Summary
A vulnerability identified as CVE-2021-44228 and CVE-2021-45105 has been reported in the Apache Log4j library. This vulnerability may allow for remote code execution in susceptible products.
Problem Description
Upon analysis, CVE-2021-44228 and CVE-2021-45105 have been determined to impact the optional part of alerter module under examples with the (FlexNet Publisher 64-bit License Server Manager) lmadmin.
Resolution
IMPORTANT: FlexNet Publisher is not vulnerable to log4j vulnerability. It is just used in the example. Customers can also modify on their own.
Log4j version has been upgraded to 2.17.0 and an updated version of FlexNet Publisher 11.18.3.1 is now available in the Product and License Center.
Workaround
For older versions of FlexNet Publisher other than 11.18.3.1, you can follow this workaround.
- Download the latest version of log Log4j, like 2.15 or 2.16 or 2.17, and then replace each of the files in this path with its corresponding updated file:
C:\Program Files\FlexNet Publisher 64-bit License Server Manager\examples\alerter\lib - Replace these files:
log4j-1.2-api-2.13.3.jarlog4j-api-2.13.3.jarlog4j-core-2.13.3.jar
with these files:log4j-1.2-api-2.16.0.jarlog4j-api-2.16.0.jarlog4j-core-2.16.0.jar
or these files:log4j-1.2-api-2.17.0.jarlog4j-api-2.17.0.jarlog4j-core-2.17.0.jar
Related Articles
Vulnerability: CVE-2021-44832 Log4j vulnerability impact on FlexNet Publisher 20Number of Views CVE-2021-45046: Log4j vulnerability impact on FlexNet Publisher? 6Number of Views INDEX: Log4j vulnerability impact on FlexNet Publisher 9Number of Views CVE-2021-44832 Log4j vulnerability impact on FlexNet Publisher 11Number of Views CVE-2021-44228: Log4j Vulnerability Impact on FlexNet Operations On-Premises 8Number of Views
Hi, I am Reva - Ask me anything.
No new updates
Thanks for the feedback!
Your feedback has been saved.Rate this response:
Add Additional feedback ( Optional )
Are you sure you want to cancel
the case creation?
Are you sure you want to cancel the case creation?
Are you sure you want to close this case
| Products | Region | Phone Numbers |
|---|---|---|
| FlexNet Operations FlexNet Embedded FlexNet Publisher FlexNet Connect FlexNet Code Insight InstallAnywhere InstallShield |
North America * |
+1 630-332-2513 (toll) +1 877-279-2853 (toll-free in North America) |
| Europe * |
+44 1925 944367 (toll) +44 800 047 8642 (toll-free in Europe) |
|
| Japan * | +81 3-4540-5335 (select option 2) | |
| Australia * |
+61 3 9895 2177 +61 1800 560 603 (toll-free in Australia) |
|
|
Usage Intelligence (formerly
Revulytics) Compliance Intelligence |
Please use the Case Portal to submit your support ticket or reach out to your Revenera contact. | |
Case id: 00001065
Activity: Status change: 2 hours ago