WORKAROUND:
Solution below applies for Standalone Server (JBoss) only. For Central Agents on WebLogic, it is recommended to upgrade to Stat 5.8.x or to switch Central Agent to Standalone.
Important Note: The following solution limits Web functionality of Stat. For example, one of the limitations would be not being able to open up a csr via stat web. However user can create a csr via stat web and uses the approval functionality without any problem.
1. Make sure to sign in with your supportlink account and scroll all the way down to the attachment section. Download struts.zip attachment from this solution
2. Stop Central Agent
3. Backup and delete the following files from <STAT_HOME>\app\server\default\lib
freemarker-2.3.19.jar
ognl-3.0.6.jar
struts2-core-2.3.20.jar
struts2-json-plugin-2.3.20.jar
struts2-tiles-plugin-2.3.20.jar
tiles-api-2.0.6.jar
tiles-core-2.0.6.jar
tiles-jsp-2.0.6.jar
xwork-core-2.3.20.jar
4. Unzip the struts.zip into <STAT_HOME>\app\server\default\lib
5. Start Central Agent
STATUS:
This issue has been addressed in Stat 5.8.0 hf-e and Stat 5.8.1 hf-c. Upgrade to 5.8.x and apply the hotfix below in order to resolve the CVE-2017-5638 vulnerability issue.
Stat 5.8.0 hf-e:
https://support.quest.com/stat/kb/227180
Stat 5.8.1 hf-c:
https://support.quest.com/stat/kb/227182