Error: Apache Struts2 Denial of Service Vulnerability S2-068 (CVE-2024-53932) in Identity Manager
search cancel

Error: Apache Struts2 Denial of Service Vulnerability S2-068 (CVE-2024-53932) in Identity Manager

book

Article ID: 448843

calendar_today

Updated On:

Products

CA Identity Suite

Issue/Introduction

A vulnerability scanner identifies a Denial of Service (DoS) vulnerability (S2-068 / CVE-2024-53932) in the Symantec Identity Manager environment. This vulnerability exists in the Apache Struts 2 library version 6.7.0.

Symptoms

  • Security scans flag CVE-2024-53932 or S2-068.
  • The scanner detects the following vulnerable file: ####/iam_im.ear/management_console.war/WEB-INF/lib/struts2-core-6.7.0.jar

 

Environment

  • Identity Manager 14.5.x
  • JBoss EAP 7.4
  • Red Hat Enterprise Linux (RHEL)

Cause

The Identity Manager Management Console uses Apache Struts 2. Version 6.7.0 is susceptible to a Denial of Service attack when processing certain file upload requests.

 

Resolution

This issue is fixed by upgrading the Struts library to version 6.8.0.

  1. Review HotFixes link from Symantec Identity Governance Administration (IGA) 14.5 page  for Virtual Appliance distribution mode or HotFixes link for Symantec Idnetity Governance Admninnistration (IGA) 14.5 page for Standalone Distribution mode to review if this is already published (spedifically for Struss version 6.8.0 - disregard if publication is old from 21 May 2025 that has an update to Apache Struts to version 6.7.0. In this case don't download the patch).
    If yes, download the patch that updates to struts 6.8.0 and follow installation steps from there and stop following this Article steps here. If not available yet, continue the next steps from this Doc
  2. Open a Support Case with Broadcom and asks you need a HotFix to update Virtual Appliance to Strus 6.8.0.

Additional Information To receive updates on this defect, subscribe to this article. To speak with a customer representative or a Support Engineer, see Contact Support.