Addressing CVE-2018-11776 for the API Management Product Suite
search cancel

Addressing CVE-2018-11776 for the API Management Product Suite

book

Article ID: 112118

calendar_today

Updated On:

Products

CA API Management SaaS CA API Gateway

Issue/Introduction

  • From the Red Hat CVE Database entry on CVE-2018-11776:
"Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when using results with no namespace and in same time, its upper action(s) have no or wildcard namespace. Same possibility when using url tag which doesn't have value and action set and in same time, its upper action(s) have no or wildcard namespace."
  • Are any of the CA API Management products vulnerable to CVE-2018-11776, including the CA API Gateway, Mobile API Gateway, API Developer Portal, Live API Creator, and others?

Environment

All supported versions of the API Management Product Suite

Resolution

  • The simple answer is "No".
  • Below is a listing of each API Management product for reference that have been confirmed as not vulnerable to CVE-2018-11776:
    • CA API Gateway
    • CA Mobile API Gateway
    • CA API Developer Portal ("Classic Portal"; version 3.5 & lower)
    • On-premise CA API Developer Portal Enhanced Experience ("Portal"; version 4.0 & higher)
    • Live API Creator

Additional Information

  • Red Hat CVE database: https://access.redhat.com/security/cve/cve-2018-11776