Vulnerability Impact: CVE-2025-68493 (Apache Struts XXE Injection) in CA Client Automation
search cancel

Vulnerability Impact: CVE-2025-68493 (Apache Struts XXE Injection) in CA Client Automation

book

Article ID: 449887

calendar_today

Updated On:

Products

CA Client Automation CA Client Automation - IT Client Manager

Issue/Introduction

Following vulnerability is detected in Client Automation 14.5 with or without CU patches.

Vulnerability Name: Apache Struts XML External Entity (XXE) Injection in XWork (S2-069)
CVE ID: CVE-2025-68493
Severity: High
Scanners typically flag vulnerable Struts libraries located in the installation path, such as: ####/CA/DSM/WebConsole/WEB-INF/lib/struts2-core-####.jar

CVE-2025-68493

 

Apache Struts XML External Entity (XXE) Injection in XWork (S2-069) – CVE-2025-68493 is present in following package versions 

  • Affected packages: struts2-core
  • OSS Affected versions: >=2.0.0 <=2.3.37, >=2.5.0 <=2.5.33, >=6.0.0 <6.1.1

 

In 14.5 CU7 we could find struts2-core package under :

Directory of C:\Program Files (x86)\CA\DSM\Web Console\webapps\AMS\WEB-INF\lib
12/12/2023  11:02 PM         1,629,169 struts2-core-2.5.33.jar

Directory of C:\Program Files (x86)\CA\DSM\Web Console\webapps\wac\WEB-INF\lib
04/29/2024  11:00 PM         1,629,169 struts2-core-2.5.33.jar

Directory of C:\Program Files (x86)\CA\SC\CIC\Tomcat\webapps\CICManager\WEB-INF\lib
04/18/2024  04:45 PM         1,629,169 struts2-core-2.5.33.jar

 

Version is 2.5.33 is affected by the vulnerability

 

In 14.6 the files have version 6.7.4 and are not affected by the vulnerability :

Directory of C:\Program Files (x86)\CA\DSM\Web Console\webapps\AMS\WEB-INF\lib
10/31/2025  10:52 AM         1,628,412 struts2-core-6.7.4.jar

Directory of C:\Program Files (x86)\CA\DSM\Web Console\webapps\wac\WEB-INF\lib
10/31/2025  03:31 PM         1,628,412 struts2-core-6.7.4.jar

Directory of C:\Program Files (x86)\CA\SC\CIC\Tomcat\webapps\CICManager\WEB-INF\lib
10/21/2025  10:17 AM         1,628,412 struts2-core-6.7.4.jar

 

Environment

Client Automation 14.5 with or without CU patches.

Resolution

There is no standalone hotfix or patch available for the 14.5 RU7 branch to remediate this specific vulnerability.

Upgrade the Domain Manager Client Automation environment to version R14.6 or later.