S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2017-5638 Scanner

CVE-2017-5638 scanner - Remote Code Execution (RCE) vulnerability in Jakarta Multipart parser in Apache Struts

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.4k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2017-5638
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header, as exploited in the wild in March 2017 with a Content-Type header containing a #cmd= string.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Apache Strutsby Apache Software Foundation
2.3.x before 2.3.32
Updated Aug 5, 2026View on NVD →
Detail

Apache Struts 2 is a widely used open-source web application framework for developing Java EE web applications. One of the key components of this framework is the Jakarta Multipart parser, which is used to handle file upload requests. The Jakarta Multipart parser is responsible for parsing the uploaded files and extracting the content from them. The parser is also responsible for handling errors and generating error messages when there is an issue with the file upload.

One of the most significant vulnerabilities that was detected in the Jakarta Multipart parser is the CVE-2017-5638 vulnerability. This vulnerability allows remote attackers to execute arbitrary commands on the server by manipulating the HTTP headers in the file upload request. Specifically, attackers can use a crafted Content-Type, Content-Disposition, or Content-Length header with a #cmd= string to execute arbitrary commands on the server. This vulnerability was exploited in the wild in March 2017, and it affected Apache Struts versions 2.3.x and 2.5.x.

If this vulnerability is exploited, attackers can gain complete control over the targeted server. They can access sensitive data, execute arbitrary commands, and launch further attacks on other systems connected to the server. This vulnerability is particularly dangerous because it is relatively easy to exploit and can be targeted with a simple HTTP request.

Thanks to the pro features of the s4e.io platform, those who read this article can easily and quickly learn about vulnerabilities in their digital assets. The platform provides comprehensive vulnerability scanning and reporting tools that can help individuals and organizations identify and remediate security weaknesses in their systems. Using s4e.io, users can stay up-to-date on the latest security threats and vulnerabilities, and take proactive steps to protect their digital assets from potential attacks.

 

REFERENCES

Solution Advice

To protect against this vulnerability, there are several precautionary measures that can be taken. These precautions include:

  • Updating to the latest version of Apache Struts
  • Applying patches provided by Apache Struts for the vulnerable versions
  • Configuring firewalls to block malicious traffic
  • Monitoring network traffic for suspicious activity
  • Conducting regular vulnerability scans to detect any potential threats

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2017-5638 scanner - Remote Code Execution (RCE) vulnerability in Jakarta Multipart parser in Apache Struts | S4E