This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
      • Netwitness XDR
      • EC-Council Training
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
    • Role-Based Training
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
NetWitness Platform Product Advisories
Read and subscribe to the latest announcements and advisories relating to the NetWitness Platform.
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
  • NetWitness Community
  • Products
  • NetWitness Platform
  • Advisories
  • Product Advisories
  • Apache Struts 2 Remote Code Execution Vulnerability (CVE-2018-11776): Impact on RSA products
  • Options
    • Subscribe to RSS Feed
    • Bookmark
    • Subscribe
    • Printer Friendly Page
    • Report Inappropriate Content
Apache Struts 2 Remote Code Execution Vulnerability (CVE-2018-11776): Impact on RSA products

Apache Struts 2 Remote Code Execution Vulnerability (CVE-2018-11776): Impact on RSA products

Article Number

000036658

CVE ID

000036658

Article Summary

On August 22, 2018, Apache Software Foundation disclosed a vulnerability in Apache Struts 2 that could allow an attacker to execute arbitrary commands remotely on affected systems. For more information on this vulnerability, please review the Apache security advisory (S2-057).

Link to Advisories

  • Apache: https://cwiki.apache.org/confluence/display/WW/S2-057

Resolution

RSA is aware of and investigating the impact of this vulnerability on our products. The following table contains the latest available impact information. The table will be updated as additional information becomes available.
 
