
In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag instead of string literals can lead to a RCE attack.
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.