Jan 03, 2022
12:02 PM
1 Kudo
@scott_alexande - This is possible by following the "offline synchronization" steps described on page 25 of the Data Platform Administrator Guide: https://docs.flexera.com/dataplatform55/Data_Platform_Administrator_Guide_5.5_e.pdf
... View more
Dec 30, 2021
12:49 PM
2 Kudos
Summary
A vulnerability has been publicly disclosed in Apache Log4j 1.2. The vulnerability has been assigned the identifier CVE-2021-4104 with a CVSS score of “High”.
All versions of Data Platform include Log4j 1.2 components, and thus are potentially exposed to this vulnerability. This article describes the potential impact of the vulnerability on Data Platform and options for mitigation.
Vulnerability description
The National Vulnerability Database describes the CVE-2021-4104 vulnerability at https://nvd.nist.gov/vuln/detail/CVE-2021-4104 as follows (current as of Dec 30, 2021):
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-44228. Note this issue only affects Log4j 1.2 when specifically configured to use JMSAppender, which is not the default.
The default configuration of Data Platform does not meet the preconditions described for the vulnerability to be exploited.
Mitigation options
The following steps should be taken on all computers on which Data Platform components are installed:
The following mitigation advised by Apache is appropriate to follow:
Audit your logging configuration to ensure it has no JMSAppender configured.
Logging configuration is stored in files named log4j.xml. Such configuration would be highly unusual for a Data Platform installation, and would only appear if a non-default configuration has been applied.
Ensure appropriate access controls are in place to ensure only authorized users have access to computers. (This is appropriate to do regardless of the impact from Log4j vulnerabilities.)
Upgrade to the Data Platform 5.5.48 release (or later). Out of an abundance of caution, Flexera has upgraded some of the Log4j components in this release of Data Platform to version 2.17.0 that is not exposed to currently disclosed vulnerabilities.
Steps to upgrade Data Platform
Perform the following steps to upgrade to the latest version of Data Platform. This is the typical upgrade process used for regular monthly releases, as documented in the Data Platform Release Notes.
Verify that a notice indicating a new Patch Set is now available is shown in the Data Platform Admin Console after a catalog sync.
Click the Details link to invoke the Patch Set deployment dialog. Ensure the Patch Set version shown is 5.5.48 (or newer).
Click the APPLY button to start the Patch Set installation.
Patch Set installation typically takes around 15 minutes. You may see an authentication dialog appear due to services restarting, which is normal. In this case, close your browser window, wait 10-15 minutes, then try logging back into the Admin Console.
The New Patch Set Available banner will no longer be displayed when installation is completed.
Related information
Also see the following pages:
CVE definition: https://nvd.nist.gov/vuln/detail/CVE-2021-4104
Expanded CVE definition: https://www.cve.org/CVERecord?id=CVE-2021-4104
Apache Log4j Security Vulnerabilities page: https://logging.apache.org/log4j/2.x/security.html
Changelog
2021-12-30 12:53 PM CST: Initial article.
2022-01-03 7:50 PM CST: Add link to Data Platform 5.5.48 release notification.
2022-02-01 11:20 PM CST: Update to clarify that not all instances of the Log4j component have been updated in the Data Platform 5.5.48 release.
... View more
Dec 17, 2020
07:12 PM
2 Kudos
Yes it will. We run the same agent code inside containers, that we do outside.
... View more
May 13, 2020
10:42 AM
I would like to dig into this a bit. Where in the product are you seeing this? Is it possible for you to send us a log from the agent (using the logging options -c -v -v -v ).
Thanks,
Mike Marino
... View more
Nov 15, 2019
08:30 AM
1 Kudo
Try this:
https://api.app.flexerasoftware.com/api/advisories/SA92130/
Thanks,
Mike
... View more
Sep 10, 2012
04:49 PM
Our activation server experienced an outage. It should be working now.
... View more
Jul 19, 2012
10:12 PM
This error: An invalid condition was encoutered Type: ASSuiteIISCheck:GetAS11ProductionLocation Conversion: Compare: Error: 0x80004005 The setup will abort Has been correct with the Compatibility Solver installation. If you download the latest version from the Flexera Product and License center you should be good to go.
... View more
Aug 24, 2011
09:31 AM
Yes, installation streaming is available in the evaluation of the Premier edition of InstallShield 2012.
... View more
May 17, 2011
05:03 PM
Try this... Get regtypelib.exe from... http://kb.flexerasoftware.com/selfservice/microsites/search.do?cmd=displayKC&docType=kc&externalId=Q109148&sliceId=1&docTypeID=DT_ERRDOC_1_1&dialogID=109573353&stateId=0 0 109571232 Then register C:\Program Files (x86)\Common Files\InstallShield\Shared\ISWrkSpaceMgr.tlb and C:\Program Files (x86)\Common Files\InstallShield\Shared\Ismauto.tlb And see if that helps. (Note "C:\Program Files (x86)" will be "C:\Program Files" on a 32 bit machine) If not, look in the folder C:\Program Files (x86)\InstallShield\2011\System and see if there is a file called iside.log. If there is please attach it to a post (or email it to me at mmarino@flexerasoftware.com)
... View more
May 13, 2011
10:49 AM
I would try to run a repair of InstallShield and see if that helps.
