Is Control Compliance Suite vulnerable to new Apache Struts2 vulnerability?
search cancel

Is Control Compliance Suite vulnerable to new Apache Struts2 vulnerability?

book

Article ID: 164844

calendar_today

Updated On:

Products

Control Compliance Suite Windows

Issue/Introduction

Talos has reported a new Apache vulnerability that is being actively exploited in the wild. The vulnerability () is a remote code execution bug that affects the Jakarta Multipart parser in Apache Struts. - CVE-2017-5638 

Content-Type: Malicious - New Apache Struts2 0-day Under Attack http://blog.talosintelligence.com/2017/03/apache-0-day-exploited.html

Resolution

Apache Struts2 is an open-source web application framework for developing Java EE web applications whereas CCS web application is hosted by Internet Information Services (IIS). As a result CCS product is NOT vulnerable to the vulnerability mentioned in the blog:

http://blog.talosintelligence.com/2017/03/apache-0-day-exploited.html or any other Apache Struts2