PAM-API-1104/PAM-API-1105 Warnings on PAM Dashboard
search cancel

PAM-API-1104/PAM-API-1105 Warnings on PAM Dashboard

book

Article ID: 445933

calendar_today

Updated On:

Products

CA Privileged Access Manager (PAM)

Issue/Introduction

PAM administrators observe one or more of the following warnings after logging into PAM, these warnings have not occurred in the past. What are these warnings and how can they be addressed?

  • PAM-API-1104: CATapApiUser API Key password is still the default value.
  • PAM-API-1105: MCApiUser API Key password is still the default value.

Environment

The warnings will occur in Privileged Access Manager in one of the following versions

  • 4.2.2, 4.2.3, or 4.2.4 with the respective 4.2.x.75 hotfix applied
  • 4.3.0 with the 4.3.0.75 hotfix applied
  • 4.3.1 and above

Cause

As part of code changes for the Symantec PAM Maintenance & Security Update (CVE-2025-15467), PAM now has an enhanced security validation to check if internal accounts are using the initial password generated when the environment was deployed. If either of these accounts have not had their password rotated, the warning(s) will be triggered.

Resolution

To clear the warning, rotate the credentials for the API key associated with the MCApiUser and/or CATapApiUser users.

  1. Navigate to Credentials > Manage Targets > Accounts.
  2. Filter the accounts by Application Type and select API Key.
  3. Double click on CATapApiUser-#### or MCApiKey-#### to update it.
  4. Click the key icon to generate a new credential, then click OK to save.

Additional Information

If either of these accounts are used as part of their respective integration, these integrations must be updated to prevent loss of functionality. For CATapApiUser, refer to Implementing Threat Analytics. For MCApiUser, refer to Integrate with the Management Console.

For more information about how these accounts are used, refer to KB259252- DSApiUser, LDAPApiUser, MCApiUser, & CATapApiUser Usage in PAM.

Note that, per the Broadcom Support site, support for the Management Console will be discontinued in January 2027.