Article Content
Article Number | 000034930 |
Applies To | RSA Product Set: All RSA Products |
CVE ID | CVE-2017-5638 |
Article Summary | On March 6, 2017, Apache disclosed a vulnerability in the Jakarta multipart parser used in Apache Struts 2 that could allow an attacker to execute commands remotely on the targeted system using a crafted Content-Type header value. The details for this vulnerability can be found at https://cwiki.apache.org/confluence/display/WW/S2-045. |
Resolution | RSA is aware of and investigating this issue to identify the product impact. The level of impact may vary depending on the affected product. The following table contains the latest available impact information. This table will be updated as additional information becomes available.
RSA Product Name | Versions | Impacted? | Details | Last Updated |
---|
3D Secure / Adaptive Authentication eCommerce | All Supported | Not Impacted | | 2017-03-13 | Access Manager | 6.2, 6.2.1, 6.2.2, 6.2.3, 6.2.4 | Impacted | Refer to the security advisory ESA-2017-038 on RSA Link. Hotfix 6.2.4.04 with a fix for this issue, is available for RSA Access Manager 6.2.4. For other affected versions, hotfixes are being worked on. See KB 000034968 for remedial steps where hotfix is not yet available. | 2017-03-28 | Adaptive Authentication Hosted | 11, 12 | Not Impacted | | 2017-03-13 | Adaptive Authentication On-Prem | 7.x | Not Impacted | Product does not use impacted version of Apache Struts | 2017-03-13 | Archer Hosted | N/A | Not Impacted | | 2017-03-13 | Archer Platform | All Supported | Not Impacted | | 2017-03-11 | Archer SecOps | All Supported | Not Impacted | | 2017-03-11 | Archer Vulnerability & Risk Manager (VRM) | All Supported | Not Impacted | | 2017-03-13 | Authentication Manager | 8.1, 8.1SP1, 8.2, 8.2SP1 | Not Impacted | | 2017-03-11 | Authentication Manager Appliance | 8.1, 8.1SP1, 8.2, 8.2SP1 | Not Impacted | | 2017-03-11 | BSAFE C Products: MES, Crypto-C ME, SSL-C | All Supported | Not Impacted | BSAFE products do not use Apache Struts. | 2017-03-14 | BSAFE Java Products: Cert-J, Crypto-J, SSL-J | All Supported | Not Impacted | BSAFE products do not use Apache Struts. | 2017-03-14 | Data Loss Prevention | All Supported | Not Impacted | | 2017-03-11 | Data Protection Manager | 3.5.2.5 | Impacted - Remediated | This issue is fixed in RSA DPM 3.5.2.5.1 (see ESA-2017-037). All other versions prior to 3.5.2.5 are NOT impacted. | 2017-04-10 | DCS: Certificate Manager | All Supported | Not Impacted | Product does not use Apache Struts. | 2017-03-14 | DCS: Validation Manager | All Supported | Not Impacted | Product does not use impacted version of Apache Struts | 2017-03-14 | ECAT (NetWitness Endpoint) | All Supported | Not Impacted | | 2017-03-11 | eFraudNetwork (eFN) | All Supported | | | | enVision | EOPS | Not Impacted | Product does not use Struts. | 2017-03-14 | Federated Identity Manager | All Supported | Not Impacted | | 2017-03-15 | FraudAction (OTMS) | All Supported | Not Impacted | | 2017-03-16 | Identity Governance and Lifecycle Software (Via Lifecycle and Governance Software, Identity Management & Governance Software) | All Supported | Not Impacted | Product does not use impacted version of Apache Struts | 2017-03-13 | Identity Governance and Lifecycle Appliance (Via Lifecycle and Governance Appliance, Identity Management & Governance Appliance) | All Supported | Not Impacted | Product does not use impacted version of Apache Struts | 2017-03-13 | Identity Governance and Lifecycle SaaS / MyAccessLive (Via Lifecycle and Governance SaaS / MyAccessLive) | All Supported | Not Impacted | Product does not use impacted version of Apache Struts | 2017-03-15 | RSA Central | All Supported | | | | RSA Live Infrastructure | All Supported | Not Impacted | | 2017-03-13 | SecurID Access Suite | All Supported | Not Impacted | | 2017-03-11 | SecurID Agent for PAM | All Supported | Not Impacted | | 2017-03-11 | SecurID Agent for Web | All Supported | Not Impacted | | 2017-03-11 | SecurID Agent for Windows | All Supported | Not Impacted | | 2017-03-11 | SecurID Authentication Engine | All Supported | Not Impacted | | 2017-03-11 | SecurID Authentication SDK | All Supported | Not Impacted | | 2017-03-11 | SecurID Software Token Converter | All Supported | Not Impacted | | 2017-03-11 | SecurID Software Token for Android | All Supported | Not Impacted | | 2017-03-11 | SecurID Software Token for Blackberry | All Supported | Not Impacted | | 2017-03-11 | SecurID Software Token for Desktop | All Supported | Not Impacted | | 2017-03-11 | SecurID Software Token for iPhone | All Supported | Not Impacted | | 2017-03-11 | SecurID Software Token for Windows Mobile | All Supported | Not Impacted | | 2017-03-11 | SecurID Software Token Toolbar | All Supported | Not Impacted | | 2017-03-11 | SecurID Software Token Web SDK | All Supported | Not Impacted | | 2017-03-11 | SecurID Transaction Signing SDK | All Supported | Not Impacted | | 2017-03-15 | Security Analytics (Physical and Virtual Appliances) | All Supported | Not Impacted | | 2017-03-11 | Via Access IDR VM (SecurID Access Suite) | All Supported | Not Impacted | | 2017-03-11 | Via Access Cloud Service (SecurID Access Suite) | All Supported | Not Impacted | | 2017-03-11 | Web Threat Detection | All Supported | Not Impacted | | 2017-03-13 |
|
Notes | For status of Dell products, see: http://www.dell.com/support/article/us/en/19/SLN305421 For status of Dell EMC products, see: https://support.emc.com/kb/497237 For status of VCE products, see: https://na7.salesforce.com/knowledge/publishing/articleOnlineDetail.apexp?id=kA2A00000004eyP |
Disclaimer
Read and use the information in this RSA Security Advisory to assist in avoiding any situation that might arise from the problems described herein. If you have any questions regarding this product alert, contact RSA Software Technical Support at 1- 800 995 5095. RSA Security LLC and its affiliates, including without limitation, its ultimate parent company, EMC Corporation, distributes RSA Security Advisories in order to bring to the attention of users of the affected RSA products, important security information. RSA recommends that all users determine the applicability of this information to their individual situations and take appropriate action. The information set forth herein is provided 'as is' without warranty of any kind. RSA disclaims all warranties, either express or implied, including the warranties of merchantability, fitness for a particular purpose, title and non-infringement. In no event, shall RSA, its affiliates or suppliers, be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if RSA, its affiliates or suppliers have been advised of the possibility of such damages. Some jurisdictions do not allow the exclusion or limitation of liability for consequential or incidental damages, so the foregoing limitation may not apply.