Our vulnerability scan has flagged the following Log4j files as vulnerable, as the current version in use is 2.19.0.
Based on the reported Log4j vulnerabilities (CVE-2026-49844), the recommended solution is to upgrade to version 2.25.5.
Kindly advise whether the DU is impacted by these Log4j vulnerabilities?
Path : /u02/app/orsyp/DUAS/UNIABC_XXX06/bin/bin_java/log4j-core.jar
Installed version : 2.19.0
Fixed version : 2.25.5
Path : /u02/app/orsyp/DUAS/UNIABC_XXX06/bin/bin_java/log4j-jcl.jar
Installed version : 2.19.0
Fixed version : 2.25.5
Path : /u02/app/orsyp/7.00.11/du_as_7.00.11_linux_26_64/bin_java/log4j-core.jar
Installed version : 2.19.0
Fixed version : 2.25.5
Path : /u02/app/orsyp/7.00.11/du_as_7.00.11_linux_26_64/bin_java/log4j-jcl.jar
Installed version : 2.19.0
Fixed version : 2.25.5
DU 7.00.11
Engineering confirmed that none of the DU components are affected with this vulnerability.
Additionally the log4j will be upgraded to 2.25.5 in 7.01.31 release