legacy-knowledge-base
公開されました Sep. 10, 2025

Apache Struts 1の既知の脆弱性

written-by

Justin Choi

How To articles are not official guidelines or officially supported documentation. They are community-contributed content and may not always reflect the latest updates to Liferay DXP. We welcome your feedback to improve How To articles!

While we make every effort to ensure this Knowledge Base is accurate, it may not always reflect the most recent updates or official guidelines.We appreciate your understanding and encourage you to reach out with any feedback or concerns.

legacy-article

learn-legacy-article-disclaimer-text

QUESTION: Liferay DXP 7.0、7.1、Liferay Portalは、以下の脆弱性からどのような影響を受けるのでしょうか?

解決策

Liferayへの影響

Liferay DXP 7.0、7.1をご利用のお客様には、主にLiferay Portal 6.2が脆弱性の対象となります。 修正内容は、すでにDXPのプラットフォームに組み込まれています。

CVE-2016-1182に関して、Liferay DXPはstrutsの検証メッセージを使用しません。

CVE-2016-1181および関連する問題CVE-2015-0899に関して、Liferay DXPおよびPortalは、両製品がstrutsフォームを使用せず、セッション内に保存しないため、脆弱性はないとのことです。

お客さまへの影響

Strutsの検証出力メッセージのサポートが削除されたため、可能な修正で一部のカスタムアプリケーションを破壊する可能性があります。

did-this-article-resolve-your-issue

legacy-knowledge-base