Apache Struts 2 Freemarker Remote Code Execution Vulnerability (CVE-2017-12611) in RSA Products
Originally Published: 2017-09-11
Last Modified: 2023-10-06
Article Number
Applies To
CVE Identifier(s)
Article Summary
The details for this vulnerability can be found at https://struts.apache.org/docs/s2-053.html.
Resolution
| RSA Product Name | Versions | Impacted? | Details | Last Updated |
|---|---|---|---|---|
| 3D Secure / Adaptive Authentication eCommerce | All Supported | Not Impacted | 2017-09-25 | |
| Access Manager | 6.2.4, 6.2.3, 6.2.2, 6.2.1, 6.2 | Impacted - Remediated | Refer to the security advisory ESA-2017-130 on RSA Link. Hotfixes 6.2.4.07, 6.2.3.08, 6.2.2.11, 6.2.1.10, and 6.2.0.24 with a fix for this issue, are available for RSA Access Manager 6.2.x. | 2017-10-17 |
| Adaptive Authentication Cloud | All Supported | Not Impacted | 2017-10-02 | |
| Adaptive Authentication Hosted | All Supported | Not Impacted | Product does not use impacted version of Apache Struts | 2017-09-15 |
| Adaptive Authentication On-Prem | 7.x | Not Impacted | 2017-09-22 | |
| Archer Hosted | N/A | Not Impacted | 2017-09-25 | |
| Archer Platform | All Supported | Not Impacted | Product does not use Apache Struts. | 2017-09-11 |
| Archer SecOps | All Supported | Not Impacted | Product does not use Apache Struts. | 2017-09-11 |
| Archer Vulnerability & Risk Manager (VRM) | All Supported | Not Impacted | Product does not use Apache Struts. | 2017-09-11 |
| Authentication Manager | 8.1, 8.1SP1, 8.2, 8.2SP1 | Not Impacted | 2017-09-12 | |
| Authentication Manager Appliance | 8.1, 8.1SP1, 8.2, 8.2SP1 | Not Impacted | 2017-09-12 | |
| BSAFE C Products: MES, Crypto-C ME, SSL-C | All Supported | Not Impacted | Product does not use Apache Struts. | 2017-09-14 |
| BSAFE Java Products: Cert-J, Crypto-J, SSL-J | All Supported | Not Impacted | Product does not use Apache Struts. | 2017-09-14 |
| Data Loss Prevention | All Supported | Not Impacted | Product does not use Apache Struts. | 2017-09-12 |
| Data Protection Manager | 3.5.2.5 and earlier | Impacted - Remediated | Refer to the security advisory ESA-2017-132 on RSA Link. RSA Data Protection Manager 3.5.2.6 with a fix for this issue is available. | 2017-10-20 |
| DCS: Certificate Manager | All Supported | Not Impacted | Product does not use Apache Struts. | 2017-09-11 |
| DCS: Validation Manager | All Supported | Not Impacted | Does not ship Freemarker Java Template Engine | 2017-09-11 |
| ECAT (NetWitness Endpoint) | All Supported | Not Impacted | Product does not use Apache Struts. | 2017-09-12 |
| eFraudNetwork (eFN) | All Supported | Not Impacted | 2017-09-25 | |
| enVision | EOPS | Not Impacted | Product does not use Apache Struts. | 2017-09-11 |
| Federated Identity Manager | All Supported | Not Impacted | Product does not use impacted version of Apache Struts | 2017-09-14 |
| FraudAction (OTMS) | All Supported | Not Impacted | 2017-09-25 | |
| Identity Governance and Lifecycle Software (Via Lifecycle and Governance Software, Identity Management & Governance Software) | All Supported | Not Impacted | Product does not use Apache Struts. | 2017-09-21 |
| Identity Governance and Lifecycle Appliance (Via Lifecycle and Governance Appliance, Identity Management & Governance Appliance) | All Supported | Not Impacted | Product does not use Apache Struts. | 2017-09-21 |
| Identity Governance and Lifecycle SaaS / MyAccessLive (Via Lifecycle and Governance SaaS / MyAccessLive) | All Supported | Not Impacted | Product does not use Apache Struts. | 2017-09-21 |
| NetWitness / Security Analytics (Physical and Virtual Appliances) | All Supported | Not Impacted | Product does not use Apache Struts. | 2017-09-12 |
| RSA Central | All Supported | Not Impacted | Product does not use impacted version of Apache Struts | 2017-09-15 |
| RSA Live Infrastructure | All Supported | Not Impacted | Product does not use Apache Struts. | 2017-09-12 |
| SecurID Access Cloud Service | All Supported | Not Impacted | 2017-09-25 | |
| SecurID Access IDR VM | All Supported | Not Impacted | 2017-09-25 | |
| SecurID Agent for PAM | All Supported | Not Impacted | 2017-09-12 | |
| SecurID Agent for Web | All Supported | Not Impacted | 2017-09-12 | |
| SecurID Agent for Windows | All Supported | Not Impacted | 2017-09-12 | |
| SecurID Authentication Engine | All Supported | Not Impacted | 2017-09-12 | |
| SecurID Authentication SDK | All Supported | Not Impacted | 2017-09-12 | |
| SecurID Software Token Converter | All Supported | Not Impacted | 2017-09-12 | |
| SecurID Software Token for Android | All Supported | Not Impacted | 2017-09-12 | |
| SecurID Software Token for Blackberry | All Supported | Not Impacted | 2017-09-12 | |
| SecurID Software Token for Desktop | All Supported | Not Impacted | 2017-09-12 | |
| SecurID Software Token for iPhone | All Supported | Not Impacted | 2017-09-12 | |
| SecurID Software Token for Windows Mobile | All Supported | Not Impacted | 2017-09-12 | |
| SecurID Software Token Toolbar | All Supported | Not Impacted | 2017-09-12 | |
| SecurID Software Token Web SDK | All Supported | Not Impacted | 2017-09-12 | |
| SecurID Transaction Signing SDK | All Supported | Not Impacted | 2017-09-12 | |
| Web Threat Detection | All Supported | Not Impacted | Product does not use Apache Struts | 2017-10-16 |
Notes
For status of Dell EMC products, see: https://support.emc.com/kb/504013
For status of Dell EMC CPSD products, see: http://support.vce.com/kA2A0000000LKm0
Disclaimer
Related Articles
Apache Struts 2 Remote Code Execution Vulnerability (CVE-2018-11776): Impact on RSA products 147Number of Views RSA Identity Governance & Lifecycle Malicious Code Execution by root Vulnerability 51Number of Views How to get the Apache Tomcat version on an RSA enVision appliance 34Number of Views RSA Authentication Manager 8.1 SP 1 patch 1 backups to a Windows Shared Folder are failing after software upgrade 247Number of Views KCA Apache web server showing security vulnerability with scan due patch level/version 55Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Reporting on RSA Authentication Manager 8.x users with On-Demand Token, a fixed passcode or a hardware/software token assi… How to Download OTP Token Seed Files from myRSA Anomalix idGenius - SAML Relying Party Configuration - RSA Ready Implementation Guide RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide
Don't see what you're looking for?