Lucene search

K
ibmIBM1629CA1DFD389EEFF25556E8C9B707086E571E474449820E949D944C6EB994C3
HistoryDec 13, 2021 - 1:37 p.m.

Security Bulletin: IBM Security Verify Privilege Products NOT Affected by CVE-2021-44228 Exploit

2021-12-1313:37:26
www.ibm.com
172
ibm security verify
privilege products
cve-2021-44228
exploit
thycoticcentrify
java library
vulnerability
oem partner
remote
server suite

EPSS

0.965

Percentile

99.6%

Summary

IBM Security Verify Privilege Products NOT Affected by CVE-2021-44228 Exploit.

Vulnerability Details

OEM partner ThycoticCentrify, after conducting extensive research product code base, it is determined that none of the products outlined below are using the vulnerable Java library log4j with JNDI exploit (CVE-2021-44228). Additionally,none of the products outlined below are built on the Java programming language, preventing the library to be present.

  • IBM Security Verify Privilege Vault
  • IBM Security Verify Privilege Manager
  • IBM Security Verify Privilege Account Lifecycle Manager
  • IBM Security Verify Privilege Behavior Analytics
  • IBM Security Verify Privilege DevOps Vault
  • IBM Security Verify Privilege Vault Remote
  • IBM Security Verify Privilege Server Suite