View Only
Expand all | Collapse all

HMC and Log4j

  • 1.  HMC and Log4j

    Posted Mon December 13, 2021 09:16 AM
    anyone have any idea if the HMC is in any way affected by the recent log4j vulnerability?
    Would be nice to know if I need to start the planning of emergency HMC updates or not.

    If all else fails I can log a call with IBM but wondered if anyone else had already been privy to any relevant info.


    Matt Dulson

  • 2.  RE: HMC and Log4j

    Posted Tue December 14, 2021 08:55 AM

    Well, that's not final proof, but there is at least one indication, that HMCs might not be affected:
    hscroot@mqde01hmcsap01:~> ls /usr/share/java/log4j*
    /usr/share/java/log4j12-1.2.17.jar /usr/share/java/log4j-1.2.17.jar /usr/share/java/log4j-1.jar

    So while log4j is installed, that version isn't affected.... Disclaimer: That doesn't mean, that there is an affected version installed anywere else.

    Best regards,

    PS: Looking at HMC V9R2 M950.

    Alexander Reichle-Schmehl

  • 3.  RE: HMC and Log4j

    Posted Tue December 14, 2021 09:36 AM

    there are more log4j-Files in several subdirectories under
    • /opt/apache-tomcat-7.0.105
    • opt/hmc/share/jars-9.2.950.5
    e.g. /opt/apache-tomcat-7.0.105/usr/servers/pmc/apps/pmc-ui-war-9.2.950.5-2103160809.war/WEB-INF/lib/log4j-core-2.13.3.jar

    We also use HMC V9R2 M950.

    Best regards

    Winfried Oesterle
    AIX Administrator

  • 4.  RE: HMC and Log4j

    Posted Tue December 14, 2021 01:02 PM
    Thanks for correcting my earlier post!

    Alexander Reichle-Schmehl

  • 5.  RE: HMC and Log4j

    Posted Wed December 15, 2021 12:37 PM

  • 6.  RE: HMC and Log4j

    Posted Tue December 14, 2021 04:11 PM
    Looking at HMC V9R2 M950 I am also seeing quite a few entries under /proc with the log4j2.xml extension


    among others.

    Stephen Beaton - UNIX Administrator

    Stephen Beaton

  • 7.  RE: HMC and Log4j

    Posted Tue December 14, 2021 10:09 PM
    Hi All