CVE-2017-9791—Apache Struts 1 Improper Input Validation Vulnerability
PUBLISHEDvulnerability record
2022-02-10 · last modified June 21, 2025
Metadata
Vulnerability Name
Apache Struts 1 Improper Input Validation Vulnerability
Description
The Struts 1 plugin in Apache Struts might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.
Known To Be Used in Ransomware Campaigns?
Action
Apply updates per vendor instructions.