Apache Struts 2 Remote Code Execution Vulnerability (CVE-2018-11776): Impact on RSA products
Originally Published: 2018-08-24
Article Number
CVE Identifier(s)
Article Summary
Link to Advisories
Resolution
| RSA Product Name | Versions | Impact Status | Details | Last Updated |
|---|---|---|---|---|
| RSA 3D Secure/Adaptive Authentication eCommerce | All Supported | Not Impacted | Product does not use Apache Struts. | 2018-08-24 |
| RSA Access Manager | 6.2, 6.2.1, 6.2.2, 6.2.3, 6.2.4 | Not Impacted | Product uses Apache Struts but not impacted by this issue. | 2018-08-30 |
| RSA Adaptive Authentication Cloud | All Supported | Not Impacted | 2018-08-24 | |
| RSA Adaptive Authentication Hosted | All Supported | Not Impacted | Product does not use Apache Struts. | 2018-08-28 |
| RSA Adaptive Authentication On-Prem | 7.x | Not Impacted | Product does not use impacted version of Apache Struts. | 2018-08-28 |
| RSA Archer Hosted | N/A | Not Impacted | 2018-08-24 | |
| RSA Archer Platform | All Supported | Not Impacted | Product does not use Apache Struts. | 2018-08-24 |
| RSA Archer Security Operations Management (SecOps) | All Supported | Not Impacted | Product does not use Apache Struts. | 2018-08-24 |
| RSA Archer Vulnerability & Risk Manager (VRM) | All Supported | Not Impacted | Product does not use Apache Struts. | 2018-08-24 |
| RSA Authentication Client (RAC) | All Supported | Investigating | 2018-08-24 | |
| RSA Authentication Manager | All Supported | Not Impacted | 2018-08-24 | |
| RSA Authentication Manager Web Tier | All Supported | Not Impacted | 2018-08-27 | |
| RSA BSAFE C Products: MES, Crypto-C ME, SSL-C | All Supported | Not Impacted | Product does not use Apache Struts. | 2018-08-24 |
| RSA BSAFE Java Products: Cert-J, Crypto-J, SSL-J | All Supported | Not Impacted | Product does not use Apache Struts. | 2018-08-24 |
| RSA Central | All Supported | Not Impacted | Product does not use Apache Struts. | 2018-10-25 |
| RSA Data Loss Prevention | All Supported | Not Impacted | Product does not use Apache Struts. | 2018-08-24 |
| RSA Data Protection Manager | All Supported | Not Impacted | 2018-08-31 | |
| RSA DCS: RSA Certificate Manager | All Supported | Not Impacted | Product does not use Apache Struts. | 2018-08-24 |
| RSA DCS: RSA Validation Manager | All Supported | Not Impacted | Product does not use impacted version of Apache Struts. | 2018-08-27 |
| RSA eFraudNetwork (eFN) | All Supported | Not Impacted | 2018-08-24 | |
| RSA Federated Identity Manager | All Supported | Not Impacted | Product does not use impacted version of Apache Struts. | 2018-08-27 |
| RSA FraudAction (OTMS) | All Supported | Not Impacted | 2018-08-24 | |
| RSA Identity Governance and Lifecycle Software (RSA Via Lifecycle and Governance Software, RSA Identity Management & Governance Software) | All Supported | Not Impacted | Product does not use Apache Struts. | 2018-08-24 |
| RSA Identity Governance and Lifecycle Appliance (RSA Via Lifecycle and Governance Appliance, RSA Identity Management & Governance Appliance) | All Supported | Not Impacted | Product does not use Apache Struts. | 2018-08-24 |
| RSA Identity Governance and Lifecycle SaaS / MyAccessLive (RSA Via Lifecycle and Governance SaaS / MyAccessLive) | All Supported | Not Impacted | Product does not use Apache Struts. | 2018-08-24 |
| RSA Identity Governance and Lifecycle Virtual Application | All Supported | Not Impacted | Product does not use Apache Struts. | 2018-08-29 |
