This discussion has been locked. The information referenced herein may be inaccurate due to age, software updates, or external references.
You can no longer post new replies to this discussion. If you have a similar question you can start a new discussion in this forum.

Apache Log4j vulnerability variant [CVE-2021-44228]

This is probably a no brainer, but is the Solarwinds Orion 2020.2.6 HF1 version impacted at all by the new log4j vulnerability variant?  My guess is probably not, being that it needs JAVA to manifest itself, and I don't believe Solarwinds Orion utilizes any JAVA components with the latest software versions.  But my management wanted me to check with you folks.  So please advise and confirm?  Thank you!

Parents Reply
  • So believe that we can modify some configuration file 

    Mitigation: In releases >=2.10, this behavior can be mitigated by setting either the system property log4j2.formatMsgNoLookups or the environment variable LOG4J_FORMAT_MSG_NO_LOOKUPS to true.

    Assuming it is the log4j2.xml in the DPA path but not 100% sure if that is the case, has anyone tried this yet?

Children
No Data