There are security concerns regarding outdated third-party JAR files used within the Agent. This specifically impacts the Bouncy Castle (bcprov), Log4j, and Jackson library suites.
Workload Automation AE Agents 24.2 on Linux
To mitigate these security concerns, the affected third-party libraries have been updated to newer, secure versions.
The updated library versions are as follows:
Bouncy Castle: bcprov-jdk.jar (v1.84)
Jackson Suite: jackson-annotations, jackson-core, jackson-databind (v2.18.9)
Log4j Suite: log4j-api, log4j-core, log4j-slf4j2-impl (v2.26.0)
For complete solution details and to obtain the patch, please refer to the following link:
To speak with a customer representative or a Support Engineer see Contact Support. Scroll to the bottom of the page and click on the respective region.