CVE-2017-5638General(apache / clearpass_policy_manager)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch apache clearpass_policy_manager systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header, as exploited in the wild in March 2017 with a Content-Type header containing a #cmd= string.

9.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-05-03. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-755

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • clearpass_policy_manager
  • oncommand_balance
  • server_automation
  • storage_v5030

Threat summary

  • Active exploitation appears in 6 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 20 mentions across 16 observed days

What's happening

  • Active exploitation reported across 6 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 4 signals
  • General: 10 classified signals
  • Peaked 14d ago at 2 mentions (2026-03-21); latest day: 1
  • 20 total mentions across 16 days

Affected systems

Products
clearpass_policy_manageroncommand_balanceserver_automationstorage_v5030storage_v5030_firmwarestorwize_v3500storwize_v3500_firmwarestorwize_v5000storwize_v5000_firmwarestorwize_v7000

12 versions affected across 13 products

Deep dive

Activity timeline20 mentions / 16d
01122Mentions · 2026-03-17: 1Mentions · 2026-03-21: 2Mentions · 2026-03-24: 1Mentions · 2026-03-28: 1Mentions · 2026-04-07: 1Mentions · 2026-04-20: 1Mentions · 2026-05-27: 1Mentions · 2026-06-14: 2Mentions · 2026-06-19: 2Mentions · 2026-09-04: 2Mentions · 2026-09-07: 1Mentions · 2026-09-13: 1Mentions · 2026-09-14: 1Mentions · 2026-09-25: 1Mentions · 2026-10-01: 1Mentions · 2026-10-02: 1PoC Mentioned / Linked · 2026-03-24: 1PoC Mentioned / Linked · 2026-09-04: 1Exploit Tool / Code · 2026-09-04: 1Active Exploitation · 2026-03-28: 1Active Exploitation · 2026-04-20: 1Active Exploitation · 2026-05-27: 1Active Exploitation · 2026-06-19: 2Active Exploitation · 2026-09-25: 1Patch / Workaround · 2026-03-17: 1Patch / Workaround · 2026-03-28: 1Patch / Workaround · 2026-06-19: 2Technical Details · 2026-05-27: 1Technical Details · 2026-06-19: 1Technical Details · 2026-09-07: 1Technical Details · 2026-09-14: 103-1703-2103-2403-2804-0704-2005-2706-1406-1909-0409-0709-1309-1409-2510-0110-02
Signal classification6 categories
General
1055.6%
Patch
316.7%
Active Exploitation
211.1%
PoC
15.6%
Disclosure
15.6%
Exploit
15.6%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-171
General1
2026-03-212
General2
2026-03-241
PoC1
2026-03-281
Patch1
2026-04-071
General1
2026-04-201
Active Exploitation1
2026-05-271
Disclosure1
2026-06-142
General2
2026-06-192
Patch2
2026-09-042
Exploit1General1
2026-09-071
General1
2026-09-131
General1
2026-09-141
General1
2026-09-251
Active Exploitation1
Full discourse20 posts
  • Nitin Gavhane@NitinGavhane_
    General

    CVE Vulnerabilities That Shaped the Bug Bounty World A quick timeline worth knowing: 1. CVE-2014-0160 • Heartbleed - 2014 2. CVE-2014-6271 • Shellshock - 2014 3. CVE-2016-5195 • Dirty COW - 2016 4. CVE-2017-0144 • EternalBlue - 2017 5. CVE-2017-5638 • Apache Struts RCE - 2017 6. CVE-2018-7600 • Drupalgeddon2 - 2018 7. CVE-2019-0708 • BlueKeep - 2019 8. CVE-2021-44228 • Log4Shell - 2021 9. CVE-2023-34362 • MOVEit - 2023 10. CVE-2024-3094 • XZ Utils - 2024 Learn the CVE → understand the root cause → study the patch → reproduce safely in a lab. #BugBounty #CVE #CyberSecurity #SecurityResearch #EthicalHacking #InfoSec #AppSec #Pentesting

    Post summary

    The text provides a timeline of ten historically significant CVEs that impacted bug bounty programs, accompanied by general educational advice on how to learn about vulnerabilities through root cause analysis, patch study, and lab reproduction.

    31411016411.3K
    3.5K followersView on X
  • DestroyerX@ide9x
    PoC

    good news 😌 CVE-2017-5638 الحمدلله🩶 #BugHunting #BugBounty #Security #CyberSecurity #HackerOne #Infosec https://t.co/hTClUC9iyD

    Post summary

    The tweet references CVE-2017-5638 and includes a link that likely hosts a proof‑of‑concept, but it provides no further technical, exploitation, or patch details.

