Security check - CVE-2021-44228
![]()
Ivica Simic (51●3)
| asked Dec 11 '21, 10:34 a.m.
edited Dec 17 '21, 8:23 a.m. by Ralph Schoon (60.5k●3●36●43) Is CLM affected by this CVE-2021-44228, it scored 10. |
5 answers
![]()
Ralph Schoon (60.5k●3●36●43)
| answered Dec 11 '21, 2:58 p.m.
FORUM ADMINISTRATOR / FORUM MODERATOR / JAZZ DEVELOPER edited Dec 11 '21, 3:00 p.m. IBM is actively monitoring this kind of stuff and is announcing security issues with products as soon as possible.
A forum like this forum is NOT a safe place to get this kind of information. I could answer there is no issue completely unaware what this is about.
ELM uses log4j, but I do not have the knowledge or the capability to answer if the server are affected. Apparently the attacker has to be able to create certain names that are then used in the logs. Not sure they can enforce that. Wait for the IBM CERT team to assess this.
|
![]()
Ivica,
It seems that this issues is not relevant to all ELM Apps as the log4j used on the platform is 1.2 version and affected log4j is version =>2.
Only application that seems to be impacted is DNG that is using loggers in v2.
|
![]() Please be aware before You will install any patches or make actions that 2.15 is affected as well. |
![]()
The official status is described at https://www.ibm.com/blogs/psirt/an-update-on-the-apache-log4j-cve-2021-44228-vulnerability/?_ga=2.50033510.1513919312.1639386197-2119267424.1628078537
Jazz developers, please do not make any statements regarding this - the information must only come from the official IBM PSIRT channels.
|