Security Bulletin
Summary
The Struts 1 plugin in Apache Struts 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.
Among all the PSS products (LSF, PPM, RTM, PWS), only PWS 9.1 and 9.1.3 have Struts libs in the package. However, PWS will not use the libs even though they are there, so there is no risk that the vulnerability will be exploited. The struts/structs2 libs have been removed from the package for PWS 9.1.3.2 (which will be shipped with PSS 10.1). In other words, all the PSS products will not be affected by the vulnerability CVE-2017-9791.
The patch to remove Struts libs in PWS 9.1.3 has been released at patches/pws913/build149044 in SAS FTP Site.
Vulnerability Details
|
Affected Products and Versions
PWS 9.1 and 9.1.3
Remediation/Fixes
The patch to remove Struts libs in PWS 9.1.3 has been released at patches/pws913/build149044 in SAS FTP Site.
Workarounds and Mitigations
PWS will not use the libs so there is no risk that the vulnerability will be exploited.
Get Notified about Future Security Bulletins
References
*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.
Disclaimer
Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.
Was this topic helpful?
Document Information
Modified date:
17 June 2018
UID
isg3T1025578