Managed File Transfer

 View Only
  • 1.  log4j vulnerability Connect:Direct for Windows 6.1.0.2

    Posted Mon December 13, 2021 08:17 AM

    Hi,

    Has anyone got any information on a fix for this as yet?  

    Thanks,
    Julie



    ------------------------------
    Julie Miller
    ------------------------------

    #filetransfer
    #DataExchange


  • 2.  RE: log4j vulnerability Connect:Direct for Windows 6.1.0.2

    Posted Tue December 14, 2021 07:24 AM
    Julie,
    You would be better off opening a case with IBM to get the intended solution, as your platform/version may be different than others on this thread.  
    IBM will be releasing technotes for the Log4Shell/LogJam vulnerability.

    ------------------------------
    Michael Geier
    IT Engineer 3
    Enterprise Holdings, Inc
    St. Louis MO
    ------------------------------



  • 3.  RE: log4j vulnerability Connect:Direct for Windows 6.1.0.2

    Posted Wed December 15, 2021 01:12 AM
    fix is available and please download it from IBM fix central.

    ------------------------------
    Wai Man Wong
    ------------------------------



  • 4.  RE: log4j vulnerability Connect:Direct for Windows 6.1.0.2

    Posted Thu December 16, 2021 03:13 PM
    The fix available from IBM fix central is from before log4j announcement and doesn't mention it at all...

    Is Connect:Direct affected by this in a first place?

    ------------------------------
    Lucas Kadzinski
    ------------------------------



  • 5.  RE: log4j vulnerability Connect:Direct for Windows 6.1.0.2

    Posted Thu December 16, 2021 07:59 PM

    Version 6.1 and 4.8 has released the fix on CVE-2021-44228. .........please go to IBM fix central and check .....

    4.8.0.3_iFix037
    : MFT-12770 / APAR IT39370 / CVE-2021-44228

    Description of Issue: There is a vulnerability in Apache Log4j used by Install Agent in IBM Sterling Connect:Direct for Microsoft Windows. IBM Sterling Connect:Direct for Microsoft Windows has addressed the applicable CVE.

    Description of Fix: Updated log4j in Install Agent.

    Fix Availability Date: 13 December 2021

    High Impact: Y

    Reported Severity: 1




    ------------------------------
    Wai Man Wong
    ------------------------------



  • 6.  RE: log4j vulnerability Connect:Direct for Windows 6.1.0.2

    Posted Thu December 16, 2021 08:28 PM
    got it, thank you - fix for 6.0.0.x was released today, I was checking yesterday

    ------------------------------
    Lucas Kadzinski
    ------------------------------



  • 7.  RE: log4j vulnerability Connect:Direct for Windows 6.1.0.2

    Posted Fri December 17, 2021 04:06 AM

    The following new ifixes have been published on IBM Fix Central to address CVE-2021-44228 for IBM Sterling Connect:Direct for Windows and Unix

    C:D Windows 6.1.0.2_iFix030 
    C:D Windows 6.0.0.4_iFix043 
    C:D Windows 4.8.0.3_iFix037 

    C:D Unix 6.2.0.1_iFix016  
    C:D Unix 6.1.0.4_iFix033 
    C:D Unix 6.0.0.2 iFix 123 
    C:D Unix 4.3.0.1_iFix089 

    Also

    C:D File Agent 1.4.0.2_iFix013



    ------------------------------
    John Mason
    Support Manager (EMEA & Asia Pacific)
    IBM Sterling Managed File Transfer Solutions
    ------------------------------