Lucene search

K
ibmIBMF35EB0C55F08CA4C671A4E6D2454A08936C6D1CD868709D0EE04FB71FFC263C1
HistoryJan 26, 2022 - 4:33 p.m.

Security Bulletin: IBM Tivoli System Automation Application Manager is vulnerable to arbitrary code execution due to Apache Log4j (CVE-2021-4104, CVE-2021-45046)

2022-01-2616:33:49
www.ibm.com
43

0.974 High

EPSS

Percentile

99.9%

Summary

IBM Tivoli System Automation Application Manager is vulnerable to arbitrary code execution due to multiple Apache Log4j (CVE-2021-4104, CVE-2021-45046) vulnerabilities in Webssphere Application Server. The remediation addresses the vulnerabilities by removing Apache Log4j.

Vulnerability Details

Refer to the security bulletin(s) listed in the Remediation/Fixes section

Affected Products and Versions

Affected Product(s) Version(s)
IBM Tivoli System Automation Application Manager 4.1

Remediation/Fixes

IBM strongly recommends addressing the vulnerability now.

Principal Product and Version(s) Affected Supporting Product and Version Affected Supporting Product Security Bulletin
IBM Tivoli System Automation Application Manager 4.1 WebSphere Application Server 8.5 Security Bulletin: Multiple vulnerabilities in Apache log4j affect the IBM WebSphere Application Server and IBM WebSphere Application Server Liberty (CVE-2021-4104, CVE-2021-45046)
IBM Tivoli System Automation Application Manager 4.1 WebSphere Application Server 9.0 Security Bulletin: Multiple vulnerabilities in Apache log4j affect the IBM WebSphere Application Server and IBM WebSphere Application Server Liberty (CVE-2021-4104, CVE-2021-45046)

Workarounds and Mitigations

None