RSA Product NameVersionsImpact StatusDetailsLast Updated
RSA 3D Secure/Adaptive Authentication eCommerceAll SupportedNot ImpactedProduct does not use Apache Struts.2018-08-24
RSA Access Manager6.2, 6.2.1, 6.2.2, 6.2.3, 6.2.4Not ImpactedProduct uses Apache Struts but not impacted by this issue.2018-08-30
RSA Adaptive Authentication CloudAll SupportedNot Impacted 2018-08-24
RSA Adaptive Authentication HostedAll SupportedNot ImpactedProduct does not use Apache Struts.2018-08-28
RSA Adaptive Authentication On-Prem7.xNot ImpactedProduct does not use impacted version of Apache Struts.2018-08-28
RSA Archer HostedN/ANot Impacted 2018-08-24
RSA Archer PlatformAll SupportedNot ImpactedProduct does not use Apache Struts.2018-08-24
RSA Archer Security Operations Management (SecOps)All SupportedNot ImpactedProduct does not use Apache Struts.2018-08-24
RSA Archer Vulnerability & Risk Manager (VRM)All SupportedNot ImpactedProduct does not use Apache Struts.2018-08-24
RSA Authentication Client (RAC)All SupportedInvestigating 2018-08-24
RSA Authentication ManagerAll SupportedNot Impacted 2018-08-24
RSA Authentication Manager Web TierAll SupportedNot Impacted 2018-08-27
RSA BSAFE C Products: MES, Crypto-C ME, SSL-CAll SupportedNot ImpactedProduct does not use Apache Struts.2018-08-24
RSA BSAFE Java Products: Cert-J, Crypto-J, SSL-JAll SupportedNot ImpactedProduct does not use Apache Struts.2018-08-24
RSA CentralAll SupportedNot ImpactedProduct does not use Apache Struts.2018-10-25
RSA Data Loss PreventionAll SupportedNot ImpactedProduct does not use Apache Struts.2018-08-24
RSA Data Protection ManagerAll SupportedNot Impacted 2018-08-31
RSA DCS: RSA Certificate ManagerAll SupportedNot ImpactedProduct does not use Apache Struts.2018-08-24
RSA DCS: RSA Validation ManagerAll SupportedNot ImpactedProduct does not use impacted version of Apache Struts.2018-08-27
RSA eFraudNetwork (eFN)All SupportedNot Impacted 2018-08-24
RSA Federated Identity ManagerAll SupportedNot ImpactedProduct does not use impacted version of Apache Struts.2018-08-27
RSA FraudAction (OTMS)All SupportedNot Impacted 2018-08-24
RSA Identity Governance and Lifecycle Software
(RSA Via Lifecycle and Governance Software, RSA Identity Management & Governance Software)
All SupportedNot ImpactedProduct does not use Apache Struts.2018-08-24
RSA Identity Governance and Lifecycle Appliance
(RSA Via Lifecycle and Governance Appliance, RSA Identity Management & Governance Appliance)
All SupportedNot ImpactedProduct does not use Apache Struts.2018-08-24
RSA Identity Governance and Lifecycle SaaS / MyAccessLive
(RSA Via Lifecycle and Governance SaaS / MyAccessLive)
All SupportedNot ImpactedProduct does not use Apache Struts.2018-08-24
RSA Identity Governance and Lifecycle Virtual ApplicationAll SupportedNot ImpactedProduct does not use Apache Struts.2018-08-29
RSA NetWitness Endpoint (ECAT)All SupportedNot ImpactedProduct does not use Apache Struts.2018-08-24
RSA NetWitness Logs & Packets / Security Analytics
(Hardware and Virtual Appliances)
All SupportedNot ImpactedProduct does not use Apache Struts.2018-08-24
RSA NetWitness Live InfrastructureAll SupportedNot ImpactedProduct does not use Apache Struts.2018-08-24
RSA SecurID Access Cloud ServiceAll SupportedNot Impacted 2018-08-24
RSA SecurID Access IDR VMAll SupportedNot Impacted 2018-08-24
RSA SecurID Agent for PAMAll SupportedNot Impacted 2018-08-24
RSA SecurID Agent for WebAll SupportedNot Impacted 2018-08-24
RSA SecurID Agent for WindowsAll SupportedNot Impacted 2018-08-24
RSA SecurID Authenticate App for AndroidAll SupportedInvestigating 2018-08-24
RSA SecurID Authenticate App for iOSAll SupportedInvestigating 2018-08-24
RSA SecurID Authenticate App for Windows 10All SupportedInvestigating 2018-08-24
RSA SecurID Authentication EngineAll SupportedNot Impacted 2018-08-24
RSA SecurID Authentication SDKAll SupportedNot Impacted 2018-08-24
RSA SecurID Software Token ConverterAll SupportedNot Impacted 2018-08-24
RSA SecurID Software Token for AndroidAll SupportedNot Impacted 2018-08-24
RSA SecurID Software Token for BlackberryAll SupportedNot Impacted 2018-08-24
RSA SecurID Software Token for DesktopAll SupportedNot Impacted 2018-08-24
RSA SecurID Software Token for iPhoneAll SupportedNot Impacted 2018-08-24
RSA SecurID Software Token for Windows MobileAll SupportedNot Impacted 2018-08-24
RSA SecurID Software Token ToolbarAll SupportedNot Impacted 2018-08-24
RSA SecurID Software Token Web SDKAll SupportedNot Impacted 2018-08-24
RSA SecurID Transaction Signing SDKAll SupportedNot Impacted 2018-08-24
RSA SYNCurrent Hosted EnvironmentNot ImpactedProduct does not use Apache Struts.2018-11-01
RSA Web Threat DetectionAll SupportedNot ImpactedProduct does not use Apache Struts2018-08-24
Tags (30)
  • Advisory
  • All Products
  • All RSA Products
  • All Versions
  • Any Version
  • Customer Support
  • Customer Support Article
  • CVE
  • Every Version
  • High Profile
  • Impact
  • Impacted
  • KB Article
  • Knowledge Article
  • Knowledge Base
  • Recommendation
  • RSA Security Advisory
  • RSA Security Alert
  • Security Advisory
  • Security Advisory Article
  • Security Alert
  • Security Notification
  • Security Recommendations
  • Security Warning
  • Version Agnostic
  • Vuln
  • Vulnerabilities
  • Vulnerability
  • Vulnerability Warning
  • Vulnerable
0 Likes
Was this article helpful? Yes No
Share
No ratings

In this article

Version history
Last update:
‎2020-12-12 07:29 PM
Updated by:
Administrator RSA-KB-Sync Administrator

Related Content

Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.