cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
613
Views
0
Helpful
2
Replies

ISE 2.2 patch 12 - Apache Struts Vulnerability

chbudima
Cisco Employee
Cisco Employee

Hi Team,

 

We have ISE 2.2 patch 9 with Apache Struts Hotpatch "ise-apply-CSCvm14030_2.2.0.470_common_1-SPA.tar.gz" installed. The Apache Struts hotpatch was installed from CCO download page to fix Apache Struts vulnerability CVE-2018-11776 back in August 2018.

 

We need to install ISE 2.2 patch 12 to fix the latest Apache Struts vulnerability CVE-2016-1000031 which announced on Nov 2018.

 

My query is how to install ISE 2.2 patch 12 in this situation:

Do we need to rollback Apache Struts Hotpatch "ise-apply-CSCvm14030_2.2.0.470_common_1-SPA.tar.gz" first before installing 2.2 patch 12?

Or do we directly install 2.2 patch 12 without uninstall Apache Struts Hotpatch first on top ofISE 2.2 patch 9 with Apache Struts Hotpatch "ise-apply-CSCvm14030_2.2.0.470_common_1-SPA.tar.gz" ?

 

Could you please advise ?

 

Thanks for your help.

 

Regards,

Charles

1 Accepted Solution

Accepted Solutions

Jason Kunst
Cisco Employee
Cisco Employee

Per the TAC and development team, rollback is recommended. There will be no further guidance on this for now

 

View solution in original post

2 Replies 2

Jason Kunst
Cisco Employee
Cisco Employee

Per the TAC and development team, rollback is recommended. There will be no further guidance on this for now

 

Thanks Jason for your recommendation.

 

Regards,

Charles