Symantec Identity Manager- CVE-2021-4104 - Is Identity Manager exposed to the JMSAppender Vulnerability?
search cancel

Symantec Identity Manager- CVE-2021-4104 - Is Identity Manager exposed to the JMSAppender Vulnerability?

book

Article ID: 231982

calendar_today

Updated On:

Products

CA Identity Suite CA Identity Manager

Issue/Introduction

Recent vulnerability scans are showing Log4j v1.2x is vulnerable against CVE-2021-4104. Is Identity Manager exposed to the JMSAppender Vulnerability? 

Environment

Release : 14.X

Component : Symantec Identity Manager

Resolution

Sustaining Engineering has reviewed this vulnerability and determined that Identity Manager is not vulnerable to CVE-2021-4104. The JMSAppender is not configured in any OOTB log4j configuration files. The Log4j configuration file not accessible to remote hackers.