A vulnerability scanner identifies a Denial of Service (DoS) vulnerability (S2-068 / CVE-2024-53932) in the Symantec Identity Manager environment. This vulnerability exists in the Apache Struts 2 library version 6.7.0.
Symptoms
CVE-2024-53932 or S2-068.####/iam_im.ear/management_console.war/WEB-INF/lib/struts2-core-6.7.0.jar
The Identity Manager Management Console uses Apache Struts 2. Version 6.7.0 is susceptible to a Denial of Service attack when processing certain file upload requests.
This issue is fixed by upgrading the Struts library to version 6.8.0.
Additional Information To receive updates on this defect, . To speak with a customer representative or a Support Engineer, see .