- Revenera Community
- :
- FlexNet Publisher
- :
- FlexNet Publisher Knowledge Base
- :
- CVE-2021-44832 Log4j vulnerability impact on FlexNet Publisher
- Mark as New
- Mark as Read
- Subscribe
- Printer Friendly Page
- Report Inappropriate Content
CVE-2021-44832 Log4j vulnerability impact on FlexNet Publisher
CVE-2021-44832 Log4j vulnerability impact on FlexNet Publisher
Summary:
Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack where an attacker with permission to modify the logging configuration file can construct a malicious configuration using a JDBC Appender with a data source referencing a JNDI URI which can execute remote code. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.
Problem Description:
Upon analysis for the CVE-2021-44832 in FlexNet Publisher, it does not use any JNDI data source
Resolution:
FNP solution around log4j is not vulnerable to vulnerability CVE-2021-44832
- Mark as Read
- Mark as New
- Permalink
- Report Inappropriate Content
Hi,
Does this affect FNP running in Linux OS server. I'm on version 11.19.0.0.
- Mark as Read
- Mark as New
- Permalink
- Report Inappropriate Content
Hi @rsaroeun FNP solution around log4j is not vulnerable to vulnerability CVE-2021-44832 so any version of FNP is not affected with this Vulnerability. However, my suggestion to use the latest version always.
Best Regards,
Mani.