MQ

MQ

Join this online group to communicate across IBM product users and experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Impact of log4j vulnerability on MQ8

    Posted Fri December 24, 2021 11:24 AM
    Hi,

    We are currently using MQ version 8. From the bulletin links Does IBM MQ ship Apache Log4J? , I see that MQ 9 is affected, but its not mentioned that MQ 8 is not affected by the log4j vulnerability.
    As per one of the articles, MQSeriesBCBridge rpm uses log4j. But I do not see the MQSeriesBCBridge rpm installed on the hosts. So as per my understanding MQ 8 wont be affected. Can you please confirm the same?

    ------------------------------
    Ritu Chaurasia
    ------------------------------


  • 2.  RE: Impact of log4j vulnerability on MQ8

    Posted Mon December 27, 2021 04:35 PM
    Hello,

    As stated in MQ Security bulletin, MQ Blockchain Bridge is the only log4j affected component for MQ which isn't available in MQ 8
    https://www.ibm.com/support/pages/node/6526274

    Thanks,

    ------------------------------
    Navaneeth Sakthi
    Senior Professional
    DXC Technology, Spain
    ------------------------------



  • 3.  RE: Impact of log4j vulnerability on MQ8

    Posted Mon December 27, 2021 09:11 PM
    Hello Navaneeth,

    Thanks for your response! Do I need to wait for any bulletin update or can I conclude that there is no impact on MQ8?

    Regards,
    Ritu Chaurasia

    ------------------------------
    Ritu Chaurasia
    ------------------------------



  • 4.  RE: Impact of log4j vulnerability on MQ8

    Posted Mon December 27, 2021 10:28 PM

    Hi Rita,

    The Security Bulletin that @Navaneeth Sakthi pointed you to, https://www.ibm.com/support/pages/node/6526274, contains the following statements:-

    the IBM MQ blockchain bridge component of IBM MQ 9.1.4 and later

    So you know from that statement that the IBM MQ blockchain bridge component is not part of IBM MQ V8.

    Based on current knowledge and analysis, no other IBM MQ components or installable packages are affected.

    Bear in mind that IBM MQ V8 is now out of support, and that the above security bulletin is only for MQ V9.x.

    If the statements made in the security bulletin are not conclusive enough for you, then you should probably contact IBM, assuming you have an extended support contract, and ask them for a more explicit statement.

    Cheers,
    Morag



    ------------------------------
    Morag Hughson
    MQ Technical Education Specialist
    MQGem Software Limited
    Website: https://www.mqgem.com
    ------------------------------