Apache Struts Vulnerabilities (S2-068 & S2-069) in Symantec VIP Enterprise Gateway 9.11.2
search cancel

Apache Struts Vulnerabilities (S2-068 & S2-069) in Symantec VIP Enterprise Gateway 9.11.2

book

Article ID: 448594

calendar_today

Updated On:

Products

VIP Service

Issue/Introduction

Does Symantec VIP Enterprise Gateway (EG) version 9.11.2 contain vulnerable versions of the Apache Struts library?

  • S2-068 – Denial of Service (DoS)
  • S2-069 – XML External Entity (XXE) Injection

 

Environment

Symantec VIP Enterprise Gateway 9.11.2

Cause

Vulnerability Status Breakdown

AdvisoryVulnerability Type & CVEAffected Struts VersionsStatus in VIP EG 9.11.2 (Struts 6.4.0)
S2-068

Denial of Service (DoS) via File Leak


(CVE-2025-64775)

2.0.0 through 6.7.0


7.0.0 through 7.0.3

VULNERABLE


(Struts 6.4.0 falls directly within the affected range)

S2-069

XML External Entity (XXE) Injection


(CVE-2025-68493)

2.0.0 through 2.3.37


2.5.0 through 2.5.33


6.0.0 through 6.1.0

NOT VULNERABLE


(Struts 6.4.0 is a newer release outside of the affected ranges)

 

Resolution

Vulnerability Details

1. S2-068 – Denial of Service (CVE-2025-64775)

  • Apache Struts Affected Versions: 2.0.0 ≤ 6.7.0
  • EG Component: struts2-core-6.4.0.jar
  • Severity: High
  • Description: A Denial of Service vulnerability exists in Apache Struts versions up to 6.7.0.

Fixed Version: Apache Struts 6.8.0

2. S2-069 – XML External Entity Injection (CVE-2025-68493)

  • Apache Struts Affected Versions: 2.x ≤ 2.3.37, 2.5.x ≤ 2.5.33, 6.x < 6.1.1
  • EG Components:
    • struts2-core-6.4.0.jar
    • struts2-core-2.5.33.jar
  • Severity: High
  • Description: XML External Entity Injection vulnerability in XWork.

Fixed Version: Apache Struts 6.1.1 or later

Resolution

Recommended Action: Upgrade to VIP Enterprise Gateway 9.11.3. This includes the upgraded Struts libraries that address both vulnerabilities.

For full details regarding this release, please review the VIP Enterprise Gateway 9.11.3 Release Notes.

Additional Information

Symantec VIP Enterprise Gateway is continuously monitored for third-party library vulnerabilities. Customers are encouraged to keep their environments up to date with the latest releases to benefit from security fixes and improvements.

  • Is Symantec VIP and its components vulnerable to Apache Struts S2-067 (CVE-2024-53677)?
  • Apache Struts Official Security Bulletins (for S2-068 and S2-069)

For upgrade assistance or further questions, please contact Broadcom Support.