This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
NetWitness Platform Product Advisories
Read and subscribe to the latest announcements and advisories relating to the NetWitness Platform.
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
Announcement Banner

Users are unable to open Netwitness Support Cases via email. Please open support cases via portal or by phone

View Details
  • NetWitness Community
  • Products
  • NetWitness Platform
  • Advisories
  • Product Advisories
  • Threat Content Advisory: Apache Struts - CVE-2017-9805
  • Options
    • Subscribe to RSS Feed
    • Bookmark
    • Subscribe
    • Email to a Friend
    • Printer Friendly Page
    • Report Inappropriate Content
Threat Content Advisory: Apache Struts - CVE-2017-9805

Threat Content Advisory: Apache Struts - CVE-2017-9805

Summary

The Apache Software Foundation has patched a vulnerability identified as CVE-2017-9805. The vulnerability affects all versions of Apache Struts since 2008. In response to this we have created and released a parser to help identify systems exploited by the vulnerability. Upon this parser matching network traffic you'll see "apache struts CVE-2017-9805 attempt" appear in the 'Indicators of Compromise' meta-key and the command that was included in the exploit attempt will be present in the 'Action' meta-key. The parser, 'struts_exploit', is now available in RSA NetWitness Live.

 

Here's a sample attack that our researchers have seen in the wild:

pastedImage_4.png

 

EOPS Policy

RSA has a defined End of Primary Support policy associated with all major versions. Please refer to the Product Version Life Cycle for additional details.
Labels (2)
Labels:
  • RSA NetWitness Platform

  • Technical Advisories

Tags (16)
  • Advisory
  • Exploit
  • NetWitness
  • NW
  • NWP
  • Product Communication
  • Product Notification
  • RSA Live Content
  • RSA NetWitness
  • RSA NetWitness Platform
  • RSA Technical Advisory
  • technical advisory
  • Technical Alert
  • Technical Communication
  • Technical Notification
  • threat
1 Like
Was this article helpful? Yes No
Share
No ratings

In this article

Version history
Last update:
‎2017-09-08 05:32 PM
Updated by:
Employee NetWitnessTeam

Related Content

Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.