Apache Struts 2 Freemarker Remote Code Execution Vulnerability (CVE-2017-12611) in RSA Products
Originally Published: 2017-09-11
Article Number
Applies To
CVE Identifier(s)
Article Summary
The details for this vulnerability can be found at https://struts.apache.org/docs/s2-053.html.
Resolution
| RSA Product Name | Versions | Impacted? | Details | Last Updated |
|---|---|---|---|---|
| 3D Secure / Adaptive Authentication eCommerce | All Supported | Not Impacted | 2017-09-25 | |
| Access Manager | 6.2.4, 6.2.3, 6.2.2, 6.2.1, 6.2 | Impacted - Remediated | Refer to the security advisory ESA-2017-130 on RSA Link. Hotfixes 6.2.4.07, 6.2.3.08, 6.2.2.11, 6.2.1.10, and 6.2.0.24 with a fix for this issue, are available for RSA Access Manager 6.2.x. | 2017-10-17 |
| Adaptive Authentication Cloud | All Supported | Not Impacted | 2017-10-02 | |
| Adaptive Authentication Hosted | All Supported | Not Impacted | Product does not use impacted version of Apache Struts | 2017-09-15 |
| Adaptive Authentication On-Prem | 7.x | Not Impacted | 2017-09-22 | |
| Archer Hosted | N/A | Not Impacted | 2017-09-25 | |
| Archer Platform | All Supported | Not Impacted | Product does not use Apache Struts. | 2017-09-11 |
| Archer SecOps | All Supported | Not Impacted | Product does not use Apache Struts. | 2017-09-11 |
| Archer Vulnerability & Risk Manager (VRM) | All Supported | Not Impacted | Product does not use Apache Struts. | 2017-09-11 |
| Authentication Manager | 8.1, 8.1SP1, 8.2, 8.2SP1 | Not Impacted | 2017-09-12 | |
| Authentication Manager Appliance | 8.1, 8.1SP1, 8.2, 8.2SP1 | Not Impacted | 2017-09-12 | |
| BSAFE C Products: MES, Crypto-C ME, SSL-C | All Supported | Not Impacted | Product does not use Apache Struts. | 2017-09-14 |
| BSAFE Java Products: Cert-J, Crypto-J, SSL-J | All Supported | Not Impacted | Product does not use Apache Struts. | 2017-09-14 |
| Data Loss Prevention | All Supported | Not Impacted | Product does not use Apache Struts. | 2017-09-12 |
| Data Protection Manager | 3.5.2.5 and earlier | Impacted - Remediated | Refer to the security advisory ESA-2017-132 on RSA Link. RSA Data Protection Manager 3.5.2.6 with a fix for this issue is available. | 2017-10-20 |
| DCS: Certificate Manager | All Supported | Not Impacted | Product does not use Apache Struts. | 2017-09-11 |
| DCS: Validation Manager | All Supported | Not Impacted | Does not ship Freemarker Java Template Engine | 2017-09-11 |
| ECAT (NetWitness Endpoint) | All Supported | Not Impacted | Product does not use Apache Struts. | 2017-09-12 |
| eFraudNetwork (eFN) | All Supported | Not Impacted | 2017-09-25 | |
| enVision | EOPS | Not Impacted | Product does not use Apache Struts. | 2017-09-11 |
| Federated Identity Manager | All Supported | Not Impacted | Product does not use impacted version of Apache Struts | 2017-09-14 |
| FraudAction (OTMS) | All Supported | Not Impacted | 2017-09-25 | |
| Identity Governance and Lifecycle Software (Via Lifecycle and Governance Software, Identity Management & Governance Software) | All Supported | Not Impacted | Product does not use Apache Struts. | 2017-09-21 |
| Identity Governance and Lifecycle Appliance (Via Lifecycle and Governance Appliance, Identity Management & Governance Appliance) | All Supported | Not Impacted | Product does not use Apache Struts. | 2017-09-21 |
| Identity Governance and Lifecycle SaaS / MyAccessLive (Via Lifecycle and Governance SaaS / MyAccessLive) | All Supported | Not Impacted | Product does not use Apache Struts. | 2017-09-21 |
| NetWitness / Security Analytics (Physical and Virtual Appliances) | All Supported | Not Impacted | Product does not use Apache Struts. | 2017-09-12 |
| RSA Central | All Supported | Not Impacted | Product does not use impacted version of Apache Struts | 2017-09-15 |
| RSA Live Infrastructure | All Supported | Not Impacted | Product does not use Apache Struts. | 2017-09-12 |
| SecurID Access Cloud Service | All Supported | Not Impacted | 2017-09-25 | |
| SecurID Access IDR VM | All Supported | Not Impacted | 2017-09-25 | |
| SecurID Agent for PAM | All Supported | Not Impacted | 2017-09-12 | |
| SecurID Agent for Web | All Supported | Not Impacted | 2017-09-12 | |
| SecurID Agent for Windows | All Supported | Not Impacted | 2017-09-12 | |
| SecurID Authentication Engine | All Supported | Not Impacted | 2017-09-12 | |
| SecurID Authentication SDK | All Supported | Not Impacted | 2017-09-12 | |
| SecurID Software Token Converter | All Supported | Not Impacted | 2017-09-12 | |
| SecurID Software Token for Android | All Supported | Not Impacted | 2017-09-12 | |
| SecurID Software Token for Blackberry | All Supported | Not Impacted | 2017-09-12 | |
| SecurID Software Token for Desktop | All Supported | Not Impacted | 2017-09-12 | |
| SecurID Software Token for iPhone | All Supported | Not Impacted | 2017-09-12 | |
| SecurID Software Token for Windows Mobile | All Supported | Not Impacted | 2017-09-12 | |
| SecurID Software Token Toolbar | All Supported | Not Impacted | 2017-09-12 | |
| SecurID Software Token Web SDK | All Supported | Not Impacted | 2017-09-12 | |
| SecurID Transaction Signing SDK | All Supported | Not Impacted | 2017-09-12 | |
| Web Threat Detection | All Supported | Not Impacted | Product does not use Apache Struts | 2017-10-16 |
Notes
For status of Dell EMC products, see: https://support.emc.com/kb/504013
For status of Dell EMC CPSD products, see: http://support.vce.com/kA2A0000000LKm0
Disclaimer
Related Articles
Apache Common Library InvokerTransformer Vulnerability (CVE-2015-4852 & CVE-2015-6420) in RSA Access Manager 6.x - False P… 44Number of Views Apache Struts 2 Remote Code Execution Vulnerability (CVE-2018-11776): Impact on RSA products 143Number of Views RSA Certificate Manager security vulnerabilities for Apache - False Positives (CVE-2011-3368 / CVE-2012-0053 / CVE-2013-18… 73Number of Views KCA Apache web server showing security vulnerability with scan due patch level/version 47Number of Views Multiple Apache Tomcat Vulnerabilities in RSA Authentication Manager - False Positive 117Number of Views
Trending Articles
Troubleshooting RSA SecurID Access Identity Router to RSA Authentication Manager test connection failures RSA SecurID Software Token 5.0.2 Downloads for Microsoft Windows RSA Authentication Manager 8.9 Release Notes (January 2026) RSA Governance & Lifecycle 8.0.0 Administrators Guide Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory
Don't see what you're looking for?