Struts Vulnerability - CVE-2019-0233 and its impact on Identity Manager
search cancel

Struts Vulnerability - CVE-2019-0233 and its impact on Identity Manager

book

Article ID: 235819

calendar_today

Updated On:

Products

CA Identity Manager CA Identity Suite

Issue/Introduction

Struts Vulnerability - CVE-2019-0233 and its impact on Identity Manager

Resolution

IM doesn't use Struts based Action class to carry out file upload process. Rather, it uses custom file upload implementation leveraging Apache Commons library with required validation controls in place. So, it's not possible for an attacker to override access permissions to cause a Denial of Service via a file upload and hence, IM is not exploitable for this vulnerability.