DevOps Automation

DevOps Automation

Join this online group to communicate across IBM product users and experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  How to remove log4j 1.x jars from Urban Code

    Posted Tue August 23, 2022 11:58 AM
    Hi,

    I have recently upgraded my Urban Code Deploy to v6.2.7.17 but it still has log4j 1.2.17 jars in it. Since 1.x is out of support, it is coming as a vulnerability in our security scan. Can anyone help on how to resolve it.

    Thanks

    ------------------------------
    Mahesh PARKAR
    ------------------------------


  • 2.  RE: How to remove log4j 1.x jars from Urban Code

    Posted Tue August 23, 2022 04:28 PM
    Hi Mahesh, I've reached out to our experts with your question. You will hear from them soon. Thanks for reaching out on the community.

    ------------------------------
    Divya Koppolu
    ------------------------------



  • 3.  RE: How to remove log4j 1.x jars from Urban Code

    Posted Wed August 24, 2022 11:07 AM


    ------------------------------
    Senthil Nathan
    ------------------------------



  • 4.  RE: How to remove log4j 1.x jars from Urban Code

    Posted Fri September 02, 2022 03:28 PM
    Thank you for the update. Vulnerability has been closed after upgrading UCD to v.7.2.3.1.

    ------------------------------
    Mahesh PARKAR
    ------------------------------