Vulnerabilities (CVE)

Filtered by vendor Cisco Subscribe
Filtered by product Media Experience Engine
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-9805 3 Apache, Cisco, Netapp 7 Struts, Digital Media Manager, Hosted Collaboration Solution and 4 more 2025-10-22 6.8 MEDIUM 8.1 HIGH
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.