I've been asked to look into assisting with mitigating CVE-2021-45105 in our ARCGIS enterprise environment. Searching log4j, I did not find any other discussions relating to this specific CVE so I'm asking it here.
The python script only seems to address CVE-2021-44228 and CVE-2021-45046.
Anyone else working on this, or have a solution?
The ESRI blog referencing this reccomends applying Web Application Firewall rules to mitigate this. ESRI tech support (even our premium support tier) is unable to advise or assist us with these firewall rules.
So I've forwarded the Web Application Firewall doc included in the log4j blog post from ESRI to our network team, and while I'm waiting for them to get back to me, I thought I'd see if anyone else has done anything on this specific CVE.