Question

CVE-2021-44228 - Log4J 2

  • 13 December 2021
  • 5 replies
  • 835 views

Userlevel 5
Badge +9
  • Sidekick (Customer)
  • 87 replies

Hi, can IFS please provide a notice on whether IFS Applications 10 (inc. MWO, and Aurena) are vulnerable to the Log4J2 CVE-2021-44228?


This topic has been closed for comments

5 replies

Badge +1

Any comments from IFS regarding this?

Userlevel 5
Badge +9

Yes, eagerly awaiting an update. I came across POC on Twitter which suggested WebLogic is vulnerable so we’ve locked things down until IFS provide an update.

Userlevel 2
Badge +6

Hi @Garak how have you gone about locking things down?

Thanks,

Mick.

Userlevel 5
Badge +9

We turned off all internet accessibility to our environments so they are only accessible on the corporate network directly. That way it’s impossible for the module to be called outside our network.

They are behind a reverse proxy and firewall etc. but obviously they are unlikely to help with this vuln.

By turning off internet access it means that we’ve lost the use of MWO and Aurena in the field for our maintenance team unless they’re on corporate wi-fi, and contractors now will have to use the terminal server.

This is all in addition to other network-wide mitigations too of course.

Userlevel 7
Badge +17

Please subscribe to this KBA which will be updated every 24 hours