Release Notes (10.5.1.1)

Release Notes (10.5.1.1)

Apache Log4j RCE Vulnerabilities

Apache Log4j RCE Vulnerabilities

Informatica 10.5.1.1 addresses the CVE-2021-44228 and CVE-2021-45046 Log4j RCE vulnerabilities by removing the JndiLookup class from the vulnerable Log4j libraries.
If you have completed the remediation steps in your current version of Informatica, you don't need to take any further action.
If you have not completed the remediation steps in your current version, you need to apply EBF-23143 before you apply 10.5.1.1 as described in Apply EBF-23143 to remediate Log4j security vulnerabilities. After you complete this step, you don't need to take any further action after you apply 10.5.1.1.

0 COMMENTS

We’d like to hear from you!