Lucene search

K
ibmIBMC7FAA00C9C125584B8B9505CE7E7AC97AF7514904E37D2747A78CB0B5B0F3315
HistoryJan 19, 2022 - 11:35 a.m.

Security Bulletin: Log4j vulnerability affects IBM Cloud Pak for Data System 2.0

2022-01-1911:35:02
www.ibm.com
80
log4j
ibm cloud pak
data system 2.0
openshift-logging
remote code execution
cve-2021-44228
apache log4j
vulnerability
remediation
fix
release notes

EPSS

0.967

Percentile

99.7%

Summary

Log4j is used by IBM Cloud Pak for Data System 2.0 in openshift-logging. This bulletin provides a remediation for the reported Apache Log4j vulnerability, CVE-2021-44228.

Vulnerability Details

CVEID:CVE-2021-44228
**DESCRIPTION:**Apache Log4j could allow a remote attacker to execute arbitrary code on the system, caused by the failure to protect against attacker controlled LDAP and other JNDI related endpoints by JNDI features. By sending a specially crafted code string, an attacker could exploit this vulnerability to load arbitrary Java code on the server and take complete control of the system. Note: The vulnerability is also called Log4Shell or LogJam.
CVSS Base score: 10
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/214921 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)

IBM Cloud Pak for Data System 2.0 -

Openshift Container Platform 4

| 2.0.0.0 - 2.0.1.1

Remediation/Fixes

**IBM strongly recommends addressing the vulnerabilities now by applying following remediation **

Product VRMF Remediation / Fix

IBM Cloud Pak for Data System 2.0 - Openshift Container Platform 4

| 1.0.0.0-openshift-4.6.log4j-WS-ICPDS-fp132 | Link to Fix Central

Please follow the steps given in release notes to apply above remediation.

Workarounds and Mitigations

None