Is Applications Manager vulnerable to Terrapin SSH vulnerability (CVE-2023-48795)?
Applications Manager 9.4 and 9.5
Applications Manager ships with a 3rd party Apache Mina SSHD server which has been flagged as vulnerable to CVE-2023-48795.
The SSH server shipped with Applications Manager is not a full-fledged SSH server. It has very limited capabilities. The shell cannot execute all commands. Since it is embedded, there currently is no work around for the issue.
Fixed in Applications Manager version 9.5.2