    600124132.7K
    965 followersView on X
  • DEGEN 👑@iamjustape
    Patch

    Good morning. 🌅 Interesting technical detail to start the day: The Equifax breach in 2017, 147 million people's personal data exposed traced back to a single Apache Struts vulnerability, CVE-2017-5638, for which a patch had been available for two months before exploitation. The patch was available on March 7th 2017. Equifax's security team was notified. The patch wasn't applied. The breach began May 13th. 67 days after the patch was released. 147 million records. 67 days. One unpatched library. Have a good Friday. 🔐

    Post summary

    The 2017 Equifax breach was caused by an unpatched Apache Struts CVE-2017-5638, with a vendor patch available two months prior to exploitation.

    3103098
    3.9K followersView on X
  • CyberPulse@CyberPulse56

    ⚠️ EXPLOIT TOOL CLAIM — CVE-2017-5638 Threat actor Hacknatill is reportedly advertising a tool allegedly capable of exploiting CVE-2017-5638, a critical vulnerability in the Apache Struts 2 framework. 🔎 Vulnerability: CVE-2017-5638 💥 Impact: Remote Code Execution (RCE) 🔐 Authentication: Exploitation can occur without authentication on vulnerable systems 🎯 Attack vector: Maliciously crafted Content-Type header in multipart requests ⚠️ Potential impact includes unauthorized command execution, data access, malicious file deployment and server compromise. The vulnerability has been widely known since 2017, making vulnerable, unpatched Struts 2 deployments a significant security concern. ⚠️ The advertised tool and the seller’s claims have not been independently verified. Organizations should identify affected Apache Struts deployments and apply appropriate security updates/mitigations. #CyberSecurity #CVE20175638 #CVE #ApacheStruts #RCE #Exploit #ThreatIntel #InfoSec

    11010545
    3.8K followersView on X
  • DEGEN 👑@iamjustape
    Patch

    CVE-2017-5638. Patch available March 7th. Exploitation began May 13th. 67 days. One unpatched library. 147 million records. But the vulnerability was only the entry point. What allowed 78 days of undetected exfiltration was an expired SSL inspection certificate offline for 19 months that nobody noticed. The full technical postmortem of the Equifax breach. Full breakdown 👆 Follow for daily cybersecurity content. 🔐

    Post summary

    A brief post‑mortem of the Equifax breach highlights that CVE‑2017‑5638 was exploited, the patch was released on March 7th, and attackers remained undetected for 78 days due to an expired SSL inspection certificate.

    0002070
    3.9K followersView on X
  • X3r0Day@X3r0DaySec
    General

    @OriginalSicksec is this CVE-2017-5638 or CVE-2018-11776 ?

    Post summary

    The tweet simply lists two CVE identifiers and asks which one is correct; no additional technical or operational information is included.

    10001121
    237 followersView on X
  • b4dg0d@0xb4dg0d
    General

    @Psycho10k_ damn, CVE-2017-5638 in the wild, for real?

    Post summary

    User asks whether CVE‑2017‑5638 is currently being exploited, but no additional information is provided.

    10001320
    98 followersView on X
  • Freemen OS@theFreemenOS
    General

    Replaced productId=2 with productId=e in Burp Suite. Server returned HTTP 500 with a full stack trace. Hidden in the response: Apache Struts 2 2.3.31 the framework behind the Equifax breach. CVE-2017-5638. CVSS 10.0. No auth. Just a letter instead of a number. #BurpSuite https://t.co/BBUKTM7To7

    Post summary

    The post demonstrates a vulnerability exploitation against Apache Struts 2 using Burp Suite, providing technical details but no PoC code, exploit tool, or patch information.

    0001060
    17 followersView on X
  • ExploitGrid@exploitgrid
    Exploit

    [EXPLOIT] EGE-GH-XMhR9gC [CRITICAL/PoC] Linked: CVE-2017-5638 struts2-tool 🔗 https://exploitgrid.net/exploits/946e45d6-f881-4a9d-ae4a-ddf59c468eba

    Post summary

    The text announces an exploit for CVE-2017-5638, providing a PoC and a link to functional exploit code, with no evidence of active exploitation, patches, or debunking.

    1000035
    40 followersView on X
  • ExploitGrid@exploitgrid
    General

    🛡️ ExploitGrid Daily Threat Digest Critical Exploits disclosed today: CVE-2025-57819 CVE-2026-83548 CVE-2026-59827 CVE-2017-5638 CVE-2025-32958 ..🧵👇

    Post summary

    The excerpt lists several CVE identifiers under a threat digest title without providing any details, proofs, or context about the vulnerabilities.

