WA Agent and Log4j Vulnerability CVE-2025-68161
search cancel

WA Agent and Log4j Vulnerability CVE-2025-68161

book

Article ID: 426763

calendar_today

Updated On:

Products

Workload Automation Agent ESP dSeries Workload Automation - Business Agents (dSeries) ESP dSeries Workload Automation - System Agent (dSeries)

Issue/Introduction

Our security team is telling us we need to upgrade log4j used by Workload Automation Agent to version 2.25.3 or later. 

CVE-2025-68161

Environment

Workload Automation Agent 12.1.x, 24.0, 24.1

Cause

 

Resolution

The mentioned vulnerability is considered to have a medium impact only when the Log4j2 SocketAppender functionality is used. The Workload Automation Agent does not utilize this specific functionality of Log4j2; therefore, Agent is not impacted by this vulnerability.

However, to remediate the vulnerability for your security scan and satisfy compliance requirements, you have two options:

Option 1:

  • Upgrade the Agent (Recommended) - Upgrade the agent to the latest release (version 24.2), which is shipped with Log4j 2.25.3.

Option 2: