Agent Temp directory Accessible to All Users - Folder/File Permission: Authenticated Users in Windows Server
search cancel

Agent Temp directory Accessible to All Users - Folder/File Permission: Authenticated Users in Windows Server

book

Article ID: 366955

calendar_today

Updated On:

Products

CA Automic Workload Automation - Automation Engine

Issue/Introduction

A security Audit performed on Agents deployed on Windows and Unix revealed the following security gaps.

1. All Users have Read Access to Secret Keys and Passwords (TLS and transfer keys in the ./security folder and ./trustedCert folder).

2. All Users have Write Access to the 'Temp Folder in the attached report.

 

Environment

System Agents Automic Automation on Windows and Linux/UNIX in version 21.

Cause

Currently these points are considered as potential vulnerabilities and will be reviewed/improved.

Resolution

R&D is currently reviewing these points and will decide on their next action. A Story ticket has been opened for these two topics (F137634)