    1000067
    40 followersView on X
  • SickSec 🇲🇦 🇵🇸@OriginalSicksec
    General

    @X3r0DaySec CVE-2017-5638

    Post summary

    The post merely references CVE-2017-5638 without providing any additional information.

    10000100
    9.1K followersView on X
  • Janelle Elaina McKnight@McKnight69420
    Disclosure

    1. **Equifax 2017**: A critical vulnerability (CVE-2017-5638 in Apache Struts) was disclosed in March. Equifax knew about it but failed to patch one of their web portals. Hackers exploited it May–July, stealing names, SSNs, and more for ~147 million people. Textbook "unpatched systems" failure—timely updates could’ve prevented it entirely. -thats absolute bullshit. Didn't know about that. I was targeted and audited by the irs for my 2017 tax year!!! Not cool 2. Totally fair—personal grit shows life’s toughness better than any lab! 3. Spot on: AI is 100% human-driven. We choose the prompts, the guardrails, and the applications. No force, just tools we build. What’s your take on where that choice leads next? 🚀

    Post summary

    The post highlights the Equifax 2017 Apache Struts CVE disclosure, noting its critical nature, historical exploitation, and lack of timely patching.

    1000051
    248 followersView on X
  • XHack@xhackio
    Patch

    This is the most severe Struts vulnerability since CVE-2017-5638 (Equifax breach). Successful exploitation grants attackers full control over affected servers. Patch immediately—Struts applications are frequent targets for automated scanning and exploitation. ##threatintel #cybersecurity #infosec

    Post summary

    The post warns of a severe Struts vulnerability similar to CVE-2017-5638, highlights ongoing exploitation, and urges immediate patching.

    0001031
    15 followersView on X
  • David@davidsheyi
    General

    3/ Reference past incidents. For example, after the Equifax breach (CVE-2017-5638), emphasize the importance of timely patch management. #InfoSec #CISO

    Post summary

    The post references a historic CVE to highlight the need for patch management, providing no technical, exploitation, or PoC details.

    1000029
    555 followersView on X
  • General Intels Daily@intels_daily

    🔴 𝗖𝗥𝗜𝗧𝗜𝗖𝗔𝗟 · 𝗖𝗹𝗮𝗶𝗺𝗲𝗱 𝗵𝗮𝗰𝗸𝗶𝗻𝗴 𝘁𝗼𝗼𝗹 𝗼𝗳𝗳𝗲𝗿𝗶𝗻𝗴 👤 Actor: Blacknet00 🧩 Product: 𝗔𝗽𝗮𝗰𝗵𝗲 𝗦𝘁𝗿𝘂𝘁𝘀𝟮 🛡️ CVE-2017-5638 Threat actor 'Blacknet00' claims to offer hacking tools involving Apache Struts2. Unverified claim. #HackingTools #ThreatIntel #CTI

    00000119
    828 followersView on X
  • General Intels Daily@intels_daily
    Active Exploitation

    🔴 𝗖𝗥𝗜𝗧𝗜𝗖𝗔𝗟 · 𝗩𝗶𝗰𝘁𝗶𝗺 𝗮𝗻𝗻𝗼𝘂𝗻𝗰𝗲𝗺𝗲𝗻𝘁 🏢 Target: 𝗦𝗿𝗶 𝗟𝗮𝗻𝗸𝗮 𝗣𝗼𝗹𝗶𝗰𝗲 𝗗𝗲𝗽𝗮𝗿𝘁𝗺𝗲𝗻𝘁 🧩 Products: 𝗪𝗶𝗹𝗱𝗙𝗹𝘆, 𝗔𝗽𝗮𝗰𝗵𝗲 𝗦𝘁𝗿𝘂𝘁𝘀 𝟮, 𝗠𝘆𝗦𝗤𝗟 🛡️ CVE-2017-5638 Threat actor Blacknet00 claims to have compromised the Sri Lanka Police Department's electronic services server (eservices.police[.]lk) by exploiting the CVE-2017-5638 (Apache Struts 2) vulnerability. The actor claims full root access and the theft of configuration files, source code, database backups, and system logs, potentially exposing citizen PII and credit card data. #DataBreach #ThreatIntel #CTI

    Post summary

    The tweet reports that threat actor Blacknet00 claims to have breached the Sri Lanka Police Department's server by exploiting CVE-2017-5638 (Apache Struts 2), resulting in alleged theft of sensitive data.

