PatchSiren

PatchSiren cyber security CVE debrief

CVE-2017-9805 Apache CVE debrief

CVE-2017-9805 is identified in the supplied official records as an Apache Struts deserialization of untrusted data vulnerability. CISA includes it in the Known Exploited Vulnerabilities catalog, which means it should be treated as a real-world exploitation risk rather than a theoretical issue. The KEV entry directs defenders to apply updates per vendor instructions, and the supplied metadata marks known ransomware campaign use as Unknown.

Vendor
Apache
Product
Struts
CVSS
Unknown
CISA KEV
Listed
Original CVE published
2021-11-03
Original CVE updated
2021-11-03
Advisory published
2021-11-03
Advisory updated
2021-11-03

Who should care

Organizations that run Apache Struts, as well as vulnerability management, application owners, and incident response teams responsible for patching and exposure review.

Technical summary

The official record describes the issue as deserialization of untrusted data in Apache Struts. The CISA KEV entry confirms it is a known exploited vulnerability and points defenders to vendor updates. Because the supplied record does not include a CVSS score, prioritization should lean on KEV status, asset exposure, and whether the application processes untrusted input.

Defensive priority

High. CISA lists this CVE in KEV, so affected Apache Struts deployments should be prioritized for inventory and remediation.

Recommended defensive actions

  • Inventory all Apache Struts deployments and identify any systems that may be affected.
  • Follow vendor guidance and apply the recommended updates as soon as possible.
  • Prioritize exposed or business-critical applications for remediation first.
  • Verify remediation after patching and confirm the vulnerable component is no longer present.
  • Review monitoring, logging, and incident response readiness for signs of abuse on affected systems.

Evidence notes

This debrief is based only on the supplied CISA KEV metadata and the official CVE/NVD/CISA links. The KEV record names Apache Struts as the affected product, classifies the issue as deserialization of untrusted data, lists dateAdded as 2021-11-03 and dueDate as 2022-05-03, and states requiredAction: Apply updates per vendor instructions. The supplied data does not include a CVSS score.

Sources and references

Verified primary and authoritative sources

  • CVE-2017-9805 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2017-9805

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2017-9805 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2017-9805

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

  • CISA Known Exploited Vulnerabilities catalog

    Publisher, destination, and source semantics verified

    URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

    Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json

    cisa_kev

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.