VMware Response to CVE-2017-5638: Apache Struts 2 Remote Code Execution
search cancel

VMware Response to CVE-2017-5638: Apache Struts 2 Remote Code Execution

book

Article ID: 342801

calendar_today

Updated On:

Products

VMware VMware Aria Suite VMware vCenter Server

Issue/Introduction

On March 8th, 2017, a critical vulnerability in Apache Struts 2 identified by CVE-2017-5638 was disclosed that may allow for remote code execution.

VMware has classified this issue as critical and as such began work on a fix or corrective action immediately following the disclosure.

The VMware Security Engineering, Communications, and Response group (vSECR) has completed our investigations of the impact this vulnerability may have on VMware products.

Resolution

Please see VMSA-2017-0004 for details on the vulnerability, affected products, workarounds, and fixes. Products not mentioned in this advisory are not affected by the vulnerability.