Log4j vulnerability about specific files in tmp directory
search cancel

Log4j vulnerability about specific files in tmp directory

book

Article ID: 233655

calendar_today

Updated On:

Products

SITEMINDER CA Single Sign On Secure Proxy Server (SiteMinder)

Issue/Introduction

 

When running Siteminder component, after having applied the log4j
update as per KD (1) the following log4j file can still be found :

  /myApp/myDir/tmp/533186.tmp/log4j-core-2.10.0.jar

 

Resolution

 

At first glance, none of the Policy Server, AdminUI nor CA Access
Gateway (SPS) install that file in that directory. For which, this one
can be safely removed on the Siteminder perspective.

 

Additional Information

 

(1)

    CVE-2021-44228: SiteMinder Resolution to the Log4j Vulnerability
    https://knowledge.broadcom.com/external/article?articleId=230270