Apache Struts Jakarta Multi-part Parser Code Execution (CVE-2017-5638)

Share this post:

On March 6, 2017 a vulnerability in the Apache Struts Jakarta Multi-part parser code execution was reported by Apache.

IBM is analyzing its products to determine which ones may be affected by this vulnerability. Affected IBM products will be issuing mitigations and/or fixes as soon as possible. Please actively monitor both your IBM Support Portal for available fixes and this blog for additional information.

IBM recommends that customers:

More Featured Carousel stories

IBM Security Bulletin: IBM Security Key Lifecycle Manager stores password in clear text (CVE-2019-4566)

Sep 21, 2019 9:02 am EDT | Medium Severity

IBM Security Key Lifecycle Manager stores user credentials in plain in clear text which can be read by a local user. CVE(s): CVE-2019-4566 Affected product(s) and affected version(s): IBM Security Key Lifecycle Manager (SKLM) v3.0 – v3.0.0.2 on distributed platforms IBM Security Key Lifecycle Manager (SKLM) v3.0.1- v3.0.1.1 on distributed platforms Refer to the following ...read more


IBM Security Bulletin: Apache Commons Compress vulnerability affects IBM Spectrum Control (formerly Tivoli Storage Productivity Center) (CVE-2019-12402)

Sep 21, 2019 9:02 am EDT | Medium Severity

Apache Commons Compress is vulnerable to a denial of service which can affect IBM Spectrum Control (formerly IBM Tivoli Storage Productivity Center). CVE(s): CVE-2019-12402 Affected product(s) and affected version(s): Affected Product Affected Versions IBM Tivoli Storage Productivity Center 5.2.0 – 5.2.7.1 IBM Spectrum Control 5.2.8 – 5.2.17.3 IBM Spectrum Control 5.3.0 – 5.3.3 The versions ...read more


IBM Security Bulletin: Node.js vulnerabilities affect IBM Spectrum Control (formerly Tivoli Storage Productivity Center) (CVE-2019-9511, CVE-2019-9512, CVE-2019-9513, CVE-2019-9514, CVE-2019-9515, CVE-2019-9516, CVE-2019-9517, CVE-2019-9518)

Sep 21, 2019 9:02 am EDT | High Severity

Node.js denial of service vulnerabilities affect IBM Spectrum Control (formerly Tivoli Storage Productivity Center). CVE(s): CVE-2019-9511, CVE-2019-9512, CVE-2019-9513, CVE-2019-9514, CVE-2019-9515, CVE-2019-9516, CVE-2019-9517, CVE-2019-9518 Affected product(s) and affected version(s): Affected Product Affected Versions IBM Spectrum Control 5.3.0 – 5.3.3 Note that the 5.2 release is not affected. Refer to the following reference URLs for remediation and ...read more