Clarity SaaS customer identified Apache log4j vulnerability after installing the XOG client in batch server
search cancel

Clarity SaaS customer identified Apache log4j vulnerability after installing the XOG client in batch server

book

Article ID: 245530

calendar_today

Updated On:

Products

Clarity PPM SaaS

Issue/Introduction

Clarity Saas Xog client is installed on internal batch server where other applications are hosted and vulnerability has been found for the unsupported version of Log4j.

Cause

This is due to older Xog client versions.

Resolution

Installing Xog client from the Clarity 16.0.2 version will take care of the vulnerability, update will come with version 2.x (mitigated).

It is good practice to update your XOG client installation with newer versions of Clarity (on upgrades) to keep up to date with what is available for XOG.

Additional Information

Need XOG details for SaaS customer

The updated version of OpenJDK that Clarity is using

Specifications: Clarity Components: Java > AdoptOpenJDK 11.0.14+9 or higher patch level