... View more
May 12, 2011
03:50 PM
Do you have a beta of IE 9 installed? If not what version of IE are you using?
... View more
Nov 08, 2010
10:27 AM
Are you running a IE 9 beta on the machine?
... View more
Sep 09, 2010
11:11 AM
Are you using a SPC or PFX file for the signing? We use slightly different methods to set the password in these cases. Generally PFX works better. The method we use for setting the password for SPC files attempts to find the password dialog and put the password in it, then click OK on the dialog. It is possible we are failing to find the password dialog in your case. If you are not using a PFX, you may want to switch to one.
... View more
Sep 07, 2010
10:03 AM
Can you try the hotfix posted at: http://community.flexerasoftware.com/showthread.php?t=194643 Then re-enter your passwords in the release view. Thanks, Mike
... View more
Aug 26, 2010
10:44 AM
Is it consistently failing with one particular solution? If so, would it be possible for me to get the failing solution to look at on my end? You can email me directly at: mmarino@flexerasoftware.com Thanks, Mike
... View more
Latest posts by Mike_Marino
Subject | Views | Posted |
---|---|---|
1576 | Jan 03, 2022 12:02 PM | |
2854 | Dec 30, 2021 12:49 PM | |
7619 | Dec 17, 2020 07:12 PM | |
1085 | May 13, 2020 10:42 AM | |
1510 | Nov 15, 2019 08:30 AM | |
1424 | Sep 10, 2012 04:49 PM | |
1925 | Jul 19, 2012 10:12 PM | |
1501 | Aug 24, 2011 09:31 AM | |
2869 | May 17, 2011 05:03 PM | |
2869 | May 13, 2011 10:49 AM |
Activity Feed
- Got a Kudo for Re: Potential exposure to Log4j vulnerability CVE-2021-4104 in Data Platform versions 5.5.47 and earlier. Jan 05, 2022 09:33 AM
- Got a Kudo for Data Platform mitigation for Apache Log4j 1.2 vulnerability CVE-2021-4104. Jan 03, 2022 04:33 PM
- Posted Re: Potential exposure to Log4j vulnerability CVE-2021-4104 in Data Platform versions 5.5.47 and earlier on Data Platform Release Blog. Jan 03, 2022 12:02 PM
- Got a Kudo for Data Platform mitigation for Apache Log4j 1.2 vulnerability CVE-2021-4104. Dec 30, 2021 01:01 PM
- Posted Data Platform mitigation for Apache Log4j 1.2 vulnerability CVE-2021-4104 on Data Platform Release Blog. Dec 30, 2021 12:49 PM
- Kudoed Flexera’s response to Apache Log4j vulnerabilities CVE-2021-4104, CVE-2021-45046, CVE-2021-45105 and CVE-2021-44228 for dosborn. Dec 14, 2021 07:18 PM
- Got a Kudo for Re: Discovery and Inventory of Docker Containers in Flexnet Manager Suite 2020 R1. Dec 17, 2020 07:46 PM
- Got a Kudo for Re: Discovery and Inventory of Docker Containers in Flexnet Manager Suite 2020 R1. Dec 17, 2020 07:33 PM
- Posted Re: Discovery and Inventory of Docker Containers in Flexnet Manager Suite 2020 R1 on FlexNet Manager Blog. Dec 17, 2020 07:12 PM
- Kudoed Upcoming Changes in the Tracking of the "Microsoft Edge" Product (June 2nd, 2020) for bkelly. May 19, 2020 08:25 AM
- Kudoed Re: Upcoming Changes in the Tracking of the "Microsoft Edge" Product (June 2nd, 2020) for Shoggi. May 19, 2020 08:25 AM
- Posted Re: false/positive vulnerabilities on Software Vulnerability Management Forum. May 13, 2020 10:42 AM
- Got a Kudo for Re: Advisory Details via API Explorer. Nov 15, 2019 09:25 AM
- Posted Re: Advisory Details via API Explorer on Software Vulnerability Management Forum. Nov 15, 2019 08:30 AM
- Kudoed Introducing the Vendor Patch Module for bkelly. Jul 24, 2019 03:37 PM
- Posted Re: Offline Activation Fails on InstallShield Forum. Sep 10, 2012 04:49 PM
- Posted Re: Installation Compatibility Solver and AdminStudio 11.5 on AdminStudio Forum. Jul 19, 2012 10:12 PM
- Posted Re: Is 2012 on InstallShield Forum. Aug 24, 2011 09:31 AM
- Posted Re: IS2011 "Hotfix A" breaks InstallShield IDE on InstallShield Forum. May 17, 2011 05:03 PM
- Posted Re: IS2011 "Hotfix A" breaks InstallShield IDE on InstallShield Forum. May 13, 2011 10:49 AM