EWM/RTC 7.0.2 iFix003 - Log4j libraries reported as vulnerable after applying latest available fix
Hello everyone,
We are currently using IBM Engineering Workflow Management (RTC/EWM) 7.0.2 iFix003, which, as far as I know, is the latest available fix level for this release.
Our Information Security (CISO) team recently performed a vulnerability scan and reported that some Log4j libraries included with the product are still being identified as vulnerable. Specifically, they are requesting remediation to at least Apache Log4j 2.25.3 due to findings related to a Log4j vulnerability (reported by the scanning tool as "Apache Log4j 2.0-beta9 < 2.25.3 MitM").
The issue is that even after applying the latest available iFix, the scan still detects vulnerable Log4j JAR files within the EWM installation.
I would like to ask:
- Has anyone faced a similar situation with EWM/RTC 7.0.2?
- Is there any official IBM guidance regarding Log4j version upgrades beyond what is delivered in the latest iFix?
- Are the detected JARs actively used by the product, or could they be legacy/inactive libraries that trigger false positives in vulnerability scanners?
- Is there a recommended approach to address security findings when the product ships with older Log4j versions and no newer fix pack is available?
Any guidance, IBM technotes, APARs, or recommendations would be greatly appreciated.
Thank you in advance.
Best regards,
Sergio