Maximo

Maximo

Come for answers, stay for best practices. All we're missing is you.

 View Only
  • 1.  Log4j Vulnerability (CVE-2021-44228)

    Posted Sat December 11, 2021 01:29 PM
    Hello, 

    Recently our cyber security team based upon their logs suspected a few attacks related to "zero-day Java log4j vulnerability". It seems that
    the vulnerability requires an application that would log a simple special string submitted by the user.  So for example, if a java app logs the HTTP User-Agent header (or any other header), the attacker merely needs to set their User-Agent to this special string.  

    Any clue whether in MAXIMO code such logging statements are present? 

    Are there any fixes, patches for MAXIMO, WebSphere, etc?


    ------------------------------
    Pankaj Bhide
    Computer Systems Engineer
    Berkeley National Laboratory
    Berkeley CA
    ------------------------------

    #AssetandFacilitiesManagement
    #Maximo


  • 2.  RE: Log4j Vulnerability (CVE-2021-44228)

    Posted Mon December 13, 2021 08:19 AM
    Hello Team,

    We have been also notified about the above Threat Log4j vulnerability (CVE-2021-44228) 

    Any update please, let us know

    Arun Prasath
    Solution Architect
    Tech Mahindra

    ------------------------------
    Arun Prasath
    ------------------------------



  • 3.  RE: Log4j Vulnerability (CVE-2021-44228)

    Posted Mon December 13, 2021 11:09 AM
    The log4j version shipped with Maximo (or Manage) for most customers will not be impacted. If you have ACM, Aviation, or Scheduler Optimization there will be information posted on how to update it as those come with a version of log4j that is impacted.

    WebSphere also is impacted and has the documentation available here: https://www.ibm.com/blogs/psirt/security-bulletin-vulnerability-in-apache-log4j-affects-websphere-application-server-cve-2021-44228/

    ------------------------------
    Steven Shull
    ------------------------------



  • 4.  RE: Log4j Vulnerability (CVE-2021-44228)

    Posted Mon December 13, 2021 11:20 AM
    Edited by System Admin Wed March 22, 2023 11:55 AM


  • 5.  RE: Log4j Vulnerability (CVE-2021-44228)

    Posted Mon January 10, 2022 05:38 PM
    Steven, what is the recommendation for remediating Log4j version 1 vulnerabilities in Maximo and ICD? Is there an existing procedure to replace it with Log4j version 2.17 (or latest)?

    ------------------------------
    Boyd Bradford
    Director, IT Service Management Practice
    Advanced Integrated Solutions, Inc.
    ------------------------------



  • 6.  RE: Log4j Vulnerability (CVE-2021-44228)

    Posted Tue January 11, 2022 08:01 AM
    The transition to Log4j 2.X requires changes in Maximo/Control Desk to support. I'm not sure what has been made public so I'm not sure what I'm allowed to share. I'd reach out to your IBM rep to get an official answer. I can say it's something we are planning to address with upcoming releases.

    ------------------------------
    Steven Shull
    ------------------------------



  • 7.  RE: Log4j Vulnerability (CVE-2021-44228)

    Posted Tue January 11, 2022 10:58 AM
    Thanks Steven. I was hoping for a workaround to satisfy the security team in the short run.

    ------------------------------
    Boyd Bradford
    Director, IT Service Management Practice
    Advanced Integrated Solutions, Inc.
    ------------------------------