Apache Struts2 RCE CVE-2017-5638 Scanner

Apache Struts2 RCE CVE-2017-5638 Scanner Detail

There is a remote code execution vulnerability in Apache Struts2.

The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before mishandles file upload, which allows remote attackers to execute arbitrary commands via a #cmd= string in a crafted Content-Type HTTP header, as exploited in the wild in March 2017.

You need to update your Apache Struts2 server to the latest version.

