Following vulnerability is detected in Client Automation 14.5 with or without CU patches.
Vulnerability Name: Apache Struts XML External Entity (XXE) Injection in XWork (S2-069)
CVE ID: CVE-2025-68493
Severity: High
Scanners typically flag vulnerable Struts libraries located in the installation path, such as: ####/CA/DSM/WebConsole/WEB-INF/lib/struts2-core-####.jar
Apache Struts XML External Entity (XXE) Injection in XWork (S2-069) – CVE-2025-68493 is present in following package versions
In 14.5 CU7 we could find struts2-core package under :
Directory of C:\Program Files (x86)\CA\DSM\Web Console\webapps\AMS\WEB-INF\lib
12/12/2023 11:02 PM 1,629,169 struts2-core-2.5.33.jar
Directory of C:\Program Files (x86)\CA\DSM\Web Console\webapps\wac\WEB-INF\lib
04/29/2024 11:00 PM 1,629,169 struts2-core-2.5.33.jar
Directory of C:\Program Files (x86)\CA\SC\CIC\Tomcat\webapps\CICManager\WEB-INF\lib
04/18/2024 04:45 PM 1,629,169 struts2-core-2.5.33.jar
Version is 2.5.33 is affected by the vulnerability
In 14.6 the files have version 6.7.4 and are not affected by the vulnerability :
Directory of C:\Program Files (x86)\CA\DSM\Web Console\webapps\AMS\WEB-INF\lib
10/31/2025 10:52 AM 1,628,412 struts2-core-6.7.4.jar
Directory of C:\Program Files (x86)\CA\DSM\Web Console\webapps\wac\WEB-INF\lib
10/31/2025 03:31 PM 1,628,412 struts2-core-6.7.4.jar
Directory of C:\Program Files (x86)\CA\SC\CIC\Tomcat\webapps\CICManager\WEB-INF\lib
10/21/2025 10:17 AM 1,628,412 struts2-core-6.7.4.jar
Client Automation 14.5 with or without CU patches.
There is no standalone hotfix or patch available for the 14.5 RU7 branch to remediate this specific vulnerability.
Upgrade the Domain Manager Client Automation environment to version R14.6 or later.