Skip to main content
Question

CVE-2021-44228 - Log4J 2

  • December 13, 2021
  • 5 replies
  • 881 views

Forum|alt.badge.img+9
  • Sidekick (Customer)
  • 92 replies

Hi, can IFS please provide a notice on whether IFS Applications 10 (inc. MWO, and Aurena) are vulnerable to the Log4J2 CVE-2021-44228?

This topic has been closed for comments

5 replies

Forum|alt.badge.img+1
  • Do Gooder (Customer)
  • 2 replies
  • December 13, 2021

Any comments from IFS regarding this?


Forum|alt.badge.img+9
  • Author
  • Sidekick (Customer)
  • 92 replies
  • December 13, 2021

Yes, eagerly awaiting an update. I came across POC on Twitter which suggested WebLogic is vulnerable so we’ve locked things down until IFS provide an update.


Forum|alt.badge.img+6
  • Sidekick (Customer)
  • 22 replies
  • December 13, 2021

Hi @Garak how have you gone about locking things down?

Thanks,

Mick.


Forum|alt.badge.img+9
  • Author
  • Sidekick (Customer)
  • 92 replies
  • December 13, 2021

We turned off all internet accessibility to our environments so they are only accessible on the corporate network directly. That way it’s impossible for the module to be called outside our network.

They are behind a reverse proxy and firewall etc. but obviously they are unlikely to help with this vuln.

By turning off internet access it means that we’ve lost the use of MWO and Aurena in the field for our maintenance team unless they’re on corporate wi-fi, and contractors now will have to use the terminal server.

This is all in addition to other network-wide mitigations too of course.


Phil Lamerton
Superhero (Employee)
Forum|alt.badge.img+24
  • Superhero (Employee)
  • 531 replies
  • December 13, 2021

Please subscribe to this KBA which will be updated every 24 hours

 


Cookie policy

We use cookies to enhance and personalize your experience. If you accept you agree to our full cookie policy. Learn more about our cookies.

 
Cookie settings