Impact of CVE-2021-44228 Apache Log4j Vulnerability on Migrate

Impact of CVE-2021-44228 Apache Log4j Vulnerability on Migrate

Article: 100052075
Last Published: 2021-12-13
Ratings: 0 0
Product(s): Migrate

Summary

Apache Log4j 2.x (2.0 to 2.14.1) JNDI features used in configuration, log message, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints.  An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. 

More information is available from the Apache Announcement and recommends upgrading to the latest Log4j 2.15.0 or applying recommended mitigations immediately.

 

Issue

CVE ID: CVE-2021-44228 - Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints.

Severity: Critical

Base CVSS Score: 10.0

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

All versions of Migrate are not affected by this vulnerability.

 

Questions

For questions or problems regarding these vulnerabilities please contact Veritas Technical Support (https://www.veritas.com/support)

 

Disclaimer

THE SECURITY ADVISORY IS PROVIDED "AS IS" AND ALL EXPRESS OR IMPLIED CONDITIONS, REPRESENTATIONS AND WARRANTIES, INCLUDING ANY IMPLIED WARRANTY OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE OR NON-INFRINGEMENT, ARE DISCLAIMED, EXCEPT TO THE EXTENT THAT SUCH DISCLAIMERS ARE HELD TO BE LEGALLY INVALID. VERITAS TECHNOLOGIES LLC SHALL NOT BE LIABLE FOR INCIDENTAL OR CONSEQUENTIAL DAMAGES IN CONNECTION WITH THE FURNISHING, PERFORMANCE, OR USE OF THIS DOCUMENTATION. THE INFORMATION CONTAINED IN THIS DOCUMENTATION IS SUBJECT TO CHANGE WITHOUT NOTICE.

 

 

Was this content helpful?