WCC - Sensitive Data Transmission to ipce.broadcom.com (Broadcom Assistant)
search cancel

WCC - Sensitive Data Transmission to ipce.broadcom.com (Broadcom Assistant)

book

Article ID: 446271

calendar_today

Updated On:

Products

Autosys Workload Automation

Issue/Introduction

Users may observe suspicious HTTP requests to an event-capturing API endpoint on a Broadcom subdomain (ipce.broadcom.com) while navigating the WCC application. These requests, identified using proxy logging tools, may contain:

  • AntiXSRFToken used for submitting HTTP requests to the WCC service.
  • Source WCC server URL.
  • Product keys and UIDs.
  • Commented-out source code in AAIAssistantIntentNavigation.js which might include session tokens or usernames.

Environment

Product: AutoSys Workload Automation
Component: WebUI (formerly Workload Control Center)
Version: 24.x

Cause

These communications are a standard part of the Broadcom Assistant feature, which includes Intelligent Content Experience (Integrated Help) and Intelligent Automation Assistant (IAA). The requests occur for product registration and whenever an end-user accesses the Help features.

Resolution

This behavior is by design for the integrated help functionality. However, if your organization's security policy prohibits this telemetry or the transmission of session tokens, the Assistant plugin can be disabled.

To disable the plugin:

  1. Open a technical support case with Broadcom.
  2. Request the deactivation of the Assistant plugin for your specific site.
  3. The deactivation must be performed by Broadcom on the backend.

Additional Information

For more information on Broadcom Assistant features, see Intelligent Content Experience (Integrated Help) and Intelligent Automation Assistant (IAA) sections in the AutoSys Workload Automation documentation.

To speak with a customer representative or a Support Engineer see Contact Support. Scroll to the bottom of the page and click on the respective region.