Apache Struts 2 Remote Code Execution Vulnerability (CVE-2018-11776): Impact on RSA products
Originally Published: 2018-08-24
Article Number
CVE Identifier(s)
Article Summary
Link to Advisories
Resolution
| RSA Product Name | Versions | Impact Status | Details | Last Updated |
|---|---|---|---|---|
| RSA 3D Secure/Adaptive Authentication eCommerce | All Supported | Not Impacted | Product does not use Apache Struts. | 2018-08-24 |
| RSA Access Manager | 6.2, 6.2.1, 6.2.2, 6.2.3, 6.2.4 | Not Impacted | Product uses Apache Struts but not impacted by this issue. | 2018-08-30 |
| RSA Adaptive Authentication Cloud | All Supported | Not Impacted | 2018-08-24 | |
| RSA Adaptive Authentication Hosted | All Supported | Not Impacted | Product does not use Apache Struts. | 2018-08-28 |
| RSA Adaptive Authentication On-Prem | 7.x | Not Impacted | Product does not use impacted version of Apache Struts. | 2018-08-28 |
| RSA Archer Hosted | N/A | Not Impacted | 2018-08-24 | |
| RSA Archer Platform | All Supported | Not Impacted | Product does not use Apache Struts. | 2018-08-24 |
| RSA Archer Security Operations Management (SecOps) | All Supported | Not Impacted | Product does not use Apache Struts. | 2018-08-24 |
| RSA Archer Vulnerability & Risk Manager (VRM) | All Supported | Not Impacted | Product does not use Apache Struts. | 2018-08-24 |
| RSA Authentication Client (RAC) | All Supported | Investigating | 2018-08-24 | |
| RSA Authentication Manager | All Supported | Not Impacted | 2018-08-24 | |
| RSA Authentication Manager Web Tier | All Supported | Not Impacted | 2018-08-27 | |
| RSA BSAFE C Products: MES, Crypto-C ME, SSL-C | All Supported | Not Impacted | Product does not use Apache Struts. | 2018-08-24 |
| RSA BSAFE Java Products: Cert-J, Crypto-J, SSL-J | All Supported | Not Impacted | Product does not use Apache Struts. | 2018-08-24 |
| RSA Central | All Supported | Not Impacted | Product does not use Apache Struts. | 2018-10-25 |
| RSA Data Loss Prevention | All Supported | Not Impacted | Product does not use Apache Struts. | 2018-08-24 |
| RSA Data Protection Manager | All Supported | Not Impacted | 2018-08-31 | |
| RSA DCS: RSA Certificate Manager | All Supported | Not Impacted | Product does not use Apache Struts. | 2018-08-24 |
| RSA DCS: RSA Validation Manager | All Supported | Not Impacted | Product does not use impacted version of Apache Struts. | 2018-08-27 |
| RSA eFraudNetwork (eFN) | All Supported | Not Impacted | 2018-08-24 | |
| RSA Federated Identity Manager | All Supported | Not Impacted | Product does not use impacted version of Apache Struts. | 2018-08-27 |
| RSA FraudAction (OTMS) | All Supported | Not Impacted | 2018-08-24 | |
| RSA Identity Governance and Lifecycle Software (RSA Via Lifecycle and Governance Software, RSA Identity Management & Governance Software) | All Supported | Not Impacted | Product does not use Apache Struts. | 2018-08-24 |
| RSA Identity Governance and Lifecycle Appliance (RSA Via Lifecycle and Governance Appliance, RSA Identity Management & Governance Appliance) | All Supported | Not Impacted | Product does not use Apache Struts. | 2018-08-24 |
| RSA Identity Governance and Lifecycle SaaS / MyAccessLive (RSA Via Lifecycle and Governance SaaS / MyAccessLive) | All Supported | Not Impacted | Product does not use Apache Struts. | 2018-08-24 |
| RSA Identity Governance and Lifecycle Virtual Application | All Supported | Not Impacted | Product does not use Apache Struts. | 2018-08-29 |
| RSA NetWitness Endpoint (ECAT) | All Supported | Not Impacted | Product does not use Apache Struts. | 2018-08-24 |
| RSA NetWitness Logs & Packets / Security Analytics (Hardware and Virtual Appliances) | All Supported | Not Impacted | Product does not use Apache Struts. | 2018-08-24 |
| RSA NetWitness Live Infrastructure | All Supported | Not Impacted | Product does not use Apache Struts. | 2018-08-24 |
| RSA SecurID Access Cloud Service | All Supported | Not Impacted | 2018-08-24 | |
| RSA SecurID Access IDR VM | All Supported | Not Impacted | 2018-08-24 | |
| RSA SecurID Agent for PAM | All Supported | Not Impacted | 2018-08-24 | |
| RSA SecurID Agent for Web | All Supported | Not Impacted | 2018-08-24 | |
| RSA SecurID Agent for Windows | All Supported | Not Impacted | 2018-08-24 | |
| RSA SecurID Authenticate App for Android | All Supported | Investigating | 2018-08-24 | |
| RSA SecurID Authenticate App for iOS | All Supported | Investigating | 2018-08-24 | |
| RSA SecurID Authenticate App for Windows 10 | All Supported | Investigating | 2018-08-24 | |
| RSA SecurID Authentication Engine | All Supported | Not Impacted | 2018-08-24 | |
| RSA SecurID Authentication SDK | All Supported | Not Impacted | 2018-08-24 | |
| RSA SecurID Software Token Converter | All Supported | Not Impacted | 2018-08-24 | |
| RSA SecurID Software Token for Android | All Supported | Not Impacted | 2018-08-24 | |
| RSA SecurID Software Token for Blackberry | All Supported | Not Impacted | 2018-08-24 | |
| RSA SecurID Software Token for Desktop | All Supported | Not Impacted | 2018-08-24 | |
| RSA SecurID Software Token for iPhone | All Supported | Not Impacted | 2018-08-24 | |
| RSA SecurID Software Token for Windows Mobile | All Supported | Not Impacted | 2018-08-24 | |
| RSA SecurID Software Token Toolbar | All Supported | Not Impacted | 2018-08-24 | |
| RSA SecurID Software Token Web SDK | All Supported | Not Impacted | 2018-08-24 | |
| RSA SecurID Transaction Signing SDK | All Supported | Not Impacted | 2018-08-24 | |
| RSA SYN | Current Hosted Environment | Not Impacted | Product does not use Apache Struts. | 2018-11-01 |
| RSA Web Threat Detection | All Supported | Not Impacted | Product does not use Apache Struts | 2018-08-24 |
Disclaimer
Related Articles
Apache Struts 2 Freemarker Remote Code Execution Vulnerability (CVE-2017-12611) in RSA Products 170Number of Views CERT/CC Vulnerability Note VU#144389: Potential Impact on RSA Products 198Number of Views Speculative Execution Side-Channel Vulnerabilities (CVE-2018-3615, CVE-2018-3620, and CVE-2018-3646): Impact on RSA products 98Number of Views Infineon Trusted Platform Module (TPM) Vulnerability (CVE-2017-15361) Impact on RSA Products 56Number of Views Apache Common Library InvokerTransformer Vulnerability (CVE-2015-4852 & CVE-2015-6420) in RSA Access Manager 6.x - False P… 44Number of Views
Trending Articles
Troubleshooting RSA SecurID Access Identity Router to RSA Authentication Manager test connection failures RSA SecurID Software Token 5.0.2 Downloads for Microsoft Windows RSA Authentication Manager 8.9 Release Notes (January 2026) Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory RSA Authentication Manager 8.8 Setup and Configuration Guide
Don't see what you're looking for?