Summary
A vulnerability identified as CVE-2021-44228 has been reported in the Apache Log4j library. This vulnerability may allow for remote code execution in susceptible products.
Applies To
InstallAnywhere 2018
Description
If you are using any version of InstallAnywhere other than the above, you are not impacted and you can choose to skip the rest of the article.
NOTE: Installers built out of InstallAnywhere (any versions) do not have the Log4j 2 library, therefore they are not impacted.
InstallAnywhere 2018 contains the library Log4j 2x by virtue of an additional module – Code Aware which is used to scan for Open-Source components included in your project. This is a separate menu item in Build menu which invokes a wizard for scanning. This module must be explicitly invoked and is not automatically invoked during launch of InstallAnywhere or building projects using IDE or Standalone Build. However, in our analysis, we concluded that the Log4j 2x library included in Code Aware is NOT actually used and Code Aware uses SLF4 logging, which in turn points to and uses native implementation of logback library.
This file is available only in InstallAnywhere 2018 Windows installer.
Bottom line, even InstallAnywhere 2018 is also NOT impacted by the said vulnerability. However, depending on your corporate security policies, you may consider the existence of the Log4j 2x file as a risk and this article outlines steps to remove Code Aware from your machines.
Resolution
No fix is required.
Workaround
Code Aware is not tightly coupled to the product and is not automatically invoked during the launch of InstallAnywhere. Also Code Aware is not a separate installer on the machine. The files can be deleted from InstallAnywhere home directory.
Remediation Steps for InstallAnywhere 2018
- Navigate to the InstallAnywhere 2018 installation directory:
C:\Program Files (x86)\InstallAnywhere 2018. - Delete the directory
FlexNet Code Aware.
Related Articles
CVE-2021-44228: Log4j Vulnerability Impact on FlexNet Operations On-Premises 8Number of Views CVE-2021-44228: Log4j Vulnerability Impact on Code Insight 10Number of Views CVE-2021-44228: Log4j vulnerability impact on InstallShield 8Number of Views CVE-2021-44228: Log4j vulnerability impact on FlexNet Embedded 20Number of Views CVE-2021-44228: Log4j vulnerability impact on Standalone Code Aware 16Number of Views
Hi, I am Reva - Ask me anything.
No new updates
Thanks for the feedback!
Your feedback has been saved.Rate this response:
Add Additional feedback ( Optional )
Are you sure you want to cancel
the case creation?
Are you sure you want to cancel the case creation?
Are you sure you want to close this case
| Products | Region | Phone Numbers |
|---|---|---|
| FlexNet Operations FlexNet Embedded FlexNet Publisher FlexNet Connect FlexNet Code Insight InstallAnywhere InstallShield |
North America * |
+1 630-332-2513 (toll) +1 877-279-2853 (toll-free in North America) |
| Europe * |
+44 1925 944367 (toll) +44 800 047 8642 (toll-free in Europe) |
|
| Japan * | +81 3-4540-5335 (select option 2) | |
| Australia * |
+61 3 9895 2177 +61 1800 560 603 (toll-free in Australia) |
|
|
Usage Intelligence (formerly
Revulytics) Compliance Intelligence |
Please use the Case Portal to submit your support ticket or reach out to your Revenera contact. | |
Revenera Assistant
Case id: 00001065
Activity: Status change: 2 hours ago