| RSA NetWitness Endpoint (ECAT) | All Supported | Not Impacted | Product does not use Apache Struts. | 2018-08-24 |
| RSA NetWitness Logs & Packets / Security Analytics (Hardware and Virtual Appliances) | All Supported | Not Impacted | Product does not use Apache Struts. | 2018-08-24 |
| RSA NetWitness Live Infrastructure | All Supported | Not Impacted | Product does not use Apache Struts. | 2018-08-24 |
| RSA SecurID Access Cloud Service | All Supported | Not Impacted | 2018-08-24 | |
| RSA SecurID Access IDR VM | All Supported | Not Impacted | 2018-08-24 | |
| RSA SecurID Agent for PAM | All Supported | Not Impacted | 2018-08-24 | |
| RSA SecurID Agent for Web | All Supported | Not Impacted | 2018-08-24 | |
| RSA SecurID Agent for Windows | All Supported | Not Impacted | 2018-08-24 | |
| RSA SecurID Authenticate App for Android | All Supported | Investigating | 2018-08-24 | |
| RSA SecurID Authenticate App for iOS | All Supported | Investigating | 2018-08-24 | |
| RSA SecurID Authenticate App for Windows 10 | All Supported | Investigating | 2018-08-24 | |
| RSA SecurID Authentication Engine | All Supported | Not Impacted | 2018-08-24 | |
| RSA SecurID Authentication SDK | All Supported | Not Impacted | 2018-08-24 | |
| RSA SecurID Software Token Converter | All Supported | Not Impacted | 2018-08-24 | |
| RSA SecurID Software Token for Android | All Supported | Not Impacted | 2018-08-24 | |
| RSA SecurID Software Token for Blackberry | All Supported | Not Impacted | 2018-08-24 | |
| RSA SecurID Software Token for Desktop | All Supported | Not Impacted | 2018-08-24 | |
| RSA SecurID Software Token for iPhone | All Supported | Not Impacted | 2018-08-24 | |
| RSA SecurID Software Token for Windows Mobile | All Supported | Not Impacted | 2018-08-24 | |
| RSA SecurID Software Token Toolbar | All Supported | Not Impacted | 2018-08-24 | |
| RSA SecurID Software Token Web SDK | All Supported | Not Impacted | 2018-08-24 | |
| RSA SecurID Transaction Signing SDK | All Supported | Not Impacted | 2018-08-24 | |
| RSA SYN | Current Hosted Environment | Not Impacted | Product does not use Apache Struts. | 2018-11-01 |
| RSA Web Threat Detection | All Supported | Not Impacted | Product does not use Apache Struts | 2018-08-24 |
Disclaimer
Related Articles
Infineon Trusted Platform Module (TPM) Vulnerability (CVE-2017-15361) Impact on RSA Products 56Number of Views Microprocessor Side-Channel Vulnerabilities (CVE-2018-3639 and CVE-2018-3640): Impact on RSA products 95Number of Views CERT/CC Vulnerability Note VU#144389: Potential Impact on RSA Products 198Number of Views Speculative Execution Side-Channel Vulnerabilities (CVE-2018-3615, CVE-2018-3620, and CVE-2018-3646): Impact on RSA products 97Number of Views Microprocessor Side-Channel Attacks (CVE-2017-5715, CVE-2017-5753, CVE-2017-5754): Impact on RSA products 704Number of Views
Trending Articles
Downloading RSA Authentication Manager license files or RSA Software token seed records RSA Release Notes for RSA Authentication Manager 8.8 RSA Authentication Manager 8.9 Release Notes (January 2026) Download RSA SecurID Access Cloud User Event audit logs using Cloud Administration REST API CLU RSA SecurID Software Token 5.0.2 for Windows Desktop displays message after reboot due to roaming profile: No token stor…
Don't see what you're looking for?