
Revenera Company News — cvirata (Flexera Software)
Security Advisory: Log4j Java Vulnerability (CVE-2021-4104, CVE-2021-45046, CVE-2021-44228) UPDATE: Revenera’s response to Apache Log4j vulnerabilities CVE-2021-45105, CVE-2021-45046, CVE-2021-44228, and CVE-2021-4104(as of 14-Jan 10:20 CST)A critical vulnerability in Apache Log4j 2 impacting versions from 2.0-beta9 to 2.14.1 has been publicly disclosed. The vulnerability has been assigned the identifier CVE-2021-44228 .Revenera is expanding its product impact assessment and mitigation information to include CVE-2021-45105 , CVE-2021-45046 , CVE-2021-44228 , and CVE-2021-4104 . This notice provides currently available information about the potential impact of these vulnerabilities on Revenera products. NOTE: Be advised this is an ongoing assessment. Information about related and subsequent Log4j CVEs not listed below may be found in the product's respective knowledge base. Information about Flexera products: Flexera’s response to Apache Log4j remote code execution vulnerability CVE-2021-4104, CVE-2021-45046 and CVE-2021-44228 Revenera Product AssessmentProductPotential Exposure to CVE-2021-44228Potential Exposure to CVE-2021-45105, CVE-2021-45046Potential Exposure to CVE-2021-4104Potentially Exposed Components or VersionsFixed VersionMitigationInstallShieldNoNoNoN/AN/AKB Article InstallAnywhereNoNoNoN/AN/AKB Article Code InsightNoNoNoN/AN/AKB Article Code Aware (independent of Code Insight)NoNoNoN/AN/AKB Article FlexNet Operations Cloud ALM YesYesYesRevenera managed services:Core moduleUpdates and InsightsData Access APIsCVE-2021-44228, CVE-2021-45105, CVE-2021-45046, CVE-2021-4104: 2022.02UAT: Upgraded to Log4j 2.17.0 (22-Dec)PROD: Upgraded to Log4j 2.17.0 (23-Dec)FlexNet Operations Cloud LLM NoNoYesCore moduleCVE-2021-4104: 2022.02 FlexNet Operations On-Premises YesYesYesCore moduleCVE-2021-44228, CVE-2021-45105, CVE-2021-45046: 2021 R1 HotfixCVE-2021-4104: PendingCVE-2021-44228, CVE-2021-45105, CVE-2021-45046 FlexNet Embedded YesYesYesFlexNet License Server Manager (FLSM)CVE-2021-44228, CVE-2021-45105, CVE-2021-45046: 2021.12.2 (or later)CVE-2021-44228, CVE-2021-45105, CVE-2021-45046 CVE-2021-4104 FlexNet Publisher YesYesNo2021 R4 (11.18.3.0), only when using lmadmin alerts example code2021 R4 SP1 (11.18.3.1)CVE-2021-44228, CVE-2021-45105, CVE-2021-45046 FlexNet ConnectNoNoNoN/AN/AKB Article Usage IntelligenceYesYesNoJava SDK5.6.1CVE-2021-44228, CVE-2021-45105, CVE-2021-45046 Compliance IntelligenceYesYesNoRDS (Revenera managed service)PROD: Upgraded to Log4j 2.17.0 (20-Dec)N/A Related Information:Apache Security Site for CVE severity, score, and vector string: https://logging.apache.org/log4j/2.x/security.html CVE-2021-44228:CVE Definitions: https://nvd.nist.gov/vuln/detail/CVE-2021-44228 Expanded CVE Definitions: https://www.cve.org/CVERecord?id=CVE-2021-44228 CVE-2021-4104:CVE Definitions: https://nvd.nist.gov/vuln/detail/CVE-2021-4104 Expanded CVE Definitions: https://www.cve.org/CVERecord?id=CVE-2021-4104 CVE-2021-45046:CVE Definitions: https://nvd.nist.gov/vuln/detail/CVE-2021-45046 Expanded CVE Definitions: https://www.cve.org/CVERecord?id=CVE-2021-45046 CVE-2021-45105:CVE Definitions: https://nvd.nist.gov/vuln/detail/CVE-2021-45105 Expanded CVE Definitions: https://www.cve.org/CVERecord?id=CVE-2021-45105 Change Log2022-01-14 10:20 CST: Updated FNO impact assessment and added index link to related CVEs.2022-01-10 12:28 CST: Added KB link to F
Hi,
Is there any update on this please ?
Thanks,
UZI HABAZ
Delivery Infrastructure Expert(T) +972 (9) 775-2425
(M)+972 (522)-434419uzi.habaz@nice.com
www.nice.comOur current mitigation strategy for this has been to put a complete block on ALL outgoing network access from our FNO server, with a specific exemption for SMTP access to our mail server. So, no http to google, no ntp, etc.
Given that this is a single-purpose server, are there any other outgoing connections that an FNO server might need to have whitelisted?
can you please let us know affecting products, we are using Installshield and Installanywhere .
Hi,
Can we please get an update to this advisory and details on all affected products, is Code Insight impacted?
Thanks,
Hello, We would also like to know if Code Insight is impacted.
@jefflaing If you block outgoing connections, in the long term it could be great if FNO gets it license renewed from Flexera servers.
Hi,
looks like if the local license server (FlexNet Embedded) uses the log4j libraries. Even in the latest version of the lls:
Could we please get an update if InstallAnywhere and InstallShield packaged product is vulnerable.
@maxhenselnonse :
To me this looks like version 1.2.17 is used for the FNE LLS. But according to the CVE only versions from 2.0 to 2.14.1 are affected? Can someone confirm this?Hi all, When I check our Code Insight installation I see log4j-core 2.11.1 in the tomcat directory (/tomcat/webapps/codeaware/WEB-INF/lib/log4j-core-2.11.1.jar) so I would presume it's used in our installation. Is there a good and advised way to mitigate this?