Summary
A vulnerability identified as CVE-2021-4104 has been reported in the Apache Log4j library. Related vulnerabilities have also been identified as CVE-2022-23302, CVE-2022-23305, and CVE-2020-9488. This article addresses all three vulnerabilities.
Description
The Apache Log4j vulnerability referenced by the CVE identifier CVE-2021-4104 does not affect the License Server in its default behavior. This issue only affects if the license server logging is integrated with external systems using Log4J Socket Appender.
This integration is described in the FlexNet Embedded License Server Producer Guide (Appendix E) and the FlexNet Embedded License Server Administration Guide (Appendix D), under the section Integration of License Server Logging With External Systems.
NOTE: The license server is not configured to use this class as default, hence the license server is not affected by the vulnerabilities by default.
Similarly, CVE-2022-23302, CVE-2022-23305, and CVE-2020-9488 do not affect the License Server in its default configuration.
Resolution
Refrain from using Log4J Socket Appender as an external logging mechanism.
Additional Information
| CVE Number | CVE Definition | Expanded CVE Definition |
|---|---|---|
| CVE-2021-4104 | https://nvd.nist.gov/vuln/detail/CVE-2021-4104 | https://www.cve.org/CVERecord?id=CVE-2021-4104 |
| CVE-2022-23302 | https://nvd.nist.gov/vuln/detail/CVE-2022-23302 | https://www.cve.org/CVERecord?id=CVE-2022-23302 |
| CVE-2022-23305 | https://nvd.nist.gov/vuln/detail/CVE-2022-23305 | https://www.cve.org/CVERecord?id=CVE-2022-23305 |
| CVE-2020-9488 | https://nvd.nist.gov/vuln/detail/CVE-2020-9488 | https://www.cve.org/CVERecord?id=CVE-2020-9488 |
Related Articles
CVE-2021-44228: Log4j vulnerability impact on FlexNet Embedded 20Number of Views CVE-2019-17571: Log4j vulnerability impact on FlexNet Embedded 5Number of Views INDEX: Log4j vulnerability impact on FlexNet Embedded 17Number of Views CVE-2025-15467 Impact Assessment for FlexNet Embedded 6Number of Views Vulnerability: CVE-2021-44832 Log4j vulnerability impact on FlexNet Publisher 20Number of Views
Hi, I am Reva - Ask me anything.
No new updates
Thanks for the feedback!
Your feedback has been saved.Rate this response:
Add Additional feedback ( Optional )
Are you sure you want to cancel
the case creation?
Are you sure you want to cancel the case creation?
Are you sure you want to close this case
| Products | Region | Phone Numbers |
|---|---|---|
| FlexNet Operations FlexNet Embedded FlexNet Publisher FlexNet Connect FlexNet Code Insight InstallAnywhere InstallShield |
North America * |
+1 630-332-2513 (toll) +1 877-279-2853 (toll-free in North America) |
| Europe * |
+44 1925 944367 (toll) +44 800 047 8642 (toll-free in Europe) |
|
| Japan * | +81 3-4540-5335 (select option 2) | |
| Australia * |
+61 3 9895 2177 +61 1800 560 603 (toll-free in Australia) |
|
|
Usage Intelligence (formerly
Revulytics) Compliance Intelligence |
Please use the Case Portal to submit your support ticket or reach out to your Revenera contact. | |
Case id: 00001065
Activity: Status change: 2 hours ago