Lucene search

K
ibmIBMA1680316198638EA55AFA837EE37AE44184E9B8BCA2B9FD668F06E417908DF87
HistoryJan 05, 2022 - 9:22 p.m.

Security Bulletin: Multiple vulnerabilities in Apache log4j affect the IBM WebSphere Application Server and IBM WebSphere Application Server Liberty which are bundled as part of IBM Cloud Pak for Applications(CVE-2021-4104, CVE-2021-45046)

2022-01-0521:22:54
www.ibm.com
18

0.974 High

EPSS

Percentile

99.9%

Summary

Multiple vulnerabilities in Apache log4j affect the IBM WebSphere Application Server and IBM WebSphere Application Server Liberty (CVE-2021-4104, CVE-2021-45046). Both the IBM WebSphere Application Server and IBM WebSphere Application Server Liberty products are bundled within IBM Cloud Pak for Applications. There is a vulnerability in the Apache log4j library used by IBM WebSphere Application Server in the Admin Console and UDDI Registry application and used by the IBM WebSphere Application Server Liberty for z/OS in features zosConnect-1.0 and zosConnect-1.2. This has been addressed in IBM WebSphere Application Server by removing log4j from the Admin Console and UDDI Registry application. This has been addressed in IBM WebSphere Application Server Liberty for z/OS by removing log4j from the zosConnect-1.0 and zosConnect-1.2 features.

Vulnerability Details

Refer to the security bulletin(s) listed in the Remediation/Fixes section

Affected Products and Versions

Principal Affected Product(s) and Version(s) Affected Product(s) and Version(s)
IBM Cloud Pak for Applications, 4.3

WebSphere Application Server Liberty

  • Continuous Deliver

WebSphere Application Server

  • 9.0
  • 8.5
  • 8.0
  • 7.0

Remediation/Fixes

Multiple vulnerabilities in Apache log4j affect the IBM WebSphere Application Server and IBM WebSphere Application Server Liberty (CVE-2021-4104, CVE-2021-45046)

Workarounds and Mitigations

None

CPENameOperatorVersion
ibm cloud pak for applicationseq4.3