Applications Manager vulnerability - Terrapin SSH vulnerability (CVE-2023-48795)
search cancel

Applications Manager vulnerability - Terrapin SSH vulnerability (CVE-2023-48795)

book

Article ID: 280682

calendar_today

Updated On:

Products

CA Automic Applications Manager (AM)

Issue/Introduction

Is Applications Manager vulnerable to Terrapin SSH vulnerability (CVE-2023-48795)?

Environment

Applications Manager 9.4 and 9.5

Cause

Applications Manager ships with a 3rd party Apache Mina SSHD server which has been flagged as vulnerable to CVE-2023-48795.

The SSH server shipped with Applications Manager is not a full-fledged SSH server. It has very limited capabilities. The shell cannot execute all commands. Since it is embedded, there currently is no work around for the issue.

Resolution

Fixed in Applications Manager version 9.5.2