CVE-2021-40228 and CVE-2021-45046 vulnerabilities (Apache log4j, Log4Shell)

Issue:
Perle Systems products are Not Vulnerable to CVE-2021-40228 or CVE-2021-45046 (Apache log4j, Log4Shell).

Apache Log4j <=2.14.1 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled (CVE-2021-44228).

It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations.(CVE-2021-45046)

Solution:
Perle Systems has confirmed that all products do not incorporate Apache Log4j.

Products impacted:
none


Article ID:
646
Published:
12/13/2021 12:25:19 PM
Last Modified:
12/17/2021 4:37:01 PM
Keywords:
CVE-2021-40228,CVE-2021-45046,vulnerability,IOLAN,Log4j,Apache,Log4Shell