CISA KEV · catalog date Nov 3, 2021 · first observed Jul 19, 2026
Evidence dossier
CVE-2017-5638
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload…
Exploited in the wild (CISA KEV since Nov 3, 2021). NVD reports CVSS 3.1 9.8. EPSS estimates 100.0% exploit likelihood as of Jul 18, 2026.
As of Aug 27, 2026
Normalized restatement
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header, as exploited in the wild in March 2017 with a Content-Type header containing a #cmd= string.
- State
- PUBLISHED
- Published
- Mar 11, 2017
- Updated
- Oct 21, 2025
- Evidence coverage
- 99%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCAapacheOriginal evidence ↗
Record text: The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header, as exploited in the wild in March 2017 with a Content-Type header containing a #cmd= string.
Inspect raw assertion
- Field
container- Value
- The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header, as exploited in the wild in March 2017 with a Content-Type header containing a #cmd= string.
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Apache Struts Remote Code Execution Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Apache Struts Remote Code Execution Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 100% probability · 99.99th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.999990000000; percentile 0.999940000000
FIRST EPSS · score date Jul 18, 2026 · 100th percentile · first observed Jul 19, 2026
NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header, as exploited in the wild in March 2017 with a Content-Type header containing a #cmd= string.
Inspect raw assertion
- Field
container- Value
- The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header, as exploited in the wild in March 2017 with a Content-Type header containing a #cmd= string.
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
Apache Struts Remote Code Execution Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Apache Struts Remote Code Execution Vulnerability
100% probability · 99.99th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.999990000000; percentile 0.999940000000
Applicability
Cited product scope
Grouped from 13 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
14 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "2.3.x before 2.3.32"}, {"status": "affected", "version": "2.5.x before 2.5.10.1"}]product-9cd0052bcd831ad951c3a83f953006d77d3ff2278903b02b620cad9fb02389e0Linked exactInspect raw assertions
cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 2.2.3; through excluding 2.3.32
- Match ID
40d3ee72-e37f-4f4c-996d-50e144cf43dd
cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 1
- Logic
- OR
- Version bounds
- from including 2.5.0; through excluding 2.5.10.1
- Match ID
e2f63d06-b26a-4db6-8b07-b847554abca8
product-a80551b193682c185755e1d6672b4f3b91301b906339a0b7d7df7be899178000Linked exactInspect raw assertion
cpe:2.3:a:arubanetworks:clearpass_policy_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 7 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 6.6.5
- Match ID
8d1193b0-59c9-4ac0-bba0-ced6fcc91883
product-5c349c2f8b42dbebf2c135bcb94137a177dafa2836be6d28856834b9146c0abeLinked exactInspect raw assertions
cpe:2.3:a:hp:server_automation:10.1.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ac9404a4-6b73-436e-a8fb-914530d6000a
cpe:2.3:a:hp:server_automation:10.0.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
951c042f-9c83-4dbb-8070-a926a1b46591
cpe:2.3:a:hp:server_automation:10.5.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
38abfd4f-8e97-4418-a921-bf9f4d95a4a4
cpe:2.3:a:hp:server_automation:10.2.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
32afbe84-5394-49a1-844a-ed964a46acf7
cpe:2.3:a:hp:server_automation:9.1.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
112dfe68-a609-4b76-8227-4de9cac25f54
product-db54cdc4e645ebf2feed1a7cc00428a6be7a3bd9e01eb2982e963a440aa748d7Linked exactInspect raw assertion
cpe:2.3:h:ibm:storwize_v3500:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7352face-c8d0-49a7-a2d7-b755599f0fb3
product-23ab7517d850c1af6b1a083624f0fad854ef000f56dbed751f85a370a255b228Linked exactInspect raw assertions
cpe:2.3:o:ibm:storwize_v3500_firmware:7.8.1.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a8a0c06e-b833-4a52-b1f0-fec9bef372a4
cpe:2.3:o:ibm:storwize_v3500_firmware:7.7.1.6:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5ab119e1-7736-4c99-ad9c-9e8820769d4f
product-e534c07b942bcf04805c8a19bc75a353b7a2e27611f0459adb02b7537c1e8a6dLinked exactInspect raw assertion
cpe:2.3:h:ibm:storwize_v5000:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f0b69c8d-32a4-449f-9bfc-f1587c7fa8bd
product-cf30b31ec398d0196054d33db4c66a04bf27e2c135c53153321004eed22af4b6Linked exactInspect raw assertions
cpe:2.3:o:ibm:storwize_v5000_firmware:7.7.1.6:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f445d22e-8976-4adc-81fd-49b351b2802a
cpe:2.3:o:ibm:storwize_v5000_firmware:7.8.1.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
1b9e6724-8796-4dd5-9ce2-8e602da893f9
product-e8570080d336e964db1604e040ccbd82a0953dfceca396acc95e3895023b17a3Linked exactInspect raw assertion
cpe:2.3:h:ibm:storwize_v7000:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 3 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
