Lucene search

K
ibmIBM73EAFB98AF656367DD4CBD6C4D9BDB98FBF39B358F625D93589F37D52771AA8D
HistoryJan 10, 2022 - 6:33 p.m.

Security Bulletin: IBM Tivoli Federated Identity Manager is vulnerable to arbitrary code execution due to Apache Log4j (CVE-2021-4104,  CVE-2021-45046)

2022-01-1018:33:41
www.ibm.com
190

0.974 High

EPSS

Percentile

99.9%

Summary

IBM WebSphere Application Server is shipped with IBM Tivoli Federated Identity Manager. Information about security vulnerabilities (CVE-2021-4104, CVE-2021-45046) affecting IBM WebSphere Application Server have been published in a security bulletin.

Vulnerability Details

Refer to the security bulletin(s) listed in the Remediation/Fixes section

Affected Products and Versions

Affected Product(s) Version(s)
IBM Tivoli Federated Identity Manager 6.2.0 - 6.2.2

Remediation/Fixes

IBM strongly recommends addressing the vulnerability now by upgrading. Refer to the following security bulletins for vulnerability details and information about fixes addressed by IBM WebSphere Application Server which is/are shipped with IBM Tivoli Federated Identity Manager.

Principal Product and Version(s)

|

Affected Supporting Product and Version

|

Affected Supporting Product Security Bulletin

—|—|—
IBM Tivoli Federated Identity Manager 6.2.0 - 6.2.2| IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0|

Security Bulletin: Multiple vulnerabilities in Apache log4j affect the IBM WebSphere Application Server and IBM WebSphere Application Server Liberty (CVE-2021-4104, CVE-2021-45046)

Workarounds and Mitigations

None