Interstage Application Server, Interstage Apworks, Interstage Interaction Manager, Interstage Studio: Apache Struts1 vulnerability that allows unintended remote operations against components on memory (CVE-2016-1181). June 7th, 2016


Notes on using this web page

1. Description

Struts1 ActionForm contains a vulnerability which allows unintended remote operations on server modules.

Not all computers are exposed to the threat of the vulnerability even if the corresponding product is installed.
There is a possibility of this vulnerability affecting the computer in which the product is installed if Struts1 is enabled and used in a Web application.

This vulnerability exists when following 2 conditions are met.

  • The web application can receive multipart requests. and,
  • The following ActionForm or its subclasses are used in session scope:
    • ActionForm
    • ValidatorForm
    • ValidatorActionForm

For the Patches, please contact a Fujitsu system engineer or your partner(s).

2. Impact

This vulnerability allows a malicious user to perform a DoS attack against the Web application and/or gain access to server modules of the Web application.

3. Affected systems and corresponding action

3-1. Affected systems:

GP7000F, PRIMEPOWER, PRIMERGY, GP5000, CELSIUS, AT compatible machine, PRIMEQUEST, SPARC Enterprise, Fujitsu M10

3-2. Affected products and required patch

Interstage Application Server
ProductsVersionTarget OSPackage namePatch ID.
Interstage Application Server Enterprise EditionV7.0L10RHEL-AS4(IPF)FJSVapcstPending*
Interstage Application Server Enterprise EditionV8.0.0RHEL-AS4(IPF)FJSVapcstPending*
Interstage Application Server Enterprise EditionV8.0.1RHEL-AS4(IPF)FJSVapcstPending*
Interstage Application Server Enterprise EditionV8.0.2RHEL-AS4(IPF)FJSVapcstPending*
Interstage Application Server Enterprise EditionV9.0.0RHEL-AS4(IPF)/ RHEL5(IPF)FJSVapcstPending*
Interstage Application Server Enterprise EditionV9.0.0ARHEL-AS4(IPF)/ RHEL5(IPF)FJSVapcstPending*
Interstage Application Server Enterprise EditionV9.1.0RHEL-AS4(IPF)/ RHEL5(IPF)FJSVapcstT010235QP-02
Interstage Application Server Enterprise EditionV9.2.0RHEL-AS4(IPF)/ RHEL5(IPF)FJSVapcstT010235QP-02
Interstage Application Server Standard-J EditionV9.0.0RHEL-AS4(IPF)/ RHEL5(IPF)FJSVapcstPending*
Interstage Application Server Standard-J EditionV9.1.0RHEL-AS4(IPF)/ RHEL5(IPF)FJSVapcstT010235QP-02
Interstage Application Server Standard-J EditionV9.2.0RHEL-AS4(IPF)/ RHEL5(IPF)FJSVapcstT010235QP-02
Interstage Application Server Enterprise EditionV9.2.0RHEL5(Intel64)FJSVapcstT010232LP-02
Interstage Application Server Enterprise EditionV9.3.1RHEL5(Intel64)/ RHEL6(Intel64)FJSVapcstT010232LP-02
Interstage Application Server Enterprise EditionV10.0.0RHEL5(Intel64)/ RHEL6(Intel64)FJSVapcstT010232LP-02
Interstage Application Server Enterprise EditionV11.0.0RHEL5(Intel64)/ RHEL6(Intel64)FJSVapcstT010232LP-02
Interstage Application Server Standard-J EditionV9.2.0RHEL5(Intel64)FJSVapcstT010232LP-02
Interstage Application Server Standard-J EditionV9.3.1RHEL5(Intel64)/ RHEL6(Intel64)FJSVapcstT010232LP-02
Interstage Application Server Standard-J EditionV10.0.0RHEL5(Intel64)/ RHEL6(Intel64)FJSVapcstT010232LP-02
Interstage Application Server Standard-J EditionV11.0.0RHEL5(Intel64)/ RHEL6(Intel64)FJSVapcstT010232LP-02
Interstage Application Server Enterprise EditionV6.0L10RHEL-AS3(x86)/ RHEL-ES3(x86)FJSVapcstPending*
Interstage Application Server Enterprise EditionV7.0L10RHEL-AS3(x86)/ RHEL-ES3(x86)FJSVapcstPending*
