Security scanners report the presence of an older, vulnerable version of libcrypto.so (OpenSSL 1.1.1a) located in the /opt/CA/scm/lib directory after upgrading to CA Harvest SCM 14.5.01.
The upgrade process from Harvest v14 to v14.5.01 does not automatically remove legacy OpenSSL 1.x library files. Harvest SCM 14.5.01 strictly utilizes OpenSSL 3.4.0. The older version remains as a residual file from the previous installation and is not used by the current software version.
Identify the installed version of CA Harvest Software Change Manager to confirm it is 14.5.01 or higher. If confirmed, the residual file can be safely removed.
Follow these steps to mitigate the finding:
cd /opt/CA/scm/lib.libcrypto.so) to a backup location outside of the library path: mv libcrypto.so /tmp/####_backup/.Note: On the Unix and Linux platforms, Harvest does not deploy any jar files when installing the SCM Server and Client components. The $CA_SCM_HOME/lib folder is the only place you will find this file.
CVE-2025-15467: CA Harvest SCM - OpenSSL Stack Buffer Overflow Vulnerability