Security vulnerabilities issues in ISAgent 10.8
search cancel

Security vulnerabilities issues in ISAgent 10.8

book

Article ID: 452430

calendar_today

Updated On:

Products

CA Application Performance Management (APM / Wily / Introscope)

Issue/Introduction

Below are the multiple High Severity CVEs identified during their vulnerability assessment of the Wily Introscope Agent.

 

CVESeverityAffected File/Path
CVE-2026-33870High/usr/sap/DAA/SMDA98/SMDAgent_vhjmpci/applications.config/com.sap.smd.agent.application.wily/BytecodeAgent/ISAGENT.10.8.0.2-2025-01-23/wily/core/ext/lib/netty-codec-http.jar
CVE-2026-42587High/usr/sap/DAA/SMDA98/SMDAgent_vhjmpci/applications.config/com.sap.smd.agent.application.wily/BytecodeAgent/ISAGENT.10.8.0.2-2025-01-23/wily/core/ext/lib/netty-codec-http.jar
CVE-2026-42583High/usr/sap/DAA/SMDA98/SMDAgent_vhjmpci/applications.config/com.sap.smd.agent.application.wily/BytecodeAgent/ISAGENT.10.8.0.2-2025-01-23/wily/core/ext/lib/netty-codec.jar → META-INF/maven/io.netty/netty-codec
CVE-2026-42584High/usr/sap/DAA/SMDA98/SMDAgent_vhjmpci/applications.config/com.sap.smd.agent.application.wily/BytecodeAgent/ISAGENT.10.8.0.2-2025-01-23/wily/core/ext/lib/netty-codec-http.jar
CVE-2026-42584High/usr/sap/DAA/SMDA98/SMDAgent_vhjmpci/applications.config/com.sap.smd.agent.application.wily/BytecodeAgent/ISAGENT.10.8.0.2-2025-01-23/wily/core/ext/lib/netty-codec-http.jar → META-INF/maven/io.netty/nett

Environment

APM 10.8

Wily Introscope Agent 10.8

 

Resolution

These vulnerabilities are typically remediated by upgrading the Netty component to version 4.1.133.Final or higher. Security vulnerabilities in Netty 4.1.132.Final, upgraded to 4.1.135.Final and upgraded Netty to 4.1.135.Final in this release build: SAP build-990829(10.8.0.234)

All the above critical CVEs are fixed in  build: SAP build-990829(10.8.0.234)

Contact Broadcom Support to obtain a copy of latest SAP Build.

Note:-  APM10.8 SP1 is a cumulative service pack. SAP has its own release with no hotfix procedure.