Interstage Application Server Enterprise EditionV7.0L11RHEL-AS3(x86)/ RHEL-ES3(x86)/ RHEL-AS4(x86)FJSVapcstPending*
Interstage Application Server Enterprise EditionV8.0.0RHEL-AS4(x86)/ RHEL-AS4(EM64T)FJSVapcstPending*
Interstage Application Server Enterprise EditionV8.0.2RHEL-AS4(x86)/ RHEL-AS4(EM64T)FJSVapcstPending*
Interstage Application Server Enterprise EditionV9.0.0RHEL-AS4(x86)/ RHEL-AS4(EM64T)/ RHEL5(x86)/ RHEL5(Intel64)FJSVapcstPending*
Interstage Application Server Enterprise EditionV9.1.0RHEL-AS4(x86)/ RHEL-AS4(EM64T)/ RHEL5(x86)/ RHEL5(Intel64)FJSVapcstT010232LP-02
Interstage Application Server Enterprise EditionV9.1.0BRHEL-AS4(x86)/ RHEL-AS4(EM64T)/ RHEL5(x86)/ RHEL5(Intel64)FJSVapcstT010232LP-02
Interstage Application Server Enterprise EditionV9.2.0RHEL-AS4(x86)/ RHEL-AS4(EM64T)/ RHEL5(x86)/ RHEL5(Intel64)FJSVapcstT010232LP-02
Interstage Application Server Enterprise EditionV9.3.1RHEL-AS4(x86)/ RHEL-AS4(EM64T)/ RHEL5(x86)/ RHEL5(Intel64)/ RHEL6(x86)/ RHEL6(Intel64)FJSVapcstT010232LP-02
Interstage Application Server Enterprise EditionV10.0.0RHEL5(x86)/ RHEL5(Intel64)/ RHEL6(x86)/ RHEL6(Intel64)FJSVapcstT010232LP-02
Interstage Application Server Enterprise EditionV11.0.0RHEL5(x86)/ RHEL5(Intel64)/ RHEL6(x86)/ RHEL6(Intel64)FJSVapcstT010232LP-02
Interstage Application Server PlusV7.0L10RHEL-AS3(x86)/ RHEL-ES3(x86)FJSVapcstPending*
Interstage Application Server PlusV7.0L11RHEL-AS3(x86)/ RHEL-ES3(x86)/ RHEL-AS4(x86)FJSVapcstPending*
Interstage Application Server Standard-J EditionV8.0.0RHEL-AS4(x86)/ RHEL-AS4(EM64T)FJSVapcstPending*
Interstage Application Server Standard-J EditionV8.0.2RHEL-AS4(x86)/ RHEL-AS4(EM64T)FJSVapcstPending*
Interstage Application Server Standard-J EditionV9.0.0RHEL-AS4(x86)/ RHEL-AS4(EM64T)/ RHEL5(x86)/ RHEL5(Intel64)FJSVapcstPending*
Interstage Application Server Standard-J EditionV9.1.0RHEL-AS4(x86)/ RHEL-AS4(EM64T)/ RHEL5(x86)/ RHEL5(Intel64)FJSVapcstT010232LP-02
Interstage Application Server Standard-J EditionV9.1.0BRHEL-AS4(x86)/ RHEL-AS4(EM64T)/ RHEL5(x86)/ RHEL5(Intel64)FJSVapcstT010232LP-02
Interstage Application Server Standard-J EditionV9.2.0RHEL-AS4(x86)/ RHEL-AS4(EM64T)/ RHEL5(x86)/ RHEL5(Intel64)FJSVapcstT010232LP-02
Interstage Application Server Standard-J EditionV9.3.1RHEL-AS4(x86)/ RHEL-AS4(EM64T)/ RHEL5(x86)/ RHEL5(Intel64)/ RHEL6(x86)/ RHEL6(Intel64)FJSVapcstT010232LP-02
Interstage Application Server Standard-J EditionV10.0.0RHEL5(x86)/ RHEL5(Intel64)/ RHEL6(x86)/ RHEL6(Intel64)FJSVapcstT010232LP-02
Interstage Application Server Standard-J EditionV11.0.0RHEL5(x86)/ RHEL5(Intel64)/ RHEL6(x86)/ RHEL6(Intel64)FJSVapcstT010232LP-02
Interstage Application Server Enterprise EditionV6.0.0Solaris 7/ Solaris 8/ Solaris 9FJSVapcstPending*
Interstage Application Server Enterprise EditionV7.0.0Solaris 8/ Solaris 9FJSVapcstPending*
Interstage Application Server Enterprise EditionV7.0.1Solaris 8/ Solaris 9/ Solaris 10FJSVapcstPending*
Interstage Application Server Enterprise EditionV8.0.0Solaris 9/ Solaris 10FJSVapcstPending*
Interstage Application Server Enterprise EditionV8.0.2Solaris 9/ Solaris 10FJSVapcstPending*
Interstage Application Server Enterprise EditionV9.0.0Solaris 9/ Solaris 10FJSVapcstPending*
Interstage Application Server Enterprise EditionV9.0.0BSolaris 9/ Solaris 10FJSVapcstPending*
Interstage Application Server Enterprise EditionV9.1.0Solaris 9/ Solaris 10FJSVapcstT010234SP-02
Interstage Application Server Enterprise EditionV9.1.0BSolaris 9/ Solaris 10FJSVapcstT010234SP-02
