
{"id":1445,"date":"2017-09-13T00:26:46","date_gmt":"2017-09-13T00:26:46","guid":{"rendered":"http:\/\/tech-no.104.210.61.21.xip.io\/?p=1445"},"modified":"2017-09-13T00:26:46","modified_gmt":"2017-09-13T00:26:46","slug":"apache-struts2-vendor-bulletins","status":"publish","type":"post","link":"https:\/\/tech-no.org\/?p=1445","title":{"rendered":"Apache Struts2 Vendor bulletins"},"content":{"rendered":"<p>Every time there is a critical vulnerability that is discovered, I often get the question &#8220;how am I impacted?&#8221;<\/p>\n<p>The challenge is this, even if you have a vulnerability management toolset (Nessus, Qualys etc) you may not see the entire picture of what is impacted. There could be many reasons for this such as permissions to posture, here are a couple other reasons:<\/p>\n<ol>\n<li>You may not be able to do a credentialed scan on some Network Appliances.<\/li>\n<li>Firewalls may be blocking your scanner.<\/li>\n<li>Configuration of your scanner is lacking certain networks.<\/li>\n<\/ol>\n<p>For the Apache Struts 2 vulnerability, I had a hard time coming up with a list of vendor bulletins\u00a0for a few customers and thought I should share:<\/p>\n<p>&nbsp;<\/p>\n<p>Cisco: <a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170310-struts2\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170310-struts2<\/a><\/p>\n<p>VMWARE: <a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2017-0004.html\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2017-0004.html<\/a><\/p>\n<p>BMC: <a href=\"https:\/\/communities.bmc.com\/blogs\/application-security-news\/2017\/03\/14\/apache-struts-2-vulnerability-cve-2017-5638\">https:\/\/communities.bmc.com\/blogs\/application-security-news\/2017\/03\/14\/apache-struts-2-vulnerability-cve-2017-5638<\/a><\/p>\n<p>Enterasys: <a href=\"https:\/\/gtacknowledge.extremenetworks.com\/articles\/Vulnerability_Notice\/VN-2017\/?q=apache&amp;l=en_US&amp;fs=Search&amp;pn=1\">https:\/\/gtacknowledge.extremenetworks.com\/articles\/Vulnerability_Notice\/VN-2017\/?q=apache&amp;l=en_US&amp;fs=Search&amp;pn=1<\/a><\/p>\n<p>HPE: <a href=\"http:\/\/h22208.www2.hpe.com\/eginfolib\/securityalerts\/Struts\/Struts-CVE-2017-5638%20.html\">http:\/\/h22208.www2.hpe.com\/eginfolib\/securityalerts\/Struts\/Struts-CVE-2017-5638%20.html<\/a><\/p>\n<p>DELL\/EMC Storage: <a href=\"https:\/\/emcservice.force.com\/CustomersPartners\/kA6j0000000L3j0CAC\">https:\/\/emcservice.force.com\/CustomersPartners\/kA6j0000000L3j0CAC<\/a><\/p>\n<p>Manageengine \/ Zoho (ServiceDeskPlus, Password Manager Pro etc): <span style=\"font-family: Calibri;\">Not vulnerable uses old Apache struts version 1.3.310. (Determined by calling support)<\/span><\/p>\n<p>Quest IdentityONE: Not affected (determined by calling support)<\/p>\n<p>&nbsp;<\/p>\n<p>hopefully this saves someone time.<\/p>\n<p>&nbsp;<\/p>\n<p>Michael<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Every time there is a critical vulnerability that is discovered, I often get the question &#8220;how am I impacted?&#8221; The challenge is this, even if you have a vulnerability management toolset (Nessus, Qualys etc) you may not see the entire picture of what is impacted. There could be many reasons for this such as permissions &hellip;<\/p>\n","protected":false},"author":7,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[5],"tags":[83,84,82],"_links":{"self":[{"href":"https:\/\/tech-no.org\/index.php?rest_route=\/wp\/v2\/posts\/1445"}],"collection":[{"href":"https:\/\/tech-no.org\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/tech-no.org\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/tech-no.org\/index.php?rest_route=\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/tech-no.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1445"}],"version-history":[{"count":2,"href":"https:\/\/tech-no.org\/index.php?rest_route=\/wp\/v2\/posts\/1445\/revisions"}],"predecessor-version":[{"id":1447,"href":"https:\/\/tech-no.org\/index.php?rest_route=\/wp\/v2\/posts\/1445\/revisions\/1447"}],"wp:attachment":[{"href":"https:\/\/tech-no.org\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1445"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/tech-no.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1445"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/tech-no.org\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1445"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}