Pharos software is not susceptible to the new Apache Struts vulnerability nor to the Jackson-databind vulnerability - June 2020
  • 05 Apr 2024
  • 1 Minute to read
  • Dark
    Light
  • PDF

Pharos software is not susceptible to the new Apache Struts vulnerability nor to the Jackson-databind vulnerability - June 2020

  • Dark
    Light
  • PDF

Article summary

Background  

Recently, a security vulnerability was discovered inside Apache Struts:

            CVE-2018-1327

            https://nvd.nist.gov/vuln/detail/CVE-2018-1327

 This vulnerability is reasonably serious because it allows a DoS attack when using a malicious request.

 A security vulnerability was also discovered inside Jackson-databind:

        CVE-2018-7489

        https://nvd.nist.gov/vuln/detail/CVE-2018-7489

This vulnerability is serious because it allows unauthenticated remote code execution and is easy to exploit.

Many organizations, including Pharos customers, are urgently investigating where these tools are used and to update/repair those instances.

Pharos Software, Apache Struts and Jackson-databind  

Pharos has reviewed all our software and 3 rdparty tools/libraries that we use and can confirm that  we do not use Apache Struts nor Jackson-databind in any product. This includes:

  • Uniprint (including all web interfaces)

  • Blueprint (including all web interfaces)

  • Mobileprint

  • All Omega devices (including PS60, PS150, PS200)

  • All iMFP implementations across all manufacturers

  • Beacon – both the desktop components and the cloud infrastructure

  • Kiosks

Pharos products are therefore not vulnerable to either the Apache Struts exploit nor the Jackson-databind exploit.

Regards,
Pharos Security Team
Pharos Systems International
585-939-7000
pharossecurityteam@pharos.com


Was this article helpful?


Changing your password will log you out immediately. Use the new password to log back in.
First name must have atleast 2 characters. Numbers and special characters are not allowed.
Last name must have atleast 1 characters. Numbers and special characters are not allowed.
Enter a valid email
Enter a valid password
Your profile has been successfully updated.