Table of Contents

Search

  1. Preface
  2. Apache Log4j RCE Vulnerabilities
  3. Support Changes
  4. Installation and Upgrade
  5. Hotfix Installation and Rollback
  6. 10.5.2 Fixed Issues and Closed Enhancements
  7. 10.5.2 Known Issues
  8. Cumulative Known Issues
  9. Emergency Bug Fixes Merged into 10.5.2
  10. Informatica Global Customer Support

Release Notes (10.5.2)

Release Notes (10.5.2)

Apache Log4j RCE Vulnerabilities

Apache Log4j RCE Vulnerabilities

Informatica 10.5.2 has adopted Log4j library version 2.17.1.
Informatica bundles third-party libraries containing Log4j 1.x on all nodes in the domain and on all Developer tool machines. Not all third parties have remediated this issue, and Informatica is working with the vendors to resolve them. Informatica products are not exploitable or impacted by Log4j 1.x vulnerabilities that use default configurations.
If you installed any products through the Informatica platform installer, your environment contains these libraries even if you don't use them.
For information about the impact due to the third-party libraries and the mitigation steps that you can take, see this Knowledge Base article: Apache Log4j Vulnerabilities related to Distribution Vendors

0 COMMENTS

We’d like to hear from you!