ASM Webdrive Agent has Redis 6.0 CVE Vulnerability
search cancel

ASM Webdrive Agent has Redis 6.0 CVE Vulnerability

book

Article ID: 415386

calendar_today

Updated On:

Products

CA App Synthetic Monitor

Issue/Introduction

OPMS stations are marked for critical vulnerability with regards to redis6.0 version that gets installed as part of SDK installer. OPMS ASM stations are on version 25.2.30.

critical vulnerability advisory - Redis LUA CVE-2025-49844 "RediShell"

Resolution

ASM DEV team  has following update.

1-
In the OPMS installation, redis is used only as internal storage, it is not accessible from outside and the vulnerability cannot be abused. Thus no impact due to vulnerability.

2-
ASM DEV team is currently preparing 25.10 release. As part of this release, ASM DEV team will update the redis container to the latest version.