Page 1 of 1

Log4J ?

Posted: 15 Dec 2021, 19:27
by Franck.A
Hello All,

I have heard about this "little" issue regarding a vulnerability in Log4j.
As I am more from the IBM's world, I have literraly no clue about what it is but I was wondering if this could affect the Lansa Axes tools/objects.

so here is my question : should I worry ? :)

Thank you for your help.

Re: Log4J ?

Posted: 15 Dec 2021, 23:37
by Dino
Hi Franck,

This has been posted in the lansa forum about it:
https://forum.developer.lansa.com/viewt ... f=3&t=2561

I found a jsmlog4j.jar in the /axes421jsm/jsm/instance/jar folder.

Same way as indicated in that post, you could remove jsmlog4j.jar from "/axes421jsm/jsm/instance/jar" folder (move it to /tmp for example), restart JSM (endsbs axes421jsm/axes421jsm, wait for it to end, then strsbs axes421jsm/axes421jsm) and test aXes application to see if they still work normally.

Re: Log4J ?

Posted: 16 Dec 2021, 01:02
by Franck.A
Hi Dino,

Thank you very much for this information, we are going to test the procedure on our preprod environment.

Best regards,
Franck