Table of Contents

Search

  1. Abstract
  2. Apache Log4j RCE Vulnerability
  3. Installation and Upgrade
  4. 10.5 Fixed Limitations
  5. 10.5 Known Limitations
  6. Cumulative Known Limitations
  7. Emergency Bug Fixes Merged into Multidomain MDM 10.5

Apache Log4j RCE Vulnerability

Apache Log4j RCE Vulnerability

The following files in Multidomain MDM 10.5 use Log4j library version 2.17.2:
  • BeMDMWorkflow.bpr
  • entity360view.ear
  • hubConsole.jar
  • MDMWorkflow.bpr
  • provisioning-ear.ear
  • siperian-mrm.ear
  • siperian-mrm-cleanse.ear
  • uiwebapp.ear
To remediate other Log4j 1.2.x files in Multidomain MDM and ActiveVOS, apply EBF-24956. You can find the EBF with the Multidomain MDM 10.5 installation package and in the Informatica TSFTP server.
To download the EBF from the TSFTP server, perform the following steps:
  1. Go to the following URL:
    For more information about logging in to the TSFTP server, see Knowledge Base article 497394.
  2. Navigate to the following directory:
    updates/MDM/hotfixes/Oracle_DB2_SQLServer/Hub_<Major Version Number>_GA
  3. Download EBF-24956.

0 COMMENTS

We’d like to hear from you!