04-11-2017 04:42 PM - edited 03-17-2019 10:04 AM
Does anyone have a update on when the Call Manager 11.0 and 11.5 apache struts2 patch will be out?
Call Manager bug is CSCvd49840
Unity Connection bug is CSCvd49841
The notice has March 31st for call manager but I am not finding 11.5.1.13900 version on CCO or any
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170310-struts2
Thanks, Erick
04-11-2017 06:01 PM
Right now you'd need to reach out to TAC so they can publish the ES with the fix, otherwise, you'd need to wait until they post the SU with the fix, or a standalone COP with the fix, not sure which option the BU will use.
06-06-2017 09:25 AM
Is there any updates on this issue? The latest cop file I can find for Unity/CUCM is 11.5.1.12900-21. I have found separate patches fix this vulnerability:
Unity : COP file to address CSCvd49841 in Unity Connection 11.5(1).
ciscocm.11_5_struts_2_3_32_upgrade.cop.sgn
CUCM: Rev 2 of COP file to address CSCvd49840 in CUCM 11.5(1).
ciscocm.11_5_struts_2_3_32_upgrade_v2.cop.sgn
What is the best upgrade path for a 10.5.2 system:
Upgrade 10.5.2 to 11.5.1.12900
Then upgrade ciscocm.11_5_struts_2_3_32_upgrade?
Thanks,
10-06-2017 03:04 AM
Hi
Does the 12.0.1 release include this vunerability fix?
Thanks
Chris
10-06-2017 07:05 AM
Hi Chris,
Yes, this bug/vulnerability is fixed with the release of CUCM 12.0.1 ( Cisco Unified Communications Manager 12.0(1), also known as 12.0.1.10000-10)
Cheers!
Rob
10-06-2017 07:35 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide