What are the impacts of the CVE-2023-50164 Apache Struts on Siteminder products (1)(2)?
Release: Applicable for all supported versions.
Component: SiteMinder AdminUI.
SiteMinder product suite is "NOT" impacted by the vulnerability " CVE-2023-50164 ".
The struts.jar is not being used in any of the SiteMinder components.
The "struts2-core-2.5.17.jar" or any version of "struts2-core-xxx.jar" can be that way removed from the Admin UI location.
Note also that there's no need to upgrade the AdminUI to the latest non-vulnerable release. Just "remove" the mentioned jar from the AdminUI location.
There will be NO limitations in the AdminUI console even after removing this struts2-core-xxx.jar from the Admin UI location.
Removal of any version of struts2-core-xxx.jar file from the Admin UI location does not have any functional impact on AdminUI.
As always, it is recommended to take the backup of the "struts2-core-2.5.17.jar" (struts2-core-xxx.jar) file before removing it. Test this in a lower TEST environment first and test all the possible use cases, before making the same changes in the higher environments.