Apache Struts 2 Freemarker Remote Code Execution Vulnerability (CVE-2017-12611) in RSA Products
Originally Published: 2017-09-11
Article Number
Applies To
CVE Identifier(s)
Article Summary
The details for this vulnerability can be found at https://struts.apache.org/docs/s2-053.html.
Resolution
| RSA Product Name | Versions | Impacted? | Details | Last Updated |
|---|---|---|---|---|
| 3D Secure / Adaptive Authentication eCommerce | All Supported | Not Impacted | 2017-09-25 | |
| Access Manager | 6.2.4, 6.2.3, 6.2.2, 6.2.1, 6.2 | Impacted - Remediated | Refer to the security advisory ESA-2017-130 on RSA Link. Hotfixes 6.2.4.07, 6.2.3.08, 6.2.2.11, 6.2.1.10, and 6.2.0.24 with a fix for this issue, are available for RSA Access Manager 6.2.x. | 2017-10-17 |
| Adaptive Authentication Cloud | All Supported | Not Impacted | 2017-10-02 | |
| Adaptive Authentication Hosted | All Supported | Not Impacted | Product does not use impacted version of Apache Struts | 2017-09-15 |
| Adaptive Authentication On-Prem | 7.x | Not Impacted | 2017-09-22 | |
| Archer Hosted | N/A | Not Impacted | 2017-09-25 | |
| Archer Platform | All Supported | Not Impacted | Product does not use Apache Struts. | 2017-09-11 |
| Archer SecOps | All Supported | Not Impacted | Product does not use Apache Struts. | 2017-09-11 |
| Archer Vulnerability & Risk Manager (VRM) | All Supported | Not Impacted | Product does not use Apache Struts. | 2017-09-11 |
| Authentication Manager | 8.1, 8.1SP1, 8.2, 8.2SP1 | Not Impacted | 2017-09-12 | |
| Authentication Manager Appliance | 8.1, 8.1SP1, 8.2, 8.2SP1 | Not Impacted | 2017-09-12 | |
| BSAFE C Products: MES, Crypto-C ME, SSL-C | All Supported | Not Impacted | Product does not use Apache Struts. | 2017-09-14 |
| BSAFE Java Products: Cert-J, Crypto-J, SSL-J | All Supported | Not Impacted | Product does not use Apache Struts. | 2017-09-14 |
| Data Loss Prevention | All Supported | Not Impacted | Product does not use Apache Struts. | 2017-09-12 |
| Data Protection Manager | 3.5.2.5 and earlier | Impacted - Remediated | Refer to the security advisory ESA-2017-132 on RSA Link. RSA Data Protection Manager 3.5.2.6 with a fix for this issue is available. | 2017-10-20 |
| DCS: Certificate Manager | All Supported | Not Impacted | Product does not use Apache Struts. | 2017-09-11 |
| DCS: Validation Manager | All Supported | Not Impacted | Does not ship Freemarker Java Template Engine | 2017-09-11 |
| ECAT (NetWitness Endpoint) | All Supported | Not Impacted | Product does not use Apache Struts. | 2017-09-12 |
| eFraudNetwork (eFN) | All Supported | Not Impacted | 2017-09-25 | |
| enVision | EOPS | Not Impacted | Product does not use Apache Struts. | 2017-09-11 |
| Federated Identity Manager | All Supported | Not Impacted | Product does not use impacted version of Apache Struts | 2017-09-14 |
| FraudAction (OTMS) | All Supported | Not Impacted | 2017-09-25 | |
| Identity Governance and Lifecycle Software (Via Lifecycle and Governance Software, Identity Management & Governance Software) | All Supported | Not Impacted | Product does not use Apache Struts. | 2017-09-21 |
| Identity Governance and Lifecycle Appliance (Via Lifecycle and Governance Appliance, Identity Management & Governance Appliance) | All Supported | Not Impacted | Product does not use Apache Struts. | 2017-09-21 |
| Identity Governance and Lifecycle SaaS / MyAccessLive (Via Lifecycle and Governance SaaS / MyAccessLive) | All Supported | Not Impacted | Product does not use Apache Struts. | 2017-09-21 |
| NetWitness / Security Analytics (Physical and Virtual Appliances) | All Supported | Not Impacted | Product does not use Apache Struts. | 2017-09-12 |
| RSA Central | All Supported | Not Impacted | Product does not use impacted version of Apache Struts | 2017-09-15 |
| RSA Live Infrastructure | All Supported | Not Impacted | Product does not use Apache Struts. | 2017-09-12 |
| SecurID Access Cloud Service | All Supported | Not Impacted | 2017-09-25 | |
| SecurID Access IDR VM | All Supported | Not Impacted | 2017-09-25 | |
| SecurID Agent for PAM | All Supported | Not Impacted | 2017-09-12 | |
| SecurID Agent for Web | All Supported | Not Impacted | 2017-09-12 | |
| SecurID Agent for Windows | All Supported | Not Impacted | 2017-09-12 | |
| SecurID Authentication Engine | All Supported | Not Impacted | 2017-09-12 | |
| SecurID Authentication SDK | All Supported | Not Impacted | 2017-09-12 | |
| SecurID Software Token Converter | All Supported | Not Impacted | 2017-09-12 | |
| SecurID Software Token for Android | All Supported | Not Impacted | 2017-09-12 | |
| SecurID Software Token for Blackberry | All Supported | Not Impacted | 2017-09-12 | |
| SecurID Software Token for Desktop | All Supported | Not Impacted | 2017-09-12 | |
| SecurID Software Token for iPhone | All Supported | Not Impacted | 2017-09-12 | |
| SecurID Software Token for Windows Mobile | All Supported | Not Impacted | 2017-09-12 | |
| SecurID Software Token Toolbar | All Supported | Not Impacted | 2017-09-12 | |
| SecurID Software Token Web SDK | All Supported | Not Impacted | 2017-09-12 | |
| SecurID Transaction Signing SDK | All Supported | Not Impacted | 2017-09-12 | |
| Web Threat Detection | All Supported | Not Impacted | Product does not use Apache Struts | 2017-10-16 |
Notes
For status of Dell EMC products, see: https://support.emc.com/kb/504013
For status of Dell EMC CPSD products, see: http://support.vce.com/kA2A0000000LKm0
Disclaimer
Related Articles
Apache Struts 2 Remote Code Execution Vulnerability (CVE-2018-11776): Impact on RSA products 142Number of Views How to remediate the impact of the POODLE vulnerability on RSA Endpoint 234Number of Views Apache Common Library InvokerTransformer Vulnerability (CVE-2015-4852 & CVE-2015-6420) in RSA Access Manager 6.x - False P… 44Number of Views Spring-related vulnerabilities for RSA Authentication Manager 135Number of Views Bash bug Vulnerability (Shellshock) in RSA products 1.3KNumber of Views
Trending Articles
Passwordless Authentication in Windows MFA Agent for Active Directory – Quick Setup Guide RSA Authentication Manager 8.9 Release Notes (January 2026) RSA Authentication Manager Upgrade Process RSA Authentication Manager 8.7 SP2 Setup and Configuration Guide An example of SSO using SAML and ADFS with RSA Identity Management and Governance 6.9.x
Don't see what you're looking for?