This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our private policy>

Security Notice - Statement on S2-052 Remote Code Execution Vulnerability in Apache Struts2

  • Initial Release Date: 2017.09.06
  • Last Release Date: 2017.09.19

Huawei noticed that Apache Struts published a security bulletin S2-052 (CVE-2017-9805), released a Critical Remote Code Execution vulnerability in the REST Plugin of Apache Struts. Huawei immediately launched a thorough investigation. Huawei immediately launched a thorough investigation.
The investigation is over, and no Huawei product is currently known as affected by this vulnerability.

2017-09-19 V1.1 FINAL
2017-09-06 V1.0 INITIAL

Huawei adheres to protecting the ultimate interests of users with best efforts and the principle of responsible disclosure and deal with product security issues through our response mechanism.

To enjoy Huawei PSIRT services and obtain Huawei product vulnerability information, please visit
To report a security vulnerability in Huawei products and solutions, please send it to For details, please visit