Below are the multiple High Severity CVEs identified during their vulnerability assessment of the Wily Introscope Agent.
| CVE | Severity | Affected File/Path |
|---|---|---|
| CVE-2026-33870 | High | /usr/sap/DAA/SMDA98/SMDAgent_vhjmpci/applications.config/com.sap.smd.agent.application.wily/BytecodeAgent/ISAGENT.10.8.0.2-2025-01-23/wily/core/ext/lib/netty-codec-http.jar |
| CVE-2026-42587 | High | /usr/sap/DAA/SMDA98/SMDAgent_vhjmpci/applications.config/com.sap.smd.agent.application.wily/BytecodeAgent/ISAGENT.10.8.0.2-2025-01-23/wily/core/ext/lib/netty-codec-http.jar |
| CVE-2026-42583 | High | /usr/sap/DAA/SMDA98/SMDAgent_vhjmpci/applications.config/com.sap.smd.agent.application.wily/BytecodeAgent/ISAGENT.10.8.0.2-2025-01-23/wily/core/ext/lib/netty-codec.jar → META-INF/maven/io.netty/netty-codec |
| CVE-2026-42584 | High | /usr/sap/DAA/SMDA98/SMDAgent_vhjmpci/applications.config/com.sap.smd.agent.application.wily/BytecodeAgent/ISAGENT.10.8.0.2-2025-01-23/wily/core/ext/lib/netty-codec-http.jar |
| CVE-2026-42584 | High | /usr/sap/DAA/SMDA98/SMDAgent_vhjmpci/applications.config/com.sap.smd.agent.application.wily/BytecodeAgent/ISAGENT.10.8.0.2-2025-01-23/wily/core/ext/lib/netty-codec-http.jar → META-INF/maven/io.netty/nett |
APM 10.8
Wily Introscope Agent 10.8
These vulnerabilities are typically remediated by upgrading the Netty component to version 4.1.133.Final or higher. Security vulnerabilities in Netty 4.1.132.Final, upgraded to 4.1.135.Final and upgraded Netty to 4.1.135.Final in this release build: SAP build-990829(10.8.0.234)
All the above critical CVEs are fixed in build: SAP build-990829(10.8.0.234)
Contact Broadcom Support to obtain a copy of latest SAP Build.
Note:- APM10.8 SP1 is a cumulative service pack. SAP has its own release with no hotfix procedure.