Does Symantec VIP Enterprise Gateway (EG) version 9.11.2 contain vulnerable versions of the Apache Struts library?
Symantec VIP Enterprise Gateway 9.11.2
| Advisory | Vulnerability Type & CVE | Affected Struts Versions | Status in VIP EG 9.11.2 (Struts 6.4.0) |
| S2-068 | Denial of Service (DoS) via File Leak (CVE-2025-64775) | • • | VULNERABLE (Struts 6.4.0 falls directly within the affected range) |
| S2-069 | XML External Entity (XXE) Injection (CVE-2025-68493) | • • • | NOT VULNERABLE (Struts 6.4.0 is a newer release outside of the affected ranges) |
Fixed Version: Apache Struts 6.8.0
Fixed Version: Apache Struts 6.1.1 or later
Recommended Action: Upgrade to VIP Enterprise Gateway 9.11.3. This includes the upgraded Struts libraries that address both vulnerabilities.
For full details regarding this release, please review the VIP Enterprise Gateway 9.11.3 Release Notes.
Symantec VIP Enterprise Gateway is continuously monitored for third-party library vulnerabilities. Customers are encouraged to keep their environments up to date with the latest releases to benefit from security fixes and improvements.
For upgrade assistance or further questions, please contact Broadcom Support.