Interstage Application Server Enterprise EditionV9.2.0Solaris 9/ Solaris 10FJSVapcstT010234SP-02
Interstage Application Server Enterprise EditionV10.0.0Solaris 9/ Solaris 10FJSVapcstT010234SP-02
Interstage Application Server Enterprise EditionV11.0.0Solaris 10/ Solaris 11FJSVapcstT010234SP-02
Interstage Application Server PlusV7.0.0Solaris 8/ Solaris 9FJSVapcstPending*
Interstage Application Server PlusV7.0.1Solaris 8/ Solaris 9/ Solaris 10FJSVapcstPending*
Interstage Application Server Standard-J EditionV8.0.0Solaris 9/ Solaris 10FJSVapcstPending*
Interstage Application Server Standard-J EditionV8.0.2Solaris 9/ Solaris 10FJSVapcstPending*
Interstage Application Server Standard-J EditionV9.0.0Solaris 9/ Solaris 10FJSVapcstPending*
Interstage Application Server Standard-J EditionV9.1.0Solaris 9/ Solaris 10FJSVapcstT010234SP-02
Interstage Application Server Standard-J EditionV9.1.0BSolaris 9/ Solaris 10FJSVapcstT010234SP-02
Interstage Application Server Standard-J EditionV9.2.0Solaris 9/ Solaris 10FJSVapcstT010234SP-02
Interstage Application Server Standard-J EditionV10.0.0Solaris 9/ Solaris 10FJSVapcstT010234SP-02
Interstage Application Server Standard-J EditionV11.0.0Solaris 10/ Solaris 11FJSVapcstT010234SP-02
Interstage Application Server Enterprise EditionV8.0.0Windows Server 2003(IPF)FJSVapcstPending*
Interstage Application Server Enterprise EditionV9.0.0Windows Server 2003(IPF)FJSVapcstPending*
Interstage Application Server Enterprise EditionV9.1.0Windows Server 2003(IPF)/ Windows Server 2008(IPF)FJSVapcstPending*
Interstage Application Server Enterprise EditionV9.2.0Windows Server 2003(IPF)/ Windows Server 2008(IPF)FJSVapcstPending*
Interstage Application Server Standard-J EditionV9.0.0Windows Server 2003(IPF)FJSVapcstPending*
Interstage Application Server Standard-J EditionV9.1.0Windows Server 2003(IPF)/ Windows Server 2008(IPF)FJSVapcstPending*
Interstage Application Server Standard-J EditionV9.2.0Windows Server 2003(IPF)/ Windows Server 2008(IPF)FJSVapcstPending*
Interstage Application Server Enterprise EditionV9.2.0Windows(EM64T) Server 2003/ Windows(EM64T) Server 2003 R2/ Windows(EM64T) Server 2008FJSVapcstT010236XP-02
Interstage Application Server Enterprise EditionV10.0.0Windows(EM64T) Server 2003/ Windows(EM64T) Server 2003 R2/ Windows(EM64T) Server 2008/ Windows Server 2008 R2FJSVapcstT010236XP-02
Interstage Application Server Enterprise EditionV11.0.0Windows(EM64T) Server 2003/ Windows(EM64T) Server 2003 R2/ Windows(EM64T) Server 2008/ Windows Server 2008 R2/ Windows Server 2012FJSVapcstT010236XP-02
Interstage Application Server Standard-J EditionV9.2.0Windows(EM64T) Server 2003/ Windows(EM64T) Server 2003 R2/ Windows(EM64T) Server 2008FJSVapcstT010236XP-02
Interstage Application Server Standard-J EditionV10.0.0Windows(EM64T) Server 2003/ Windows(EM64T) Server 2003 R2/ Windows(EM64T) Server 2008/ Windows Server 2008 R2FJSVapcstT010236XP-02
Interstage Application Server Standard-J EditionV11.0.0Windows(EM64T) Server 2003/ Windows(EM64T) Server 2003 R2/ Windows(EM64T) Server 2008/ Windows Server 2008 R2/ Windows Server 2012FJSVapcstT010236XP-02
Interstage Application Server Enterprise EditionV6.0L10Windows NT Server / Windows 2000 Server / Windows Server 2003/ Windows Server 2003 R2FJSVapcstPending*
Interstage Application Server Enterprise EditionV7.0L10Windows 2000 Server / Windows Server 2003/ Windows Server 2003 R2FJSVapcstPending*
Interstage Application Server Enterprise EditionV7.0L11Windows 2000 Server / Windows Server 2003/ Windows Server 2003 R2FJSVapcstPending*
