IBM Support

Control Center is not vulnerable to CVE-2017-5638

Question & Answer


Question

Is Control Center vulnerable to the Apache Struts 2 vulnerability CVE-2017-5638

Answer

Control Center in all editions and all platforms is NOT vulnerable to the Apache Struts 2 vulnerability (CVE-2017-5638).

NOTE: You should check your applications to determine if they are using the vulnerable Apache Struts APIs and update your Apache Struts 2 accordingly. Refer to https://cwiki.apache.org/confluence/display/WW/S2-045

[{"Product":{"code":"SS9GLA","label":"IBM Control Center"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Component":"Not Applicable","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF010","label":"HP-UX"},{"code":"PF016","label":"Linux"},{"code":"PF027","label":"Solaris"},{"code":"PF033","label":"Windows"}],"Version":"6.1.0.1;6.1;6.0.0.1;6.0;5.4.2.1;5.4.2;5.4.1;5.4.0.2;5.4.0.1;5.4","Edition":"","Line of Business":{"code":"LOB59","label":"Sustainability Software"}}]

Document Information

Modified date:
17 December 2019

UID

swg22001230