Apache Struts 2 Freemarker Remote Code Execution Vulnerability (CVE-2017-12611) in RSA Products
Advisory Type
Security
Advisory Content
Article Number
000035536
CVE ID
000035536
Applies To
RSA Product Set: All RSA Products
Article Summary
On September 7, 2017, Apache disclosed a vulnerability in Apache Struts2 that could allow an attacker to execute arbitrary commands remotely on affected systems by sending a specially crafted web request to the vulnerable application.
The details for this vulnerability can be found at https://struts.apache.org/docs/s2-053.html.
The details for this vulnerability can be found at https://struts.apache.org/docs/s2-053.html.
Resolution
RSA is aware of and investigating this issue to identify potential product impact. The level of impact may vary depending on the affected product. The following table contains the latest available impact information. This table will be updated as additional information becomes available.
Notes
For status of Dell products, see:
http://www.dell.com/support/article/us/en/19/sln307406/apache-struts-2-remote-code-execution-vulnerability--cve-2017-12611-?lang=en
For status of Dell EMC products, see: https://support.emc.com/kb/504013
For status of Dell EMC CPSD products, see: http://support.vce.com/kA2A0000000LKm0
For status of Dell EMC products, see: https://support.emc.com/kb/504013
For status of Dell EMC CPSD products, see: http://support.vce.com/kA2A0000000LKm0