cancel
Showing results forĀ 
Search instead forĀ 
Did you mean:Ā 
cancel
749
Views
20
Helpful
3
Replies

CSCvm14030 - Evaluation of positron for Struts remote code execution vulnerability August 2018 - 1

toyip
Cisco Employee
Cisco Employee

Just want to confirm if the newly released patch 3 for ISE 2.4 addresses the Apache Struts vulnerability as per release notes and applying the Struts2-fix-2.0to2.4 fix is not necessary if patch 3 (for ISE 2.4) is installed.

3 Replies 3

Leo Laohoo
Hall of Fame
Hall of Fame

The fix for this is called "Struts2-fix-2.0to2.4".

I was made aware ISE 2.4P3 doesn't fix the vulnerability & hotfix is required.

I just confirmed internally that ISE2.4, P3 does address the vulnerability. The release notes for ISE2.4 also confirms it.

Ok, thanks for the confirmation.