Apache Struts Jakarta Multi-part Parser Code Execution (CVE-2017-5638)

Share this post:

On March 6, 2017 a vulnerability in the Apache Struts Jakarta Multi-part parser code execution was reported by Apache.

IBM is analyzing its products to determine which ones may be affected by this vulnerability. Affected IBM products will be issuing mitigations and/or fixes as soon as possible. Please actively monitor both your IBM Support Portal for available fixes and this blog for additional information.

IBM recommends that customers:

More Featured Carousel stories

IBM Security Bulletin: Multiple vulnerabilities in IBM Java SDK affect IBM Web Experience Factory

May 21, 2019 9:01 am EDT | Medium Severity

There are multiple vulnerabilities in IBM® SDK Java™ Technology Edition, Version 8 used by IBM Web Experience Factory. IBM Web Experience Factory has addressed the applicable CVEs. CVE(s): CVE-2018-11212, CVE-2019-2426, CVE-2018-1890 Affected product(s) and affected version(s):IBM Web Experience Factory 8.5 Refer to the following reference URLs for remediation and additional vulnerability details:Source Bulletin: https://www-01.ibm.com/support/docview.wss?uid=ibm10884948X-Force Database: ...read more


IBM Security Bulletin: A security vulnerability has been identified in OpenSSL, which is shipped with IBM Tivoli Network Manager IP Edition (CVE-2018-0734)

May 21, 2019 9:00 am EDT | Low Severity

OpenSSL is shipped with IBM Tivoli Network Manager IP Edition version 3.9. Information about a security vulnerability affecting Open SSL has been published here. CVE(s): CVE-2018-0734 Affected product(s) and affected version(s): IBM Tivoli Network Manager IP Edition v3.9 Fix Pack 4 & Fix Pack 5. Refer to the following reference URLs for remediation and additional ...read more


IBM Addresses Reported Intel Security Vulnerabilities

May 20, 2019 4:34 pm EDT

In May 2019, Microarchitectural Data Sampling (MDS) side channel attack variants were disclosed (CVE-2018-12126, CVE-2018-12127, CVE-2018-12130, and CVE-2019-11091). These security vulnerabilities made public by Intel have the potential to allow an attacker running code on the same physical CPU to read other data being processed by that CPU. There are no known exploits at this ...read more