aa2ed020-4c7b-4303-abe6-74d46d127556
product-93d6b05f8eed271bf2f61e6fc29aa788c24371120303a6a67dadae2b596fefcfLinked exactInspect raw assertions
cpe:2.3:o:ibm:storwize_v7000_firmware:7.7.1.6:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d1d7a801-1861-4479-9367-60f792bf8016
cpe:2.3:o:ibm:storwize_v7000_firmware:7.8.1.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
edf96e49-9530-4718-b5a9-7366d10cc890
product-17f280a7f4e6a91f652b044742e5651448bd348f16ee5aa8de5ed6f810f424c5Linked exactInspect raw assertion
cpe:2.3:h:lenovo:storage_v5030:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 4 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a2a4179b-51c5-486b-8cff-d49436d60910
product-f4104fd5fedc5f70fb7effb572bc126c6a94aad94959ac0ba6f34ef3f57516f5Linked exactInspect raw assertions
cpe:2.3:o:lenovo:storage_v5030_firmware:7.8.1.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
da0affaa-f7ae-416c-a40d-24f972ee18bd
cpe:2.3:o:lenovo:storage_v5030_firmware:7.7.1.6:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
371cd28e-6187-4eb1-8b73-645f7a6bffd6
product-1e7e71c5224a6f4135c855890a7cd875f6ac32bf0024c6ee2e888da0212d267eLinked exactInspect raw assertion
cpe:2.3:a:netapp:oncommand_balance:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 8 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7dcbcc5d-c396-47a8-adf4-d3a2c4377fb1
product-7408bee14b201df56ba79a093a16ebcccdd09751b1d73782c2ea9e3f85eee87eLinked exactInspect raw assertions
cpe:2.3:a:oracle:weblogic_server:12.2.1.2.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
3a1728d5-e03b-49a0-849c-b722197af054
cpe:2.3:a:oracle:weblogic_server:10.3.6.0.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b40b13b7-68b3-4510-968c-6a730eb46462
cpe:2.3:a:oracle:weblogic_server:12.2.1.1.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
29f4c533-de42-463b-9d80-5d4c85bf1a5b
cpe:2.3:a:oracle:weblogic_server:12.1.3.0.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c93cc705-1f8c-4870-99e6-14bf264c3811
Affected-product evidence
Accepted scope and product mapping
9 canonical links · 1 source-reported links
vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-1e7e71c5224a6f4135c855890a7cd875f6ac32bf0024c6ee2e888da0212d267e
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
7b8397f1-f8f3-44ae-bf68-50066ae7c230vendor-d1f71e9a842a3ed0c9c994de0ad92dacaf4038f3df129e35b00ecfcc640f1b57 · product-23ab7517d850c1af6b1a083624f0fad854ef000f56dbed751f85a370a255b228
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
1c61fb98-dc36-45d7-aaae-86193aace555f402c14a-d6e6-4657-9657-82be6dc122ebvendor-70d82f349c5bfe520cb6c54b8ed40a72fd9fe4d55a875ed1d539fb17472e7b24 · product-5c349c2f8b42dbebf2c135bcb94137a177dafa2836be6d28856834b9146c0abe
- Source class
- Nvd cpe vulnerable target
- Assertions
- 5
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
4aedc8b1-ea54-48b6-a00a-983c7ae095f956bd1ad0-9614-4963-9aa6-e0fbd055afaa841cd825-c8d9-47c0-b0c8-2b7b22b06aeb9750d16f-28ef-4e3c-9339-38b706a3ae7b98c32da7-b52a-4b0c-b74f-f6946a5ae7dbvendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-7408bee14b201df56ba79a093a16ebcccdd09751b1d73782c2ea9e3f85eee87e
- Source class
- Nvd cpe vulnerable target
- Assertions
- 4
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
12eecb3f-b8a2-4781-8a79-7e56fbb26c7f3dd5214a-8f97-4c8f-854c-ecc22f5c7d875d8df065-924d-4915-90f2-36b9c7f2db509404fee3-5e31-4d66-ab48-aed04b802238vendor-d1f71e9a842a3ed0c9c994de0ad92dacaf4038f3df129e35b00ecfcc640f1b57 · product-93d6b05f8eed271bf2f61e6fc29aa788c24371120303a6a67dadae2b596fefcf
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
64dd6fa9-4d35-4a56-b59a-7a09731ba5fcaa9a25bf-3edb-4d96-b3a6-bf8e7e85d187vendor-8771dac0ae5eeec984ca23e4bbe5a243fb7896ad7c1c4afc6acd3abe53fdd152 · product-9cd0052bcd831ad951c3a83f953006d77d3ff2278903b02b620cad9fb02389e0
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
6d74e7a1-13c9-47c0-b992-31084b4a9fbffecd1c1b-1e87-4d53-a42b-43a7707ef78bvendor-2643795e72728272efd12d893f3cf243d3995491727400455d5a1ed815bddb09 · product-a80551b193682c185755e1d6672b4f3b91301b906339a0b7d7df7be899178000
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
9fbdd9fe-8ff5-4172-a9e8-f8c2be367073vendor-d1f71e9a842a3ed0c9c994de0ad92dacaf4038f3df129e35b00ecfcc640f1b57 · product-cf30b31ec398d0196054d33db4c66a04bf27e2c135c53153321004eed22af4b6
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
9e99a473-35d9-4164-8e8e-2750d720785ea68498c1-f161-4ded-9f50-e81602180590vendor-f5d08c69510fdbcf8208b7a31b08e9a7ceee2adea519a55e9c40f4d2b18bb09a · product-f4104fd5fedc5f70fb7effb572bc126c6a94aad94959ac0ba6f34ef3f57516f5
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
27584044-09e2-463d-a265-5bd70e142e382a0f61db-5fb3-4df2-8784-c7184163ed13Canonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
a6d5b19c-8287-4603-82d0-610270176b19Assessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAV:N/AC:L/Au:N/C:C/I:C/A:CCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDirect CVE/CNA normalized decisions
CISA-ADP
CVSS 3.1 · Secondary · Independent enrichment · rank 2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Validation
- Valid match
- Recomputed
- 9.8
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.