TIBCO is aware of the recently announced Apache Log4J vulnerability (CVE-2021-44228), referred to as “Log4Shell”. Performing these attacks requires an attacker to have control of log messages or at least the parameters for a given log message. This vulnerability theoretically enables arbitrary code to be executed on the affected system.
TIBCO’s Security Team is actively monitoring the information coming out about the Apache Log4J Vulnerability and our Product Security Incident Response Team (PSIRT) is actively evaluating how this vulnerability may affect TIBCO products and cloud services.
Issue/Introduction
TIBCO Runtime Agent: Mitigation for CVE-2021-44228 (Log4Shell)
3. TRA 5.11.2 and lower versions, TIBCO Administrator (Admin) 5.11.2 and lower versions either do not use Apache Log4J or are not on an affected version of Log4J.
3. For TRA 5.10.x, please refer to article# 000046322.