---
title: "Pharos software is not susceptible to the new Apache Struts vulnerability nor to the Jackson-databind vulnerability - June 2020"
slug: "pharos-software-is-not-susceptible-to-the-new-apache-struts-vulnerability-nor-to-the-jackson-databind-vulnerability"
updated: 2024-04-05T07:32:53Z
published: 2024-04-05T07:32:53Z
canonical: "kb.pharos.com/pharos-software-is-not-susceptible-to-the-new-apache-struts-vulnerability-nor-to-the-jackson-databind-vulnerability"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://kb.pharos.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Pharos software is not susceptible to the new Apache Struts vulnerability nor to the Jackson-databind vulnerability - June 2020

#### **Background**

Recently, a security vulnerability was discovered inside Apache Struts:

CVE-2018-1327

[](https://nvd.nist.gov/vuln/detail/CVE-2018-1327) [https://nvd.nist.gov/vuln/detail/CVE-2018-1327](https://nvd.nist.gov/vuln/detail/CVE-2018-1327)

This vulnerability is reasonably serious because it allows a DoS attack when using a malicious request.

A security vulnerability was also discovered inside Jackson-databind:

CVE-2018-7489

[https://nvd.nist.gov/vuln/detail/CVE-2018-7489](https://nvd.nist.gov/vuln/detail/CVE-2018-7489)

This vulnerability is serious because it allows unauthenticated remote code execution and is easy to exploit.

Many organizations, including Pharos customers, are urgently investigating where these tools are used and to update/repair those instances.

**Pharos Software, Apache Struts and Jackson-databind**

Pharos has reviewed all our software and 3 rdparty tools/libraries that we use and can confirm that **we do not** use Apache Struts nor Jackson-databind in any product. This includes:

- Uniprint (including all web interfaces)
- Blueprint (including all web interfaces)
- Mobileprint
- All Omega devices (including PS60, PS150, PS200)
- All iMFP implementations across all manufacturers
- Beacon – both the desktop components and the cloud infrastructure
- Kiosks

Pharos products are therefore not vulnerable to either the Apache Struts exploit nor the Jackson-databind exploit.

Regards, Pharos Security Team Pharos Systems International 585-939-7000 [pharossecurityteam@pharos.com](mailto:pharossecurityteam@pharos.com)

## Related

- [Blueprint 5.3 Update 1 New Features](/blueprint-53-update-1-new-features.md)
- [On a Omega PS200 How do I change the CA Certificate it uses?](/on-a-omega-ps200-how-do-i-change-the-ca-certificate-it-uses.md)
- [Blueprint: Migrating the Analyst to a New Server with Same Name](/blueprint-migrating-the-analyst-to-a-new-server-with-same-name.md)
