Skip to main content

DTEN Security Update - Apache Log4J2 Vulnerability CVE-2021-4422 - December 14, 2021

Created by DTEN Support, Modified on Thu, 28 May at 4:59 AM by RCK Freshwork

DTEN notes that the industry has made public the technical details and POC of the Apache Log4j2 high-risk vulnerability, vulnerability number CVE-2021-44228. Attackers can directly construct malicious requests to exploit this vulnerability and trigger remote code execution.

 

DTEN has completed a review and analysis of all our hardware and software products, including our Orbit managed software as a service (MSaaS) product. Our internal audits have found that DTEN products and services do not utilize any components related to the usage of Log4J or use any affected security components related to the usage of Log4J as defined in CVE-2021-44228.

 

Vulnerability analysis

The Apache Log4j2 remote code execution vulnerability attack code appeared on the night of December 9, according to Slow Fog Security Intelligence. This vulnerability exploits Apache Struts2, Apache Solr, Apache Druid, And Apache Flink without special configuration.

 

Scope of vulnerability

It has been verified that none of the DTEN product versions are affected by this vulnerability.

 

If you have additional questions or need to contact DTEN Support, please refer to this DTEN Knowledge Base article for more details:  HERE.

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article