S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2017-12611 Scanner

CVE-2017-12611 scanner - Remote Code Execution (RCE) vulnerability in Apache Software Foundation Struts

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.1k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2017-12611
9.8
CVSS

In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag instead of string literals can lead to a RCE attack.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Apache Strutsby Apache Software Foundation
2.0.0 - 2.3.33
Updated Aug 22, 2026View on NVD →
Detail

Apache Struts is a popular open-source Java web application framework developed to support the build of enterprise-level applications. It has attracted a significant number of developers and users in the Java community, thanks to its flexibility, extensibility, and powerful features. Struts is used to develop web applications that run on Java EE web servers, such as Apache Tomcat, JBoss, and WebSphere, and it provides a comprehensive Model-View-Controller (MVC) architecture that streamlines the development process.

However, like many other software, Struts is not immune to security vulnerabilities. CVE-2017-12611 is a Remote Code Execution (RCE) vulnerability that was detected in Apache Struts 2.0.0 to 2.3.33 and 2.5 to 2.5.10.1 versions. The flaw exists in the way Struts processes input parameters with the tag and the Struts plugin for Apache Freemarker, where an injection of the unintended expression is possible. This scenario can exploit poorly-written Apache Struts-based applications, leading to severe consequences.

An attacker who exploits CVE-2017-12611 on a vulnerable Struts application can execute arbitrary code, which could allow them to hijack the targeted system, gain access to sensitive data, or cause the system to crash. This vulnerability can be exploited remotely via a crafted HTTP request, and it can be automated to target multiple instances of the affected servers. In summary, a single exploit can allow an attacker to launch complex multi-stage attacks on an individual or organization's digital assets.

In conclusion, Apache Struts is a powerful web application framework widely used in developing enterprise-level applications. However, like any complex software, it is prone to vulnerabilities, such as CVE-2017-12611. The exploitation of this vulnerability could lead to significant breaches of data and systems. With s4e.io’s pro features, users can learn more about this vulnerability and how to protect their digital assets quickly and easily.

 

REFERENCES

Solution Advice

Several countermeasures can be taken to reduce the impact of this vulnerability. Here are the recommended steps:

  • Upgrade to a non-vulnerable version of Apache Struts. The CVE-2017-12611 vulnerability was fixed in versions 2.3.34 and 2.5.12.
  • Apply necessary patches or hotfixes to the affected Struts instances.
  • Consider implementing a web application firewall (WAF) to protect against some of the common exploit patterns.
  • Educate developers on secure coding practices and encourage the use of sanitization and validation functions to remove malicious input parameters.
  • Monitor network traffic and system logs for unusual patterns of activity.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2017-12611 scanner - Remote Code Execution (RCE) vulnerability in Apache Software Foundation Struts  | S4E