CVE-2017-5638

Struts2 Content-Type RCE (Equifax Breach): stopped at runtime

Waratek RASP already blocks this exploit at runtime, inside the JVM - with no application change, no vendor patch, and no downtime.

Published March 11, 2017 · Updated March 4, 2026

Mitigated by Waratek CRITICAL CVSS 9.8 v3.1 Actively exploited

The vulnerability

Remote code execution via multipart parser error handling

The Jakarta-based Multipart parser in Struts 2 mishandles errors during file uploads: a crafted Content-Type, Content-Disposition, or Content-Length header triggers an exception whose message is evaluated as an OGNL expression, letting an unauthenticated remote attacker execute arbitrary commands. This is the vulnerability behind the 2017 Equifax data breach.

Affected softwareApache Struts 2 (Jakarta Multipart parser)
Affected versions2.3.x before 2.3.32 and 2.5.x before 2.5.10.1
WeaknessImproper exception handling (OGNL injection) (CWE-755, CWE-20)
Published2017-03-11
SeverityCRITICAL · CVSS 9.8

Running an affected version? We can help.

Waratek RASP shields the vulnerable code in production - the exploit is blocked at runtime with no library upgrade, no redeploy, and no downtime. We can have you covered fast.

Talk to us about protection

How Waratek RASP stops it

Blocked at runtime by Waratek RASP

Waratek RASP ships a patch rule that blocks exploitation at the exact point the dangerous operation is attempted, inside the JVM.

Runtime, not perimeter

Waratek RASP acts inside the JVM at the exact call that turns input into code, so obfuscated and encoded payloads are caught where a WAF misses them.

No code changes

Protection is applied as a rule at runtime. No source edits, no recompilation, no library upgrade, and no application restart required.

Zero false positives

Rules target the specific unsafe behaviour of the exploit, so legitimate traffic keeps flowing while the attack is blocked and logged.

Flip one toggle in the Waratek Portal. The protection deploys to every attached application, with no restart.

Common questions

Struts2 Content-Type RCE (Equifax Breach) FAQ

Is Struts2 Content-Type RCE (Equifax Breach) (CVE-2017-5638) exploitable?

CVE-2017-5638 carries a CVSS 9.8/10 (CRITICAL) rating and affects Apache Struts 2 (Jakarta Multipart parser) 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1. The Jakarta-based Multipart parser in Struts 2 mishandles errors during file uploads: a crafted Content-Type, Content-Disposition, or Content-Length header triggers an exception whose message is evaluated as an OGNL expression, letting an unauthenticated remote attacker execute arbitrary commands. This is the vulnerability behind the 2017 Equifax data breach. It is listed in CISA's Known Exploited Vulnerabilities catalog, with known ransomware campaign use.

How does Waratek mitigate Struts2 Content-Type RCE (Equifax Breach) (CVE-2017-5638)?

Waratek RASP blocks exploitation of Struts2 Content-Type RCE (Equifax Breach) (CVE-2017-5638) inside the JVM at runtime, with no application code changes, no vendor patch and no restart.

How quickly was Struts2 Content-Type RCE (Equifax Breach) (CVE-2017-5638) exploited after disclosure?

Exploit code for CVE-2017-5638 was already circulating publicly on March 7, 2017, before the vulnerability was even formally published in the NVD. Attackers had a head start before most defenders had a CVE record to react to.

Protect your apps in production

Get protected against Struts2 Content-Type RCE (Equifax Breach) - without code changes or redeploying

Book a call and we’ll show you how Waratek RASP shields your running applications against CVE-2017-5638 and attacks like it, and get you covered in production.