IBM sprays Log4j bugs in security products

By

Apache Struts utility still causing headaches for admins.

Log4j is continuing to sting big names in the IT industry, with IBM the latest to discover products vulnerable to the Apache Struts logging bug.

IBM sprays Log4j bugs in security products

Big Blue’s latest advisories cover two security products, Security Guardium, and IBM’s Common Cryptographic Architecture for MTM 4767.

Security Guardium versions 10.5, 10.6, and 11.0 through 11.4 are affected, because they use the Apache utility in their logging infrastructure.

Only one of the multiple vulnerabilities discovered last year affects Security Guardium – CVE-2021-4104, the deserialisation vulnerability in the utility’s JMSAppender.

IBM’s fix for the security environment is an appliance patch which the company says replaces Log4j 1.x with Log4j2 V2.17.1.

In the IBM Common Cryptographic Architecture (CCA), the Log4j bugs affect the Crypto Hardware Initialization and Maintenance (CHIM).

IBM’s advisory lists all four Log4j bugs – CVE-2022-23307, CVE-2022-23302, CVE-2021-4104, and CVE-2022-23305 – as affecting the CCA.

As with Security Guardium, the fix for CCA replaces Log4j 1.x with Log4j2 V2.17.1.

As iTnews explained when the Log4j vulnerability was first discovered: “When a vulnerable application writes to a log file, the default Log4j configuration means the library looks up a server which, if an attacker controls it, can be set to send a malicious response from that system.

“The response can contain a remote Java class file which is injected into the server process and executed with the same privileges as the vulnerable application using the logging library.”

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

Eagers Automotive finds unauthorised access to parts of IT systems

Eagers Automotive finds unauthorised access to parts of IT systems

Hackers hit Victoria's court recording database

Hackers hit Victoria's court recording database

St Vincent's Health Australia warns cyber attack forensics could "take some time"

St Vincent's Health Australia warns cyber attack forensics could "take some time"

Yakult Australia confirms cyber incident

Yakult Australia confirms cyber incident

Log In

  |  Forgot your password?