Apache Log4j Vulnerability Determinations for Data Center Security Server
search cancel

Apache Log4j Vulnerability Determinations for Data Center Security Server

book

Article ID: 235502

calendar_today

Updated On:

Products

Data Center Security Server Advanced Data Center Security Server Data Center Security Monitoring Edition

Issue/Introduction

Security scanners frequently flag Apache Log4j vulnerabilities in Data Center Security (DCS) installations based on the presence of the Log4j library file version. This article provides determinations on known Log4j-related CVEs for DCS Server Advanced and explains why these detections are often false positives regarding DCS functionality.

Environment

  • Data Center Security Server Advanced: 6.9.x and 6.10.x

Resolution

A cross check was done to review DCS and its use of any vulnerable component from Log4j from the mentioned vulnerabilites 

  1. CVE-2019-17571
    • DCS Server 6.9.1 doesn't use SocketServer which is a vulnerable class so DCS Server 6.9.1 is not affected by this vulnerability
  2. CVE-2020-9488
    • DCS Server 6.9.1 doesn't use SMTPAppender so it is not affected by this vulnerability
  3. CVE-2022-23302
    • DCS Server 6.9.1 doesn't use JMSSink so it is not affected by this vulnerability
  4. CVE-2022-23305
    • DCS Server 6.9.1 doesn't use JDBCAppender so it is not affected by this vulnerability
  5. CVE-2022-23307
    • DCS Server 6.9.1 doesn't use chain saw components so it is not affected by this vulnerability
  6. CVE-2026-49844
    • DCS Server 6.9.2 and 6.9.3 doesn't use this functionality so it is not affected by this vulnerability

    • DCS Server 6.10 doesn't use this component so it's not affected by this vulnerability

Contact Broadcom support for any further questions regarding this topic