Apache Struts 2 Remote Code Execution Vulnerability (CVE-2018-11776): Impact on RSA products
Originally Published: 2018-08-24
Article Number
CVE Identifier(s)
Article Summary
Link to Advisories
Resolution
| RSA Product Name | Versions | Impact Status | Details | Last Updated |
|---|---|---|---|---|
| RSA 3D Secure/Adaptive Authentication eCommerce | All Supported | Not Impacted | Product does not use Apache Struts. | 2018-08-24 |
| RSA Access Manager | 6.2, 6.2.1, 6.2.2, 6.2.3, 6.2.4 | Not Impacted | Product uses Apache Struts but not impacted by this issue. | 2018-08-30 |
| RSA Adaptive Authentication Cloud | All Supported | Not Impacted | 2018-08-24 | |
| RSA Adaptive Authentication Hosted | All Supported | Not Impacted | Product does not use Apache Struts. | 2018-08-28 |
| RSA Adaptive Authentication On-Prem | 7.x | Not Impacted | Product does not use impacted version of Apache Struts. | 2018-08-28 |
| RSA Archer Hosted | N/A | Not Impacted | 2018-08-24 | |
| RSA Archer Platform | All Supported | Not Impacted | Product does not use Apache Struts. | 2018-08-24 |
| RSA Archer Security Operations Management (SecOps) | All Supported | Not Impacted | Product does not use Apache Struts. | 2018-08-24 |
| RSA Archer Vulnerability & Risk Manager (VRM) | All Supported | Not Impacted | Product does not use Apache Struts. | 2018-08-24 |
| RSA Authentication Client (RAC) | All Supported | Investigating | 2018-08-24 | |
| RSA Authentication Manager | All Supported | Not Impacted | 2018-08-24 | |
| RSA Authentication Manager Web Tier | All Supported | Not Impacted | 2018-08-27 | |
| RSA BSAFE C Products: MES, Crypto-C ME, SSL-C | All Supported | Not Impacted | Product does not use Apache Struts. | 2018-08-24 |
| RSA BSAFE Java Products: Cert-J, Crypto-J, SSL-J | All Supported | Not Impacted | Product does not use Apache Struts. | 2018-08-24 |
| RSA Central | All Supported | Not Impacted | Product does not use Apache Struts. | 2018-10-25 |
| RSA Data Loss Prevention | All Supported | Not Impacted | Product does not use Apache Struts. | 2018-08-24 |
| RSA Data Protection Manager | All Supported | Not Impacted | 2018-08-31 | |
| RSA DCS: RSA Certificate Manager | All Supported | Not Impacted | Product does not use Apache Struts. | 2018-08-24 |
| RSA DCS: RSA Validation Manager | All Supported | Not Impacted | Product does not use impacted version of Apache Struts. | 2018-08-27 |
| RSA eFraudNetwork (eFN) | All Supported | Not Impacted | 2018-08-24 | |
| RSA Federated Identity Manager | All Supported | Not Impacted | Product does not use impacted version of Apache Struts. | 2018-08-27 |
| RSA FraudAction (OTMS) | All Supported | Not Impacted | 2018-08-24 | |
| RSA Identity Governance and Lifecycle Software (RSA Via Lifecycle and Governance Software, RSA Identity Management & Governance Software) | All Supported | Not Impacted | Product does not use Apache Struts. | 2018-08-24 |
| RSA Identity Governance and Lifecycle Appliance (RSA Via Lifecycle and Governance Appliance, RSA Identity Management & Governance Appliance) | All Supported | Not Impacted | Product does not use Apache Struts. | 2018-08-24 |
| RSA Identity Governance and Lifecycle SaaS / MyAccessLive (RSA Via Lifecycle and Governance SaaS / MyAccessLive) | All Supported | Not Impacted | Product does not use Apache Struts. | 2018-08-24 |
| RSA Identity Governance and Lifecycle Virtual Application | All Supported | Not Impacted | Product does not use Apache Struts. | 2018-08-29 |
