Summary
A vulnerability identified as CVE-2021-44228 has been reported in the Apache Log4j library. This vulnerability may allow for remote code execution in susceptible products.
Problem Description
Upon analysis, CVE-2021-44228 has been determined to impact the optional FlexNet License Server Manager (FLSM) component packaged with the FlexNet Embedded local license server.
Resolution
Revenera has provided a FlexNet Embedded 2021.12 local license server that does not contain the FlexNet License Server Manager component. This updated package is available for download on the Product and License Center.
Note: You must have permission to access the Product and License Center. This would be granted to you by either Revenera or by your company's administrator.
A separate FlexNet License Server Manager (FLSM) package that does not use the vulnerable Log4j component is available for download from the Product and License Center. The package files are:
| For Windows | For Linux |
|---|---|
| flexnet-flsm-windows-2021.12.2.zip | flexnet-flsm-linux-2021.12.2.tar.gz |
Workaround
We advise customers to temporarily cease using the FlexNet License Server Manager until the new package is available. However, customers who wish to continue using the FlexNet License Server Manager may mitigate risk by including Dlog4j2.formatMsgNoLookups=true to JAVA_OPTS environment variable in Tomcat CATALINA_HOME/bin directory:
| Operating System | Directions |
|---|---|
| Windows |
Edit setenv.bat and append "-Dlog4j2.formatMsgNoLookups=true" if exists. If it doesn't exist, create new file and add set JAVA_OPTS="-Dlog4j2.formatMsgNoLookups=true" |
| Linux |
Edit setenv.sh in CATALINA_HOME/bin and append "-Dlog4j2.formatMsgNoLookups=true" if exists If this doesn't exist, create a new file and add export JAVA_OPTS="-Dlog4j2.formatMsgNoLookups=true" |
Additional Information
- CVE Definition: https://nvd.nist.gov/vuln/detail/CVE-2021-44228
- Expanded CVE Definition: https://www.cve.org/CVERecord?id=CVE-2021-44228
- Apache Security Site for CVE severity, score, and vector string: https://logging.apache.org/log4j/2.x/security.html
Related Articles
Log4j Vulnerability Impact on FlexNet Embedded (CVE-2021-4104) 14Number of Views INDEX: Log4j vulnerability impact on FlexNet Embedded 17Number of Views CVE-2019-17571: Log4j vulnerability impact on FlexNet Embedded 5Number of Views CVE-2025-15467 Impact Assessment for FlexNet Embedded 6Number of Views Vulnerability: CVE-2021-44832 Log4j vulnerability impact on FlexNet Publisher 20Number of Views
Hi, I am Reva - Ask me anything.
No new updates
Thanks for the feedback!
Your feedback has been saved.Rate this response:
Add Additional feedback ( Optional )
Are you sure you want to cancel
the case creation?
Are you sure you want to cancel the case creation?
Are you sure you want to close this case
| Products | Region | Phone Numbers |
|---|---|---|
| FlexNet Operations FlexNet Embedded FlexNet Publisher FlexNet Connect FlexNet Code Insight InstallAnywhere InstallShield |
North America * |
+1 630-332-2513 (toll) +1 877-279-2853 (toll-free in North America) |
| Europe * |
+44 1925 944367 (toll) +44 800 047 8642 (toll-free in Europe) |
|
| Japan * | +81 3-4540-5335 (select option 2) | |
| Australia * |
+61 3 9895 2177 +61 1800 560 603 (toll-free in Australia) |
|
|
Usage Intelligence (formerly
Revulytics) Compliance Intelligence |
Please use the Case Portal to submit your support ticket or reach out to your Revenera contact. | |
Case id: 00001065
Activity: Status change: 2 hours ago