2017-03-15
12:34 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Apache Struts Vulnerability
Is RSA SecureID authentication manager 8.X vulnerable to the new apache struts vuln? I see you had to patch struts back in 2014 with an advisory. What about the latest one? Does any of the SP resolve it? 8.2.5? or wait for SP6?
CVE number: CVE-2017-5638
The vulnerability exists in Apache Struts versions 2.3.5 through 2.3.31 and 2.5 through 2.5.10
I dont see a new advisory for this
1 Solution
Accepted Solutions
2017-03-15
08:17 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
HI Nick,
There's a KB that was recently published in regards to this: https://community.rsa.com/docs/DOC-73349
2 Replies
2017-03-15
08:17 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
HI Nick,
There's a KB that was recently published in regards to this: https://community.rsa.com/docs/DOC-73349
2017-03-15
08:30 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Quick answer.
No vulnerability for Auth Manager and no vulnerability for RSA agents. The KB has the details.
