Skip to main content
URGENT BULLETIN

URGENT BULLETIN - IFS Advisory:  IFS Products, Services and Log4j - ​CVE-2021-44228


Did this topic help you find an answer to your question?
61% found this helpful
Show first post
This topic has been closed for comments

74 replies

Forum|alt.badge.img
  • Do Gooder (Customer)
  • 1 reply
  • December 14, 2021

Assuming the fix is a delivery to us, do we need to have all our other deliveries installed into our PROD environment before we can install this new delivery?  Or are you able to pull that first delivery back in order to deliver this critical fix? 


Phil Lamerton
Superhero (Employee)
Forum|alt.badge.img+24
  • Author
  • Superhero (Employee)
  • 531 replies
  • December 15, 2021
Srikanth wrote:

It took some time for me to figure - The Impact KBA can be accessed by clicking a link in one of the updates at the top of this bulletin - 

https://community.ifs.com/notifications-security-bulletins-planned-maintenance-254/impact-of-cve-2021-44228-on-ifs-products-services-16504

Thank you IFS for providing these timely updates. 

Thank you! Yes that is the link :smiley:


Forum|alt.badge.img+8
  • Sidekick (Customer)
  • 27 replies
  • December 15, 2021

Along with FSM,  is the FSM mobile app (android) also unaffected?


Phil Lamerton
Superhero (Employee)
Forum|alt.badge.img+24
  • Author
  • Superhero (Employee)
  • 531 replies
  • December 15, 2021
TDCSOURABH wrote:

Along with FSM,  is the FSM mobile app (android) also unaffected?

That is correct 


Phil Lamerton
Superhero (Employee)
Forum|alt.badge.img+24
  • Author
  • Superhero (Employee)
  • 531 replies
  • December 15, 2021

Update (15th December 2021 13:05 UTC)


Forum|alt.badge.img+7
  • Sidekick (Partner)
  • 31 replies
  • December 15, 2021

@Phil Lamerton

 

Hi Phil, will that knowledge article will updated the soon, when fix available for IFS 10 and IFS cloud (On Premise)

 

Thank you for providing these  updates. 

 

kr

Amila


Phil Lamerton
Superhero (Employee)
Forum|alt.badge.img+24
  • Author
  • Superhero (Employee)
  • 531 replies
  • December 15, 2021
AmilaF wrote:

@Phil Lamerton

 

Hi Phil, will that knowledge article will updated the soon, when fix available for IFS 10 and IFS cloud (On Premise)

 

Thank you for providing these  updates. 

 

kr

Amila

Hi Amila

The KBA will be updated the minute I have further information, I cannot give you an answer right now but further updates are being put together.

Thanks

Phil


Forum|alt.badge.img+3
  • Do Gooder (Customer)
  • 9 replies
  • December 15, 2021

Hi, What is ESM assystIPaaS mitigation? Thanks James


Phil Lamerton
Superhero (Employee)
Forum|alt.badge.img+24
  • Author
  • Superhero (Employee)
  • 531 replies
  • December 15, 2021

Update (15th December 2021 15:30 UTC)

 


Phil Lamerton
Superhero (Employee)
Forum|alt.badge.img+24
  • Author
  • Superhero (Employee)
  • 531 replies
  • December 15, 2021

Update (15th December 2021 16:00 UTC)


Phil Lamerton
Superhero (Employee)
Forum|alt.badge.img+24
  • Author
  • Superhero (Employee)
  • 531 replies
  • December 15, 2021

Update (15th December 2021 19:30 UTC)


Forum|alt.badge.img+9
  • Sidekick (Customer)
  • 80 replies
  • December 16, 2021

Something i didn’t see written anywhere yet; will the Fix be delivered automatically to the client (via SFTP), or does each client need to reach out to their contact persons / create a LCS request?


Phil Lamerton
Superhero (Employee)
Forum|alt.badge.img+24
  • Author
  • Superhero (Employee)
  • 531 replies
  • December 16, 2021
Arend wrote:

Something i didn’t see written anywhere yet; will the Fix be delivered automatically to the client (via SFTP), or does each client need to reach out to their contact persons / create a LCS request?

