Skip to main content

Security Notice: Apache log4j Vulnerability CVE-2021-44228

Info

FromIn December 9,2021, 2021CVE-2021-44228 reportswas of a Zero Day exploitdisclosed for Apache Log4j 2.x <= 2.15.0-rc1 were being reported inLog4j2, the wildJava underlogging CVE-2021-44228.library. The vulnerability is commonly known as Log4Shell and affected vulnerable Log4j2 versions where attacker-controlled JNDI lookups could lead to remote code execution.

Question

Are FileWave systems impacted by this exploit?CVE-2021-44228?

Answer

No. FileWave atServer, oneBoosters, pointIVS, inand timeClients (moreare thannot 4impacted yearsby ago)CVE-2021-44228 based on FileWave's product assessment.

    FileWave did not use the Java Apache Log4j library. Older FileWave releases used log4qt, a C++ implementationlogging of log4j,implementation, but itsthat use was discontinued fromafter FileWave 12.4.

    This page is retained as a historical security notice. If you are validating an older or unsupported environment, compare the installed FileWave version 12.4with of FileWave. The Java version of log4j was never used by FileWave.  Thereforecurrent FileWave systemssupport (Boosters, Server, IVS,guidance and Clients)any arenewer NOTFileWave impactedsecurity by this vulnerability.notices.

    Reference

      CVE-2021-44228 record