| RSA NetWitness Endpoint (ECAT) | All Supported | Not Impacted | Product does not use Apache Struts. | 2018-08-24 |
| RSA NetWitness Logs & Packets / Security Analytics (Hardware and Virtual Appliances) | All Supported | Not Impacted | Product does not use Apache Struts. | 2018-08-24 |
| RSA NetWitness Live Infrastructure | All Supported | Not Impacted | Product does not use Apache Struts. | 2018-08-24 |
| RSA SecurID Access Cloud Service | All Supported | Not Impacted | 2018-08-24 | |
| RSA SecurID Access IDR VM | All Supported | Not Impacted | 2018-08-24 | |
| RSA SecurID Agent for PAM | All Supported | Not Impacted | 2018-08-24 | |
| RSA SecurID Agent for Web | All Supported | Not Impacted | 2018-08-24 | |
| RSA SecurID Agent for Windows | All Supported | Not Impacted | 2018-08-24 | |
| RSA SecurID Authenticate App for Android | All Supported | Investigating | 2018-08-24 | |
| RSA SecurID Authenticate App for iOS | All Supported | Investigating | 2018-08-24 | |
| RSA SecurID Authenticate App for Windows 10 | All Supported | Investigating | 2018-08-24 | |
| RSA SecurID Authentication Engine | All Supported | Not Impacted | 2018-08-24 | |
| RSA SecurID Authentication SDK | All Supported | Not Impacted | 2018-08-24 | |
| RSA SecurID Software Token Converter | All Supported | Not Impacted | 2018-08-24 | |
| RSA SecurID Software Token for Android | All Supported | Not Impacted | 2018-08-24 | |
| RSA SecurID Software Token for Blackberry | All Supported | Not Impacted | 2018-08-24 | |
| RSA SecurID Software Token for Desktop | All Supported | Not Impacted | 2018-08-24 | |
| RSA SecurID Software Token for iPhone | All Supported | Not Impacted | 2018-08-24 | |
| RSA SecurID Software Token for Windows Mobile | All Supported | Not Impacted | 2018-08-24 | |
| RSA SecurID Software Token Toolbar | All Supported | Not Impacted | 2018-08-24 | |
| RSA SecurID Software Token Web SDK | All Supported | Not Impacted | 2018-08-24 | |
| RSA SecurID Transaction Signing SDK | All Supported | Not Impacted | 2018-08-24 | |
| RSA SYN | Current Hosted Environment | Not Impacted | Product does not use Apache Struts. | 2018-11-01 |
| RSA Web Threat Detection | All Supported | Not Impacted | Product does not use Apache Struts | 2018-08-24 |
Disclaimer
Related Articles
Apache Struts 2 Freemarker Remote Code Execution Vulnerability (CVE-2017-12611) in RSA Products 172Number of Views Speculative Execution Side-Channel Vulnerabilities (CVE-2018-3615, CVE-2018-3620, and CVE-2018-3646): Impact on RSA products 100Number of Views Apache Common Library InvokerTransformer Vulnerability (CVE-2015-4852 & CVE-2015-6420) in RSA Access Manager 6.x - False P… 45Number of Views Microprocessor Side-Channel Attacks (CVE-2017-5715, CVE-2017-5753, CVE-2017-5754): Impact on RSA products 707Number of Views Spring-related vulnerabilities for RSA Authentication Manager 156Number of Views
Trending Articles
RSA Authentication Manager 8.9 Release Notes (January 2026) RSA announces the availability of the RSA SecurID Hardware Appliance 230 based on the Dell PowerEdge R240 Server How to troubleshoot Oracle database ORA-04030 errors in RSA Identity Governance & Lifecycle RSA Authentication Manager Upgrade Process Microsoft SQL Server Collectors can no longer connect to the SQL Server database after upgrade to Microsoft SQL Server 201…
Don't see what you're looking for?