Lucene search

K
ibmIBM2709A19D29B9047D230E570EBF5F26A53D322D557D88CBCFB480F1AFEEF6797C
HistoryJan 07, 2022 - 4:23 p.m.

Security Bulletin: Vulnerability in Apache Log4j addressed in IBM Spectrum Conductor

2022-01-0716:23:40
www.ibm.com
79
log4j
ibm spectrum conductor
vulnerability
log4shell
cve-2021-44228
apache
jndi
remediation
patches

EPSS

0.965

Percentile

99.6%

Summary

Log4j is used by IBM Spectrum Conductor for generating logs in some of its components. This bulletin provides patches for the Log4Shell vulnaribility (CVE-2021-44228) to IBM Spectrum Conductor.

Vulnerability Details

CVEID:CVE-2021-44228
**DESCRIPTION:**Apache Log4j could allow a remote attacker to execute arbitrary code on the system, caused by the failure to protect against attacker controlled LDAP and other JNDI related endpoints by JNDI features. By sending a specially crafted code string, an attacker could exploit this vulnerability to load arbitrary Java code on the server and take complete control of the system. Note: The vulnerability is also called Log4Shell or LogJam.
CVSS Base score: 10
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/214921 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Spectrum Conductor 2.4.1
IBM Spectrum Conductor 2.5.0
IBM Spectrum Conductor 2.5.1

Remediation/Fixes

Products VRMF APAR Remediation/First Fix
IBM Spectrum Conductor 2.4.1 P104516

sc-2.4.1-build600955

IBM Spectrum Conductor| 2.5.0| P104513|

sc-2.5-build600954

IBM Spectrum Conductor| 2.5.1| P104512|

sc-2.5.1-build600953

Workarounds and Mitigations

None