Apache Struts 1.x < 1.2.9 Denial of Service (CVE-2006-1547) vulnerability with arcotuds.
search cancel

Apache Struts 1.x < 1.2.9 Denial of Service (CVE-2006-1547) vulnerability with arcotuds.

book

Article ID: 406613

calendar_today

Updated On:

Products

CA Strong Authentication

Issue/Introduction

This vulnerability is reported for the Arcotuds and Admin component of Strong Auth product. 

Apache Struts 1.x < 1.2.9 Denial of Service (CVE-2006-1547)

  Path                   : /apps/arcotuds/webroot/WEB-INF/lib/struts-1.2.8.jar
  Installed version : 1.2.8
  Fixed version     : 1.2.9

Environment

Component and Environment: CA Strong Authentication 9.1.x

Resolution

An investigation has confirmed that this vulnerability does not impact the current system. While an older Apache Struts JAR file was detected within the arcotuds.war file, the library is entirely obsolete in this deployment and is safe to remove.

Technical Findings & Validation

  • Version Upgrade: The Apache Struts framework was previously upgraded to version 2.5.14.1, mitigating older known risks.

    Reference: View the official Third-Party Software Acknowledgments.

  • Architecture De-coupling: Current versions of the Admin Console and UDS Components of Advanced Authentication no longer rely on the Apache Struts framework.

  • Dependency Replacement: The legacy Struts dependency has been entirely replaced by Tiles 3.x.

    Reference: Review the specific updates in the New Features and Enhancements (SP1 Release Notes).