Vulnerability CVE-2024-5535 on remoteengineer directory is showing up in the vulnerability report
search cancel

Vulnerability CVE-2024-5535 on remoteengineer directory is showing up in the vulnerability report

book

Article ID: 375600

calendar_today

Updated On:

Products

Autosys Workload Automation

Issue/Introduction

An OpenSSL 1.0.2 vulnerability exists on the linux servers.  The impacted file is:

 /opt/ca/workloadautomationae/autosys/install/remoteengineer/linux/libs_gui/libcrypto.so.1.0.0

 

Can this file be removed without any impacts to any Full Client/AutoSys Application component (WAAE, WCC, EEM, etc)? The versions of AutoSys are 12.1x and 12.0x. If it cannot be removed, can it be updated?

Environment

AutoSys: 12.0x, 12.1

WCC: 12.0x, 12.1

EEM: 12.6.x

Resolution

The entire remoteengineer directory can safely be remove and it will not effect AutoSys, WCC, or EEM. The Remote Engineer was discontinued beginning with the AutoSys 11.3.6SP8 version.