search cancel

Addressing CVE-2018-11776 for Identity Management and Governance

book

Article ID: 112291

calendar_today

Updated On:

Products

CA Identity Manager CA Identity Governance CA Identity Portal CA Risk Analytics CA Secure Cloud SaaS - Arcot A-OK (WebFort) CLOUDMINDER ADVANCED AUTHENTICATION CA Secure Cloud SaaS - Advanced Authentication CA Secure Cloud SaaS - Identity Management CA Secure Cloud SaaS - Single Sign On

Issue/Introduction

  • From the Red Hat CVE Database entry on CVE-2018-11776:
"Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when using results with no namespace and in same time, its upper action(s) have no or wildcard namespace. Same possibility when using url tag which doesn't have value and action set and in same time, its upper action(s) have no or wildcard namespace."

  • Are any of the CA Identity Management and Governance products vulnerable to CVE-2018-11776, including the Identity Manager, Portal, Governance, Provisioning Manager, and Virtual Appliance?

Environment

Release: CAIDMB99000-14.1-Identity Manager-B to B
Component:

Resolution

  • The simple answer is "No".
  • Below is a listing of each Identity Management product for reference that have been confirmed as not vulnerable to CVE-2018-11776:
    • Identity Manager
    • Identity Portal
    • Identity Governance
    • Virtual Appliance
    • Provisioning Server