cancel
Showing results for 
Search instead for 
Did you mean: 
Read only

File Upload Logic Flaw in Apache Struts | CVE-2024-53677

macguire
Discoverer
0 Likes
1,013

I have a local deployment of SAP BusinessObjects 4.3 and my CYberSecurity team mentioned that the Apache Struts version used by SAP BO is vulnerable to CVE-2024-53677.

Is there a fix, patch, workaround to disable this? 

I'm being requested to update Apache Struts to 6.4.0, but I read that there is no backwards compatibility and I'm scared about something stopping to work.

Has anyone worked a fix for this vulnerability?

Accepted Solutions (1)

Accepted Solutions (1)

ayman_salem
Active Contributor

see KBA 3554753 - Impact of CVE-2024-53677 on SAP BusinessObjects

macguire
Discoverer
0 Likes
That is what I was looking for, thanks!

Answers (0)