Is UIM 20.4 impacted by CVE-2021-4104?
search cancel

Is UIM 20.4 impacted by CVE-2021-4104?

book

Article ID: 232635

calendar_today

Updated On:

Products

DX Unified Infrastructure Management (Nimsoft / UIM)

Issue/Introduction

Would like to know  CA UIM version 20.4 is impacted by CVE-2021-4104

Environment

Release : 20.4

Component :

Resolution

Yes, we have some components that use log4j 1.2. We will be updating these to log4j 2.17.1 soon.

These monitoring probes using log4j 1.2 will be updated to log4j 2.17.1 or above in Q2 2022:

apm_bridge

jvm_monitor

oi_connector

sdgtw

websphere

office365

Restmon

icmp

nutanix_

monitor

sap_basis

vmware

xendesktop