IBM Support

Security Bulletin: Apache Struts Vulnerability CVE-2017-9791 will not affect PSS products

Created by Igets Administrator on
Published URL:
https://www.ibm.com/support/pages/node/631727
631727

Security Bulletin


Summary

The Struts 1 plugin in Apache Struts 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.

Among all the PSS products (LSF, PPM, RTM, PWS), only PWS 9.1 and 9.1.3 have Struts libs in the package. However, PWS will not use the libs even though they are there, so there is no risk that the vulnerability will be exploited. The struts/structs2 libs have been removed from the package for PWS 9.1.3.2 (which will be shipped with PSS 10.1). In other words, all the PSS products will not be affected by the vulnerability CVE-2017-9791.

The patch to remove Struts libs in PWS 9.1.3 has been released at patches/pws913/build149044 in SAS FTP Site.

Vulnerability Details

CVE Reference:   CVE-2017-9791

Date:  Jul 7 2017 
Version(s): 2.3.x
Description:   A vulnerability was reported in Apache Struts. A remote user can execute arbitrary code on the target system.

A remote user can send a specially crafted parameter value to execute arbitrary code on the target system. The code will run with the privileges of the target service.

The 'Struts 1 plugin' in Struts 2 is affected when using a Struts 1 action.

icez from Tophant Competence Center reported this vulnerability.
Impact:   A remote user can execute arbitrary code on the target system.
Solution:   The vendor has provided mitigation instructions in their advisory.

The vendor advisory is available at:http://struts.apache.org/docs/s2-048.html
Vendor URL:  struts.apache.org/docs/s2-048.html
Cause:   Input validation error
Underlying OS:  Linux (Any)UNIX (Any)Windows (Any)

Affected Products and Versions

PWS 9.1 and 9.1.3

Remediation/Fixes

The patch to remove Struts libs in PWS 9.1.3 has been released at patches/pws913/build149044 in SAS FTP Site.

Workarounds and Mitigations

PWS will not use the libs so there is no risk that the vulnerability will be exploited.

Get Notified about Future Security Bulletins

References

Off

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

[{"Product":{"code":"SSVMSD","label":"Platform RTM"},"Business Unit":{"code":"BU054","label":"Systems w\/TPS"},"Component":"Not Applicable","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"Version Independent","Edition":"","Line of Business":{"code":"","label":""}}]

Document Information

Modified date:
17 June 2018

UID

isg3T1025578