After upgrading all Test Data Manager components to version 4.11, vulnerability scanners (such as Tenable.io) continue to report Apache Log4j vulnerabilities associated with the Fast Data Masker component.
The findings typically point to the following path: C:\Program Files\Grid-Tools\FastDataMasker\FDMServlet.jar
Reported CVEs:
verifyHostName attribute.Product: Test Data Manager (TDM) Component: Fast Data Masker (FDM) Release: 4.11.x
The base release of TDM 4.11 does not contain the specific Log4j version (2.25.4 or newer) required to remediate these specific CVEs within the FDMServlet.jar file used by Fast Data Masker.
Broadcom Engineering has released a specific patch for Fast Data Masker to address these vulnerabilities by updating the internal Log4j libraries.
To resolve the issue:
FDMServlet.jar and associated libraries in the FDM installation directory with the versions provided in the patch.Download Location: Patches can be found on the page.