    00000132
    747 followersView on X
  • chaos@konig0000
    General

    CVE Vulnerabilities That Shaped the Bug Bounty World A quick timeline worth knowing: 1. CVE-2014-0160 • Heartbleed - 2014 2. CVE-2014-6271 • Shellshock - 2014 3. CVE-2016-5195 • Dirty COW - 2016 4. CVE-2017-0144 • EternalBlue - 2017 5. CVE-2017-5638 • Apache Struts RCE - 2017 6. CVE-2018-7600 • Drupalgeddon2 - 2018 7. CVE-2019-0708 • BlueKeep - 2019 8. CVE-2021-44228 • Log4Shell - 2021 9. CVE-2023-34362 • MOVEit - 2023 10. CVE-2024-3094 • XZ Utils - 2024 Learn the CVE → understand the root cause → study the patch → reproduce safely in a lab.

    Post summary

    This is a historical/educational list of notable CVEs encouraging study and safe lab reproduction. It does not focus on a specific new disclosure, PoC, exploit tool, active exploitation, or concrete patch/workaround.

    00000121
    19.8K followersView on X
  • Ethiack@ethiack
    Active Exploitation

    Equifax's 2017 breach, which affected 147 million people and a loss of $1+ billion, wasn't due to a complex chain of vulnerabilities but basic failures: an unpatched Apache Struts vulnerability (CVE-2017-5638), an expired certificate that reduced visibility, and insecure credential handling. The breach resulted from gaps in patching, asset visibility, logging/monitoring, and credential hygiene, all of which could have been easily prevented with proper security practices. Unlike infrequent pentests and legacy scanners, autonomous, AI-driven ethical hacking provides continuous testing, proof of exploitability, and zero false positives, identifying the exact issues that could lead to your next breach. This is why forward-thinking organizations have shifted to autonomous pentesting delivering the continuous visibility and speed that legacy approaches simply can't match. http://ethiack.com

    Post summary

    The post recounts how an unpatched CVE‑2017‑5638 was exploited in Equifax’s 2017 breach, emphasizing the importance of patching, but offers no PoC, exploit code, or specific mitigation steps.

    00000118
    1.9K followersView on X
  • Loginsoft Threat Intel@Loginsoft_Intel
    General

    Cytellite recent detection targeting CVE-2017-5638 — Tamatiya EOOD Visit -- https://cti.loginsoft.com/ip/79.124.40.162 #Loginsoft #Cytellite #Cybersecurity #CVE20175638 #LOVI #ThreatIntelligence #Infosecurity #AI https://t.co/PTHC2IU9jE

    Post summary

    The tweet notes a detection of CVE-2017-5638 by Cytellite but provides no further technical details or evidence of exploitation.

    0000016
    19 followersView on X
  • Loginsoft Threat Intel@Loginsoft_Intel
    General

    Cytellite recent detection targeting CVE-2017-5638 — Tamatiya EOOD Visit -- https://cti.loginsoft.com/ip/79.124.40.162 #Loginsoft #Cytellite #Cybersecurity #CVE20175638 #LOVI #ThreatIntelligence #Infosecurity #AI https://t.co/CpynuCwuvo

    Post summary

    The tweet references a detection of activity against CVE‑2017‑5638 but provides no technical details, exploit code, or mitigation information.

    0000014
    19 followersView on X
CPE platform detail24 entries

24 of 24 entries

PartVendorProductVersionTarget SWTarget HW
Appapachestruts---
Apparubanetworksclearpass_policy_manager---
Apphpserver_automation10.0.0--
Apphpserver_automation10.1.0--
Apphpserver_automation10.2.0--
Apphpserver_automation10.5.0--
Apphpserver_automation9.1.0--
HWibmstorwize_v3500---
OSibmstorwize_v3500_firmware7.7.1.6--
OSibmstorwize_v3500_firmware7.8.1.0--
HWibmstorwize_v5000---
OSibmstorwize_v5000_firmware7.7.1.6--
OSibmstorwize_v5000_firmware7.8.1.0--
HWibmstorwize_v7000---
OSibmstorwize_v7000_firmware7.7.1.6--
OSibmstorwize_v7000_firmware7.8.1.0--
HWlenovostorage_v5030---
OSlenovostorage_v5030_firmware7.7.1.6--
OSlenovostorage_v5030_firmware7.8.1.0--
Appnetapponcommand_balance---
Apporacleweblogic_server10.3.6.0.0--
Apporacleweblogic_server12.1.3.0.0--
Apporacleweblogic_server12.2.1.1.0--
Apporacleweblogic_server12.2.1.2.0--

Explore more