IBM Tivoli System Automation Application Manager is vulnerable to arbitrary code execution due to multiple Apache Log4j (CVE-2021-4104, CVE-2021-45046) vulnerabilities in Webssphere Application Server. The remediation addresses the vulnerabilities by removing Apache Log4j.
Refer to the security bulletin(s) listed in the Remediation/Fixes section
Affected Product(s) | Version(s) |
---|---|
IBM Tivoli System Automation Application Manager | 4.1 |
IBM strongly recommends addressing the vulnerability now.
Principal Product and Version(s) | Affected Supporting Product and Version | Affected Supporting Product Security Bulletin |
---|---|---|
IBM Tivoli System Automation Application Manager 4.1 | WebSphere Application Server 8.5 | Security Bulletin: Multiple vulnerabilities in Apache log4j affect the IBM WebSphere Application Server and IBM WebSphere Application Server Liberty (CVE-2021-4104, CVE-2021-45046) |
IBM Tivoli System Automation Application Manager 4.1 | WebSphere Application Server 9.0 | Security Bulletin: Multiple vulnerabilities in Apache log4j affect the IBM WebSphere Application Server and IBM WebSphere Application Server Liberty (CVE-2021-4104, CVE-2021-45046) |
None
CPE | Name | Operator | Version |
---|---|---|---|
tivoli system automation application manager | eq | 4.1 |