PAM-API-11054 Warning: <USERID> API Key password is still the default value after applying patch security maintenance patch
search cancel

PAM-API-11054 Warning: <USERID> API Key password is still the default value after applying patch security maintenance patch

book

Article ID: 445933

calendar_today

Updated On:

Products

CA Privileged Access Manager (PAM)

Issue/Introduction

After applying CA Privileged Access Manager (PAM) security maintenance patch:

 Broadcom Security Advisories - Symantec PAM Maintenance & Security Update (CVE-2025-15467)

the following warning message(s) may appear in the PAM Dashboard:

  • PAM-API-1104: CATapApiUser API Key password is still the default value.
  • PAM-API-1105: MCApiUser API Key password is still the default value.

Cause

These security patches introduced an enhanced security validation. The system now proactively scans internal accounts to ensure they are not using default credentials. The MCApiUser is an internal account used as an anchor for API keys required for integration with the PAM Management Console. The CATapApiUser is an internal account used as an anchor for API keys required for integration with the Threat Analytics.  If either of these account(s) still retains its factory-default password, the PAM-API-1105/PAM-API-1104 warning is triggered.

Resolution

To clear the warning, you must rotate the credentials for these usersMCApiUser\CATapApiUser. Even if you do not utilize these integrations.   If you are using these integrations, after the credential is rotated please make sure you update it (PAM UI >> Configuration >> Management Console >> Integration or PAM UI >> Configuration >> Symantec Modules >> Threat Analytics)