Highlighted
New Member.
164 views

node.js included in installation package is vulnerable

The default LoadRunner installation contains Node.js in old version with high CVSS score and causes security scanners to report vulnerability. Paths: c:\program files (x86)\micro focus\loadrunner\bin\node_10_5_3_x64\node.exe c:\program files (x86)\micro focus\loadrunner\bin\truclient\node.exe Is the node.js in its version required for LoadRunner to function or can it be upgraded manually?
0 Likes
3 Replies
Highlighted
Super Contributor.. Super Contributor..
Super Contributor..

Re: node.js included in installation package is vulnerable

what version of LoadRunner?

 

Recommend you open as case the Micro Focus Support

0 Likes
Highlighted
New Member.

Re: node.js included in installation package is vulnerable

its latest 2020.

I tried to use Micro Focus Support, but they asked too many license questions which are not relevant to the problem. (I do not use Loadrunner, I am just admin, and my role is to keep environment up to date)
0 Likes
Highlighted
Micro Focus Expert
Micro Focus Expert

Re: node.js included in installation package is vulnerable

Hi @aqualit,

The Node.js versions are used with other components to provide functionalities in Load Runner. They will be upgraded in future releases. Consider backward compatibility is not guaranteed by Node.js versions, it's not recommended to upgrade them manually, which may cause unexpected result.

0 Likes
The opinions expressed above are the personal opinions of the authors, not of Micro Focus. By using this site, you accept the Terms of Use and Rules of Participation. Certain versions of content ("Material") accessible here may contain branding from Hewlett-Packard Company (now HP Inc.) and Hewlett Packard Enterprise Company. As of September 1, 2017, the Material is now offered by Micro Focus, a separately owned and operated company. Any reference to the HP and Hewlett Packard Enterprise/HPE marks is historical in nature, and the HP and Hewlett Packard Enterprise/HPE marks are the property of their respective owners.