Loading
Security Advisory: Log4j Java Vulnerability (CVE-2021-4104, CVE-2021-45046, CVE-2021-44228) UPDATE: Revenera’s response to Apache Log4j vulnerabilities CVE-2021-45105, CVE-2021-45046, CVE-2021-44228, and CVE-2021-4104(as of 14-Jan 10:20 CST)A critical vulnerability in Apache Log4j 2 impacting versions from 2.0-beta9 to 2.14.1 has been publicly disclosed. The vulnerability has been assigned the identifier CVE-2021-44228 .Revenera is expanding its product impact assessment and mitigation information to include CVE-2021-45105 , CVE-2021-45046 , CVE-2021-44228 , and CVE-2021-4104 . This notice provides currently available information about the potential impact of these vulnerabilities on Revenera products.  NOTE: Be advised this is an ongoing assessment. Information about related and subsequent Log4j CVEs not listed below may be found in the product's respective knowledge base.  Information about Flexera products: Flexera’s response to Apache Log4j remote code execution vulnerability CVE-2021-4104, CVE-2021-45046 and CVE-2021-44228 Revenera Product AssessmentProductPotential Exposure to CVE-2021-44228Potential Exposure to CVE-2021-45105, CVE-2021-45046Potential Exposure to CVE-2021-4104Potentially Exposed Components or VersionsFixed VersionMitigationInstallShieldNoNoNoN/AN/AKB Article InstallAnywhereNoNoNoN/AN/AKB Article Code InsightNoNoNoN/AN/AKB Article Code Aware (independent of Code Insight)NoNoNoN/AN/AKB Article FlexNet Operations Cloud ALM YesYesYesRevenera managed services:Core moduleUpdates and InsightsData Access APIsCVE-2021-44228, CVE-2021-45105, CVE-2021-45046, CVE-2021-4104: 2022.02UAT: Upgraded to Log4j 2.17.0 (22-Dec)PROD: Upgraded to Log4j 2.17.0 (23-Dec)FlexNet Operations Cloud LLM NoNoYesCore moduleCVE-2021-4104: 2022.02 FlexNet Operations On-Premises YesYesYesCore moduleCVE-2021-44228, CVE-2021-45105, CVE-2021-45046: 2021 R1 HotfixCVE-2021-4104: PendingCVE-2021-44228, CVE-2021-45105, CVE-2021-45046 FlexNet Embedded YesYesYesFlexNet License Server Manager (FLSM)CVE-2021-44228, CVE-2021-45105, CVE-2021-45046: 2021.12.2 (or later)CVE-2021-44228, CVE-2021-45105, CVE-2021-45046 CVE-2021-4104  FlexNet Publisher YesYesNo2021 R4 (11.18.3.0), only when using lmadmin alerts example code2021 R4 SP1 (11.18.3.1)CVE-2021-44228, CVE-2021-45105, CVE-2021-45046 FlexNet ConnectNoNoNoN/AN/AKB Article Usage IntelligenceYesYesNoJava SDK5.6.1CVE-2021-44228, CVE-2021-45105, CVE-2021-45046 Compliance IntelligenceYesYesNoRDS (Revenera managed service)PROD: Upgraded to Log4j 2.17.0 (20-Dec)N/A Related Information:Apache Security Site for CVE severity, score, and vector string: https://logging.apache.org/log4j/2.x/security.html CVE-2021-44228:CVE Definitions: https://nvd.nist.gov/vuln/detail/CVE-2021-44228 Expanded CVE Definitions: https://www.cve.org/CVERecord?id=CVE-2021-44228 CVE-2021-4104:CVE Definitions: https://nvd.nist.gov/vuln/detail/CVE-2021-4104 Expanded CVE Definitions: https://www.cve.org/CVERecord?id=CVE-2021-4104 CVE-2021-45046:CVE Definitions: https://nvd.nist.gov/vuln/detail/CVE-2021-45046 Expanded CVE Definitions: https://www.cve.org/CVERecord?id=CVE-2021-45046 CVE-2021-45105:CVE Definitions: https://nvd.nist.gov/vuln/detail/CVE-2021-45105 Expanded CVE Definitions: https://www.cve.org/CVERecord?id=CVE-2021-45105 Change Log2022-01-14 10:20 CST: Updated FNO impact assessment and added index link to related CVEs.2022-01-10 12:28 CST: Added KB link to F

  • Our current mitigation strategy for this has been to put a complete block on ALL outgoing network access from our FNO server, with a specific exemption for SMTP access to our mail server.  So, no http to google, no ntp, etc.

    Given that this is a single-purpose server, are there any other outgoing connections that an FNO server might need to have whitelisted?

  • can you please let us know affecting products, we are using Installshield and Installanywhere .

  • Hi,

    Can we please get an update to this advisory and details on all affected products, is Code Insight impacted?

    Thanks, 

     

  • Hello, We would also like to know if Code Insight is impacted.

  • @jefflaing  If you block outgoing connections, in the long term it could be great if FNO gets it license renewed from Flexera servers. 

  • Hi,

    looks like if the local license server (FlexNet Embedded) uses the log4j libraries. Even in the latest version of the lls:

     

    log4j.JPG

    Expand Post
  • Could we please get an update if InstallAnywhere and InstallShield packaged product is vulnerable.

  • @maxhenselnonse :

     

    To me this looks like version 1.2.17 is used for the FNE LLS. But according to the CVE only versions from 2.0 to 2.14.1 are affected? Can someone confirm this?
  • Hi all, When I check our Code Insight installation I see log4j-core 2.11.1 in the tomcat directory (/tomcat/webapps/codeaware/WEB-INF/lib/log4j-core-2.11.1.jar) so I would presume it's used in our installation. Is there a good and advised way to mitigate this?

10 of 45

Loading
Feed Detail