cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
417
Views
0
Helpful
1
Replies

Struts2 CVE-2017-5638

Ping Zhou
Level 8
Level 8

Hi,

I'm going to patch 8 in several months. Does 2.2.0.470 with Patch 8 deployment still need Struts2 CVE-2017-5638 fix, aka "ise-applystrutsfix-signed.x86_64.tar.gz"?

Thanks.

1 Accepted Solution

Accepted Solutions

hslai
Cisco Employee
Cisco Employee

No, not needed. The CVE is associated with CSCvd49829 and the fix has been integrated into 2.2 Patch 1.

View solution in original post

1 Reply 1

hslai
Cisco Employee
Cisco Employee

No, not needed. The CVE is associated with CSCvd49829 and the fix has been integrated into 2.2 Patch 1.