log4j Vulnerabilities - question
Could you please update my folks about log4j vulnerabilities? Will the new patch cover these concerns?
These are some of the locations the vulnerability scanner tagged. There may be others that the scanner didn't report. The version of log4j either has a vulnerability or is an unsupported version. I tried removing the specified files to mitigate the vulnerabilities. The program no longer opens once the files are removed. The current version of log4j that is not a vulnerability is 2.17.1 or greater.
C:\Program Files\SmartBear\ReadyAPI-2.8.2\lib\log4j-jcl-2.11.0.jar
C:\Program Files\SmartBear\ReadyAPI-2.8.2\lib\log4j-jul-2.11.0.jar
C:\Program Files\SmartBear\ReadyAPI-2.8.2\lib\log4j-core-2.11.0.jar
C:\Program Files\SmartBear\ReadyAPI-2.8.2\lib\log4j-slf4j-impl-2.11.0.jar
C:\Program Files\SmartBear\ReadyAPI-2.8.2\lib\log4j-api-2.11.0.jar
C:\Users\1189937160E\AppData\Local\SmartBear\ReadyAPI-3.6.0\lib\log4j-jcl-2.11.0.jar
C:\Users\1189937160E\AppData\Local\SmartBear\ReadyAPI-3.6.0\lib\log4j-jul-2.11.0.jar
C:\Users\1189937160E\AppData\Local\SmartBear\ReadyAPI-3.6.0\lib\log4j-core-2.11.0.jar
Mark E. Miller, Contr, USAF
AFMC/HIHO
Comm. (210) 565-1172 DSN 665-1172
Diversified Technical Services, Inc (DTSI)
(210) 341-1980