CVE-2018-2796: Workload Automation System Agent Java vulnerability
search cancel

CVE-2018-2796: Workload Automation System Agent Java vulnerability

book

Article ID: 266977

calendar_today

Updated On:

Products

Workload Automation Agent

Issue/Introduction

Does a vulnerability exists for /opt/CA/WorkloadAutomationAE/SystemAgent/WA_AGENT/jre/lib/version.properties

cat /opt/CA/WorkloadAutomationAE/SystemAgent/WA_AGENT/jre/lib/version.properties
#Created by Ant MergeProperties
#Mon Mar 26 09:19:56 BST 2018
sdk.version=8.0.5.11 - xxx####xx5xx11-20180326_01(SR5 FP11) 

Is there an update for the vulnerability?

Environment

Release : 11.4

Resolution

Having a base score of 5.3, CVE-2018-2796 is a medium risk vulnerability affecting Oracle Java SE.

The 11.4 SP1 agent has been unsupported since October 31, 2022

Your options are:

  • [OPTION 1]  Remain on the 11.4 agent and follow the documented instructions to "Replace the JRE Installed by the Agent Without Upgrading the Agent." You must remain within the JRE 8 version. Any minor version of JRE 8 is compatible.
    IMPORTANT NOTE: If you opt to remain on the 11.4 release of the agent, you are entitled to self-service support only. We will not be able to provide continued support for this agent..
  • [OPTION 2] Upgrade the agent to a fully supported release. Please reference the Support Matrix to confirm compatibility of the agent with your operating system.

 

Under both options above, be sure to create a backup of the agent for restoration purposes in case it's needed.