EEM CVE-2025-68161
search cancel

EEM CVE-2025-68161

book

Article ID: 432586

calendar_today

Updated On:

Products

CA Service Management - Service Desk Manager CA Service Catalog CA Process Automation Base

Issue/Introduction

Is EEM affected by CVE-2025-68161 vulnerability?

Environment

Embedded Entitlements Manager (EEM) 12.6/12.7

Resolution

It has been determined that EEM is not affected by this vulnerability based on the following:

API Usage: EEM doesn't utilize the Log4j SocketAppender API within the source code.
Programmatic Configuration: There is no programmatic implementation of the SocketAppender configuration within the environment.
Runtime Configuration: EEM has no Log4j configuration that references the log4j SocketAppender functionality at runtime.

Note: The .jar files located under EmbeddedEntitlementsManager folder (default location: C:\Program Files\CA\SC\EmbeddedEntitlementsManager) can't be deleted. Deleting files from the EEM folder will impact the normal EEM operations.

Additional Information

CVE-2025-68161 Detail

The EEM Engineering team is planning to release EEM 12.7.3 that contains the latest version of log4j in the first week of June 2026(subject to change) after validation from the embedding products (like Service Management), which might take some more time.