Summary
A vulnerability identified as CVE-2021-44228 has been reported in the Apache Log4j library. This vulnerability may allow for remote code execution in susceptible products.
Problem Description
Upon analysis, CVE-2021-44228 has been determined to impact the core module of FlexNet Operations On-Premises.
Resolution
A hotfix for FlexNet Operations On-Premises 2021 R1 is available for download from the Product and License Center. (Note: A community login with Product and License Center is required.)
We advise customers on earlier versions of FlexNet Operations On-Premises, who cannot upgrade to FlexNet Operations On-Premises 2021 R1, to use the mitigation steps described in the 'Workaround' section.
Workaround
At this time, we discourage customers from upgrading Log4j files to a later Log4j version. Doing so may result in runtime problems or unexpected issues.
Until the new FlexNet Operations On-Premises patch can be delivered, we advise customers to remove the JndiLookup.class from the classpath using the platform-specific instructions below:
For Windows
- Stop the server.
- Rename the "log4j-core-2.*.jar"to"log4j-core-2.*.jar.zip" to enable Windows Explorer to Open the file. (Note: FlexNet Operations On-Premises has 10 log4j-core files with version 2.8)
- Drill-down into the "log4j-core-2.*.jar.zip" using Windows Explorer to select the "org/apache/logging/log4j/core/lookup/JndiLookup.class".
- Delete the "JndiLookup.class" by right-clicking to select "Delete" from the Context-menu.
- Click "Yes" on the "Delete File" dialog and the JndiLookup.class will be deleted from the selected "log4j-core-2.*.jar.zip".
- Rename the "log4j-core-2.*.jar.zip" back to "log4j-core-2.*.jar".
- Start the server.
For Linux
Locate the log4j-core files using the command below:
find <path to deployment root> -name log4j-core-*.jar
e.g. find /root/FlexNet-Operations/ -name log4j-core-*.jar
Delete the JndiLookup.class file from all located log4j-core.jar files using the command below:
zip -q -d ./components/wildfly/standalone/deployments/flexnet.ear/flexnet-data/site/reporting/talend/lib/log4j-core-2.8.2.jar org/apache/logging/log4j/core/lookup/JndiLookup.class
Additional Information
- CVE Definition: https://nvd.nist.gov/vuln/detail/CVE-2021-44228
- Expanded CVE Definition: https://www.cve.org/CVERecord?id=CVE-2021-44228
- Apache Security Site for CVE severity, score, and vector string: https://logging.apache.org/log4j/2.x/security.html
Related Articles
FAQs: FlexNet Operations Software Delivery (ESD) – FTP/SFTP File Uploads 14Number of Views Date Discrepancy with Entitlement Data Extracts using 'Data Import Template' option 4Number of Views Is there a merge tag for Maintenance End Date available? 3Number of Views Can 'Data Import Template' be used to REPLACE the roles of users? 4Number of Views Why do End User/Portal User roles have Producer Portal permissions? 9Number of Views
Hi, I am Reva - Ask me anything.
No new updates
Thanks for the feedback!
Your feedback has been saved.Rate this response:
Add Additional feedback ( Optional )
Are you sure you want to cancel
the case creation?
Are you sure you want to cancel the case creation?
Are you sure you want to close this case
| Products | Region | Phone Numbers |
|---|---|---|
| FlexNet Operations FlexNet Embedded FlexNet Publisher FlexNet Connect FlexNet Code Insight InstallAnywhere InstallShield |
North America * |
+1 630-332-2513 (toll) +1 877-279-2853 (toll-free in North America) |
| Europe * |
+44 1925 944367 (toll) +44 800 047 8642 (toll-free in Europe) |
|
| Japan * | +81 3-4540-5335 (select option 2) | |
| Australia * |
+61 3 9895 2177 +61 1800 560 603 (toll-free in Australia) |
|
|
Usage Intelligence (formerly
Revulytics) Compliance Intelligence |
Please use the Case Portal to submit your support ticket or reach out to your Revenera contact. | |
Revenera Assistant
Case id: 00001065
Activity: Status change: 2 hours ago