CA PAM Proxy and vulnerabilities CVE-2026-21925,CVE-2026-21932,CVE-2026-21933 and CVE-2026-21945
search cancel

CA PAM Proxy and vulnerabilities CVE-2026-21925,CVE-2026-21932,CVE-2026-21933 and CVE-2026-21945

book

Article ID: 435953

calendar_today

Updated On:

Products

CA Privileged Access Manager (PAM)

Issue/Introduction

Recently vulnerabilities CVE-2026-21925,CVE-2026-21932,CVE-2026-21933,CVE-2026-21945 have been reported for the following OpenJDK versions

OpenJDK versions below 8 versions below u472 

OpenJDK versions 11.0.0  below 11.0.29

OpenJDK versions 17.0.0 below  17.0.17 

OpenJDK versions 21.0.0 below  21.0.9

OpenJDK version 25.0.0

Since for versions of CA PAM Proxy below 4.3.0 the OpenJDK version shipped with the product falls within the list of potentially vulnerable versions, a secure solution is needed

Resolution

Please install CA PAM Proxy version 4.3.1. This is a 64 bit version which comes win an OpenJDK version for which these vulnerabilities have been corrected

PAM Proxy is backward and forward compatible with CA PAM versions under the conditions established in KB429002