Security concerns for Third-Party JAR updates in Agent (bcprov, Log4j, Jackson)
search cancel

Security concerns for Third-Party JAR updates in Agent (bcprov, Log4j, Jackson)

book

Article ID: 450046

calendar_today

Updated On:

Products

Autosys Workload Automation

Issue/Introduction

There are security concerns regarding outdated third-party JAR files used within the Agent. This specifically impacts the Bouncy Castle (bcprov), Log4j, and Jackson library suites.

Environment

Workload Automation AE Agents 24.2 on Linux

Resolution

To mitigate these security concerns, the affected third-party libraries have been updated to newer, secure versions.

The updated library versions are as follows:

  • Bouncy Castle: bcprov-jdk.jar (v1.84)

  • Jackson Suite: jackson-annotations, jackson-core, jackson-databind (v2.18.9)

  • Log4j Suite: log4j-api, log4j-core, log4j-slf4j2-impl (v2.26.0)

For complete solution details and to obtain the patch, please refer to the following link:

LT21320

 

 

 

Additional Information

To speak with a customer representative or a Support Engineer see Contact Support. Scroll to the bottom of the page and click on the respective region.