Hi Arend,

This is being discussed at the moment, the minute I know more I will update the KBA 

Thanks

Phil


Phil Lamerton
Superhero (Employee)
Forum|alt.badge.img+24
  • Author
  • Superhero (Employee)
  • 531 replies
  • December 16, 2021

Updated (16th December 2021 9:00 UTC)


Phil Lamerton
Superhero (Employee)
Forum|alt.badge.img+24
  • Author
  • Superhero (Employee)
  • 531 replies
  • December 16, 2021

Update (16th December 2021 13:00 UTC)


Forum|alt.badge.img+9
  • Sidekick (Customer)
  • 92 replies
  • December 16, 2021

So for Apps 10 does that mean we’ll get the patch soon, or do we have to wait until after 3 March to get it?


Forum|alt.badge.img+16
  • Superhero (Partner)
  • 398 replies
  • December 16, 2021

I see that patch for IFS10 is ready: 161936


Phil Lamerton
Superhero (Employee)
Forum|alt.badge.img+24
  • Author
  • Superhero (Employee)
  • 531 replies
  • December 16, 2021
Garak wrote:

So for Apps 10 does that mean we’ll get the patch soon, or do we have to wait until after 3 March to get it?

We are anticipating it will be be available on the 17th December but also available in the release in March.


Forum|alt.badge.img+7
  • Do Gooder (Customer)
  • 26 replies
  • December 16, 2021

Hello, will each company on Apps10 have to request the patch individually when it’s available?  And I’m assuming the same rules apply where you have to install patches in sequence?  I have one I’m testing now.

Mary McCabe

 


GISANCAR
Sidekick (Customer)
Forum|alt.badge.img+8
  • Sidekick (Customer)
  • 28 replies
  • December 16, 2021

For Apps10, is this valid for all updates?

We are using update 11, and I did a search on our app server where I found ‘log4j-1.2.17.jar’, which is a newer version than listed above as a potential issue.

Or is the patch needed for all updates in Apps10?


Phil Lamerton
Superhero (Employee)
Forum|alt.badge.img+24
  • Author
  • Superhero (Employee)
  • 531 replies
  • December 16, 2021
knepiosko wrote:

I see that patch for IFS10 is ready: 161936

IFS Apps 10 is mitigated in cloud, but as per the KBA, patching for on premise customers is due for release tomorrow


Phil Lamerton
Superhero (Employee)
Forum|alt.badge.img+24
  • Author
  • Superhero (Employee)
  • 531 replies
  • December 16, 2021
reimccabe wrote:

Hello, will each company on Apps10 have to request the patch individually when it’s available?  And I’m assuming the same rules apply where you have to install patches in sequence?  I have one I’m testing now.

Mary McCabe

 

Distribution process is being developed and tested and will be documented as part of its release


Phil Lamerton
Superhero (Employee)
Forum|alt.badge.img+24
  • Author
  • Superhero (Employee)
  • 531 replies
  • December 16, 2021
GISANCAR wrote:

For Apps10, is this valid for all updates?

We are using update 11, and I did a search on our app server where I found ‘log4j-1.2.17.jar’, which is a newer version than listed above as a potential issue.

Or is the patch needed for all updates in Apps10?

The version referenced is a 1.x version.  The mitigation/solution is based upon 2.16.0 which is later.  It will be applicable for all IFS Apps10 updates


Forum|alt.badge.img+16
  • Superhero (Partner)
  • 398 replies
  • December 16, 2021

What about IFS9 version and customers without extended support?


Phil Lamerton
Superhero (Employee)
Forum|alt.badge.img+24
  • Author
  • Superhero (Employee)
  • 531 replies
  • December 16, 2021
knepiosko wrote:

What about IFS9 version and customers without extended support?

As is in the KBA, IFS Apps 9 customers are not impacted by this.


Cookie policy

We use cookies to enhance and personalize your experience. If you accept you agree to our full cookie policy. Learn more about our cookies.

 
Cookie settings