BigFix Inventory has a remediation for Log4j Vulnerability CVE 2021-44228

BFI Log4j vulnerabilities addressed in 10.0.7 release

BigFix Inventory 10.0.7 has now been released, and has updates to address concerns with Log4j vulnerabilities in some BFI components (VM Manager for hypervisor based metrics, SAP Tool for SAP specific metrics).

From the announcement page: BigFix Inventory: Application Update 10.0.7.0 published 2021-12-15
· “Security enhancements
log4j library, that is included in VM Manager tool and SAP tool, is updated to version 2.15.0 to address CVE-2021-44228.
Note: BigFix Inventory is not affected by CVE-2021-45046.”

CVE-2021-44228 is generally known as the first major Log4j vulnerability

CVE-2021-45046 is the secondary vulnerability discovered in Log4j

Note: These two BFI components are not widely deployed and may not even be installed in your customers BFI installation. To check whether they are installed refer to the overall BigFix Log4j vulnerability Knowledge base article: https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0095486

Helping BFI customers to find Log4j vulnerabilities in other products

The BigFix Inventory development team has created a set of custom template signatures on BigFix.me, as well as provided detailed instructions on how to uses these signatures within the BFI product.

For additional details, please read the forum post: BigFix Inventory: discovery of applications that may be affected by Log4j vulnerability (CVE-2021-44228)

1 Like

Thanks. I moved to 10.0.7 this morning with no issues, and have updated my vm managers. Currently showing log4j v2.15 as expected.
I would expect BFI to move to 2.16 asap though as external scanners are reporting 2.15 as a vulnerable version even if it BFI is not specifically vulnerable. And yes, I will be performing the manual workaround to move them to 2.16 immediately.

1 Like

Has 2.17 been tested for Inventory yet?

Also, I found references to older, 1.x versions of log4j in the Migrations folder of my BFI install (Program Files/ibm/BFI/migration/SUA 2.x/lib and /product/lib). I am assuming that this is just leftovers from previous upgrades. Can it it be confirmed that i can deleted all files in the Migration folder?