Interstage Application Server Enterprise EditionV8.0.0Windows 2000 Server / Windows Server 2003/ Windows Server 2003 R2FJSVapcstPending*
Interstage Application Server Enterprise EditionV8.0.1Windows 2000 Server / Windows Server 2003/ Windows Server 2003 R2FJSVapcstPending*
Interstage Application Server Enterprise EditionV8.0.2Windows 2000 Server / Windows Server 2003/ Windows Server 2003 R2FJSVapcstPending*
Interstage Application Server Enterprise EditionV9.0.0Windows 2000 Server / Windows Server 2003/ Windows Server 2003 R2FJSVapcstPending*
Interstage Application Server Enterprise EditionV9.0.0AWindows 2000 Server / Windows Server 2003/ Windows Server 2003 R2FJSVapcstPending*
Interstage Application Server Enterprise EditionV9.1.0Windows 2000 Server / Windows Server 2003/ Windows Server 2003 R2/ Windows Server 2008/ Windows Server 2008 R2FJSVapcstT010233WP-02
Interstage Application Server Enterprise EditionV9.1.0BWindows 2000 Server / Windows Server 2003/ Windows Server 2003 R2/ Windows Server 2008/ Windows Server 2008 R2FJSVapcstT010233WP-02
Interstage Application Server Enterprise EditionV9.2.0Windows 2000 Server / Windows Server 2003/ Windows Server 2003 R2/ Windows Server 2008/ Windows Server 2008 R2FJSVapcstT010233WP-02
Interstage Application Server Enterprise EditionV10.0.0Windows Server 2003/ Windows Server 2003 R2/ Windows Server 2008/ Windows Server 2008 R2FJSVapcstT010233WP-02
Interstage Application Server Enterprise EditionV11.0.0Windows Server 2003/ Windows Server 2003 R2/ Windows Server 2008/ Windows Server 2008 R2/ Windows Server 2012/ Windows Server 2012 R2FJSVapcstT010233WP-02
Interstage Application Server PlusV6.0L10Windows NT Server / Windows 2000 Server / Windows Server 2003/ Windows Server 2003 R2FJSVapcstPending*
Interstage Application Server PlusV7.0L10Windows 2000 Server / Windows Server 2003/ Windows Server 2003 R2FJSVapcstPending*
Interstage Application Server PlusV7.0L11Windows 2000 Server / Windows Server 2003/ Windows Server 2003 R2FJSVapcstPending*
Interstage Application Server Plus DeveloperV6.0L10Windows XP/ Windows NT/ Windows 2000/ Windows Server 2003FJSVapcstPending*
Interstage Application Server Plus DeveloperV7.0L10Windows XP/ Windows NT/ Windows 2000/ Windows Server 2003FJSVapcstPending*
Interstage Application Server Standard-J EditionV8.0.0Windows 2000 Server / Windows Server 2003/ Windows Server 2003 R2FJSVapcstPending*
Interstage Application Server Standard-J EditionV8.0.1Windows 2000 Server / Windows Server 2003/ Windows Server 2003 R2FJSVapcstPending*
Interstage Application Server Standard-J EditionV8.0.2Windows 2000 Server / Windows Server 2003/ Windows Server 2003 R2FJSVapcstPending*
Interstage Application Server Standard-J EditionV9.0.0Windows 2000 Server / Windows Server 2003/ Windows Server 2003 R2FJSVapcstPending*
Interstage Application Server Standard-J EditionV9.0.0AWindows 2000 Server / Windows Server 2003/ Windows Server 2003 R2FJSVapcstPending*
Interstage Application Server Standard-J EditionV9.0.0BWindows 2000 Server / Windows Server 2003/ Windows Server 2003 R2FJSVapcstPending*
Interstage Application Server Standard-J EditionV9.1.0Windows 2000 Server / Windows Server 2003/ Windows Server 2003 R2/ Windows Server 2008/ Windows Server 2008 R2FJSVapcstT010233WP-02
Interstage Application Server Standard-J EditionV9.1.0BWindows 2000 Server / Windows Server 2003/ Windows Server 2003 R2/ Windows Server 2008/ Windows Server 2008 R2FJSVapcstT010233WP-02
