We're reclaiming inactive PDIs to keep them available for active builders. Learn what's changing, who's affected, and how to protect your work. Read More

Handling OpenSSL Vulnerability in ServiceNow ACC

PaulMcD
Tera Contributor

Question on the critical vulnerability in the ServiceNow Agent Client Collector (ACC) related to its use of an outdated OpenSSL version (1.0.2zg). We are currently on ACC version 3.4.0, and I’ve seen that version 3.5.0 still embeds this older OpenSSL.

 

How are others addressing this issue? Has anyone found a workaround or received updates from ServiceNow about a patch or new release?

 

Any insights would be greatly appreciated!

 

Paul

2 REPLIES 2

Severin Launiau
Giga Guru

@PaulMcD: the OpenSSL bundled with ACC package is only used by external checks - not by ACC itself. You can generate an SBOM on the agent and see the binary carries the golang static libraries.

I believe ACC uses OpenSSL if using mTLS auth between the Agent and the MID, or between the Agent and MID-Less (ITOM Cloud services and/or DEX)