JDBCAppender Vulnerability (CVE-2021-44832) Exposure in Symantec Identity Manager
search cancel

JDBCAppender Vulnerability (CVE-2021-44832) Exposure in Symantec Identity Manager

book

Article ID: 231999

calendar_today

Updated On:

Products

CA Identity Suite CA Identity Manager

Issue/Introduction

This article clarifies whether Symantec Identity Manager is exposed to the Log4j v1.2x vulnerability identified as CVE-2021-44832 (JDBCAppender Vulnerability).

Environment

Identity Manager

Resolution

Sustaining Engineering has investigated this vulnerability and determined that Symantec Identity Manager is not vulnerable to CVE-2021-44832 by default.

  • Default Configuration: The JDBCAppender is not configured in any Out-of-the-Box (OOTB) log4j configuration files.
  • Access: The Log4j configuration file is not accessible to remote attackers.

Additional Information

 If you have manually declared the JDBCAppender in your Log4j configuration, you must take the following steps to secure the environment:

  • Comment out any existing JDBCAppender references in your Log4j configuration files.
  • Alternatively, remove the JDBCAppender configuration entirely if it is not required for your deployment.