Interstage Application Server Standard-J EditionV9.2.0Windows 2000 Server / Windows Server 2003/ Windows Server 2003 R2/ Windows Server 2008/ Windows Server 2008 R2FJSVapcstT010233WP-02
Interstage Application Server Standard-J EditionV10.0.0Windows Server 2003/ Windows Server 2003 R2/ Windows Server 2008/ Windows Server 2008 R2FJSVapcstT010233WP-02
Interstage Application Server Standard-J EditionV11.0.0Windows Server 2003/ Windows Server 2003 R2/ Windows Server 2008/ Windows Server 2008 R2/ Windows Server 2012/ Windows Server 2012 R2FJSVapcstT010233WP-02
Interstage Apworks
ProductsVersionTarget OSPackage namePatch ID.
Interstage Apworks Modelers-J EditionV6.0L10Windows 98/ Windows Me/ Windows XP/ Windows NT/ Windows 2000/ Windows Server 2003FJSVapcstPending*
Interstage Apworks Modelers-J EditionV6.0L10AWindows 98/ Windows Me/ Windows XP/ Windows NT/ Windows 2000/ Windows Server 2003FJSVapcstPending*
Interstage Apworks Modelers-J EditionV7.0L11Windows 98/ Windows Me/ Windows XP/ Windows 2000/ Windows Server 2003FJSVapcstPending*
Interstage Interaction Manager
ProductsVersionTarget OSPackage namePatch ID.
Interstage Interaction ManagerV10.1.0RHEL5(Intel64)/ RHEL6(Intel64)FJSVapcstT010232LP-02
Interstage Interaction ManagerV10.1.0Windows Server 2008 R2/ Windows Server 2012/ Windows Server 2012 R2FJSVapcstT010236XP-02
Interstage Studio
ProductsVersionTarget OSPackage namePatch ID.
Interstage Studio Enterprise EditionV8.0.1Windows XP/ Windows 2000/ Windows Server 2003/ Windows VistaFJSVapcstPending*
Interstage Studio Enterprise EditionV9.0.0Windows XP/ Windows 2000/ Windows Server 2003/ Windows VistaFJSVapcstPending*
Interstage Studio Enterprise EditionV9.1.0Windows XP/ Windows 2000/ Windows Server 2003/ Windows Vista/ Windows Server 2008FJSVapcstT010233WP-02
Interstage Studio Enterprise EditionV9.1.0BWindows XP/ Windows 2000/ Windows Server 2003/ Windows Vista/ Windows Server 2008FJSVapcstT010233WP-02
Interstage Studio Enterprise EditionV9.2.0Windows XP/ Windows 2000/ Windows Server 2003/ Windows Vista/ Windows Server 2008/ Windows 7FJSVapcstT010233WP-02
Interstage Studio Standard-J EditionV8.0.1Windows XP/ Windows 2000/ Windows Server 2003/ Windows VistaFJSVapcstPending*
Interstage Studio Standard-J EditionV9.0.0Windows XP/ Windows 2000/ Windows Server 2003/ Windows VistaFJSVapcstPending*
Interstage Studio Standard-J EditionV9.1.0Windows XP/ Windows 2000/ Windows Server 2003/ Windows Vista/ Windows Server 2008FJSVapcstT010233WP-02
Interstage Studio Standard-J EditionV9.1.0BWindows XP/ Windows 2000/ Windows Server 2003/ Windows Vista/ Windows Server 2008FJSVapcstT010233WP-02
Interstage Studio Standard-J EditionV9.2.0Windows XP/ Windows 2000/ Windows Server 2003/ Windows Vista/ Windows Server 2008/ Windows 7FJSVapcstT010233WP-02
Interstage Studio Standard-J EditionV10.0.0Windows XP/ Windows Server 2003/ Windows Vista/ Windows Server 2008/ Windows 7FJSVapcstT010233WP-02
Interstage Studio Standard-J EditionV11.0.0Windows XP/ Windows Server 2003/ Windows Vista/ Windows Server 2008/ Windows 7/ Windows Server 2012/ Windows 8FJSVapcstT010233WP-02

For the Patches, please contact a Fujitsu system engineer or your partner(s).



Note: Determining the affected product
Please confirm the version of the product by "Software manual" appended to the product.

3-3. Workaround

Blocking multipart requests by WAFs(Web Application Firewall) will be a workaround if the web application does not need multipart requests.

4. Related information

5. Revision history

  • June 7th, 2016: Initial release


Top of Page