A security vulnerability scan of a containerized Workload Automation Agent (version 24.1) identifies multiple libraries as susceptible to vulnerabilities based on their installed versions.
Reported Components & Paths:
/opt/CA/WorkloadAutomationAE/SystemAgent/WA_AGENT/jars/js.jar/opt/CA/WorkloadAutomationAE/SystemAgent/WA_AGENT/jars/ext/log4j-core.jar/opt/CA/WorkloadAutomationAE/SystemAgent/WA_AGENT/jars/ext/mail.jar
Product: Workload Automation Agent
Version: 24.1
Security scanners often flag libraries based solely on the version string in the filename or manifest. However, many vulnerabilities are only exploitable if specific code paths (APIs) or configuration settings (Appenders/Layouts) are active within the application.
Analysis of Impact
Recommendation
To remediate these findings for security compliance and ensure you are running the most secure versions of bundled libraries, follow these options: