ALERT: Some images may not load properly within the Knowledge Base Article. If you see a broken image, please right-click and select 'Open image in a new tab'. We apologize for this inconvenience.

CVE-2022-23307 log4j vulnerability and ESP dSeries Workload Automation DE

book

Article ID: 239817

calendar_today

Updated On:

Products

CA Workload Automation DE

Issue/Introduction

Is ESP dSeries Workload Automation DE affected by the log4j vulnerability - CVE-2022-23307? 

 

Environment

Release : 12.1, 12.2, 12.3

Component : ESP dSeries Workload Automation DE

 

Resolution

Broadcom Engineering has confirmed that these GA versions of ESP dSeries Workload Automation DE are not affected by this vulnerability.

 

The current GA versions of ESP dSeries Workload Automation DE are distributed with log4j 1.2.x that does not utilize the Chainsaw companion application available in Log4j 1.x. 

 

ESP dSeries Workload Automation DE will be providing updated log4j 2.x libraries in a future release. 

 

Additional Information

References:

https://logging.apache.org/log4j/2.x/security.html

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23307

https://nvd.nist.gov/vuln/detail/CVE-2022-23307

https://access.redhat.com/security/cve/cve-2022-23307