This is an IBM Automation portal for Digital Business Automation products. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).
We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:
Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,
Post an idea.
Get feedback from the IBM team and other customers to refine your idea.
Follow the idea through the IBM Ideas process.
Cloud Pak for Business Automation - including Business Automation Studio and App Designer, Business Automation Insights
Business Automation Workflow (BAW) - including BAW, Business Process Manager, Workstream Services, Business Performance Center, Advanced Case Management
Content Services - FileNet Content Manager
Content Services - Content Manager OnDemand
Content Services - Daeja Virtual Viewer
Content Services - Navigator
Content Services - Content Collector for Email, Sharepoint, Files
Content Services - Content Collector for SAP
Content Services - Enterprise Records
Content Services - Content Manager (CM8)
Datacap
Automation Document Processing
Automation Decision Services (ADS)
Operational Decision Manager
Robotic Process Automation
Robotic Process Automation with Automation Anywhere
Blueworks Live
Business Automation Manager Open Edition
IBM Process Mining
Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.
IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.
ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.
IBM has been addressing the use of Struts in BAW over the past few releases.
First, Process Admin Console (PAC) which used Struts has been replaced in 23.0.1. The new PAC does not use Struts.
However, there is still struts-1.x in the product:
WAS Admin Console (self-maintained by the WAS team)
Performance Admin Console
Legacy Servlets in the context of a portal in Lombardi Teamworks 7 and earlier
For (2) and (3), IBM has picked up a fixed version of Struts that was published by NTT security to address multiple vulnerabilities. The version is actually called SP3 (as in security patch 3). So, Performance Admin Console and Legacy Servlets in the context of a portal in teamworks 7 and earlier are using Struts 1.x SP3. The source is available at https://osdn.net/projects/terasoluna/releases/65922 and referenced from https://www.nttdata.com/global/ja/news/information/2014/052301/
One other CVE (CVE-2014-0114) has been addressed by introducing ServletFilters in relevant code paths many years ago. The fix was JR50221 published with https://www.ibm.com/support/pages/security-bulletin-classloader-manipulation-apache-struts-cve-2014-0114-affects-websphere-lombardi-edition-and-ibm-business-process-manager-bpm
The concern with struts-1.x is two-fold:
(1) There are known vulnerabilities. IBM has addressed this concern by using 1.2.9-SP3 and mitigating CVE-2014-0114 via ServletFilters. (2) struts-1.x is EOL and any future CVE reported against the library will not be fixed by the community project. IBM therefore will address this concern by fixing any future vulnerabilities ourselves in the struts code. IBM would modify the open source and create 1.2.9-SP4 in case nobody else does.
NOTE: WebSphere itself has been updated as follows (see links) to address Struts vulnerabilities:
IBM WebSphere Application Server is not vulnerable to CVE-2017-5638
https://www.ibm.com/support/pages/ibm-websphere-application-server-not-vulnerable-cve-2017-5638
Security Bulletin: Multiple security vulnerabilities have been identified in IBM WebSphere Application Server shipped with IBM Digital Business Automation Workflow family products
https://www.ibm.com/support/pages/security-bulletin-multiple-security-vulnerabilities-have-been-identified-ibm-websphere-application-server-shipped-ibm-digital-business-automation-workflow-family-products