<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ArcGIS Enterprise Log4j Vulnerability (CVE-2021-44228) Patch or Mitigation? in ArcGIS Enterprise Questions</title>
    <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125189#M31867</link>
    <description>&lt;P&gt;also interested&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 12 Dec 2021 07:31:13 GMT</pubDate>
    <dc:creator>OmerBen-Asher</dc:creator>
    <dc:date>2021-12-12T07:31:13Z</dc:date>
    <item>
      <title>ArcGIS Enterprise Log4j Vulnerability (CVE-2021-44228) Patch or Mitigation?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125162#M31861</link>
      <description>&lt;P&gt;Good afternoon, is there any patches in the works or potential mitigation steps for the latest java log4j vulnerability (CVE-2021-44228)?&amp;nbsp; I know that GeoEvent server uses log4j and can assume some other enterprise server's or portal potentially do as well.&amp;nbsp; Any help would be appreciated in resolving this zero-day.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Wed, 15 Dec 2021 18:44:45 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125162#M31861</guid>
      <dc:creator>Carl_Flint</dc:creator>
      <dc:date>2021-12-15T18:44:45Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Enterprise Log4j Vulnerability (CVE-2021-44228) Patch or Mitigation?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125176#M31862</link>
      <description>&lt;P&gt;I'm also waiting to hear any news from ESRI about this.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 11 Dec 2021 21:16:37 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125176#M31862</guid>
      <dc:creator>IngaPlayle1</dc:creator>
      <dc:date>2021-12-11T21:16:37Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Enterprise Log4j Vulnerability (CVE-2021-44228) Patch or Mitigation?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125178#M31864</link>
      <description>&lt;P&gt;A quick filesystem search on a stand-alone ArcGIS Server installation shows numerous components using log4j.&amp;nbsp; This won't just be about patching a file, but lots of files involving multiple components of multiple products.&amp;nbsp; A not-so-happy holidays for Esri dev teams.&lt;/P&gt;</description>
      <pubDate>Sat, 11 Dec 2021 21:31:01 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125178#M31864</guid>
      <dc:creator>JoshuaBixby</dc:creator>
      <dc:date>2021-12-11T21:31:01Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Enterprise Log4j Vulnerability (CVE-2021-44228) Patch or Mitigation?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125183#M31865</link>
      <description>&lt;P&gt;Really interested on this topic too.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 12 Dec 2021 01:01:10 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125183#M31865</guid>
      <dc:creator>AndresEcheverri</dc:creator>
      <dc:date>2021-12-12T01:01:10Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Enterprise Log4j Vulnerability (CVE-2021-44228) Patch or Mitigation?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125184#M31866</link>
      <description>&lt;P&gt;I found it here on my Portal for ArcGIS server:&lt;/P&gt;&lt;P&gt;E:\arcgisportal\upgrade-backup\10.5.1\dsdata\elasticsearch_2.3.2\lib&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;File Name:&lt;/P&gt;&lt;P&gt;apache-log4j-extras-1.2.17.jar&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The file is located in a 10.5.1 backup folder. I am currently running 10.8.1. Does it matter?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 12 Dec 2021 01:34:49 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125184#M31866</guid>
      <dc:creator>JohnBrockwell</dc:creator>
      <dc:date>2021-12-12T01:34:49Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Enterprise Log4j Vulnerability (CVE-2021-44228) Patch or Mitigation?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125189#M31867</link>
      <description>&lt;P&gt;also interested&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 12 Dec 2021 07:31:13 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125189#M31867</guid>
      <dc:creator>OmerBen-Asher</dc:creator>
      <dc:date>2021-12-12T07:31:13Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Enterprise Log4j Vulnerability (CVE-2021-44228) Patch or Mitigation?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125195#M31868</link>
      <description>&lt;P&gt;Following. &amp;nbsp;Thanks for raising. &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 12 Dec 2021 09:29:41 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125195#M31868</guid>
      <dc:creator>Scott_Tansley</dc:creator>
      <dc:date>2021-12-12T09:29:41Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Enterprise Log4j Vulnerability (CVE-2021-44228) Patch or Mitigation?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125201#M31869</link>
      <description>&lt;P&gt;Also following.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 12 Dec 2021 11:05:26 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125201#M31869</guid>
      <dc:creator>MarkusRuottinen</dc:creator>
      <dc:date>2021-12-12T11:05:26Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Enterprise Log4j Vulnerability (CVE-2021-44228) Patch or Mitigation?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125202#M31870</link>
      <description>&lt;P&gt;ArcGIS Enterprise base deployment shows more then 50 affected .jar files (Esri and 3rd party like Elasticsearch).&lt;BR /&gt;&lt;BR /&gt;Looking forward to any updates/patches/support.&lt;BR /&gt;&lt;BR /&gt;Cheers&lt;BR /&gt;Kai&lt;/P&gt;</description>
      <pubDate>Sun, 12 Dec 2021 11:10:28 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125202#M31870</guid>
      <dc:creator>Kai_Ole_Rogge_Allianz</dc:creator>
      <dc:date>2021-12-12T11:10:28Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Enterprise Log4j Vulnerability (CVE-2021-44228) Patch or Mitigation?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125209#M31871</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Do you know is it possible to set environment variables which ArcGIS Server uses in windows server.?&lt;/P&gt;&lt;P&gt;I ask this because &lt;A href="https://logging.apache.org/log4j/2.x/security.html" target="_blank" rel="noopener"&gt;https://logging.apache.org/log4j/2.x/security.html&lt;/A&gt; says: &lt;EM&gt;"Mitigation: In releases &amp;gt;=2.10, this behavior can be mitigated by setting either the system property log4j2.formatMsgNoLookups or the environment variable LOG4J_FORMAT_MSG_NO_LOOKUPS to true.&lt;/EM&gt; "&lt;/P&gt;&lt;P&gt;I just ask, I don't know is this correct solution.&lt;/P&gt;&lt;P&gt;Br&lt;/P&gt;&lt;P&gt;Markus&lt;/P&gt;</description>
      <pubDate>Sun, 12 Dec 2021 12:02:21 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125209#M31871</guid>
      <dc:creator>MarkusRuottinen</dc:creator>
      <dc:date>2021-12-12T12:02:21Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Enterprise Log4j Vulnerability (CVE-2021-44228) Patch or Mitigation?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125223#M31872</link>
      <description>&lt;P&gt;Do we have any updates on this?&amp;nbsp; &amp;nbsp;Do we have to shutdown the portal and server services as a precaution?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 12 Dec 2021 14:17:56 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125223#M31872</guid>
      <dc:creator>Swani_Jesus_Captonsiluvairajan</dc:creator>
      <dc:date>2021-12-12T14:17:56Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Enterprise Log4j Vulnerability (CVE-2021-44228) Patch or Mitigation?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125243#M31874</link>
      <description>&lt;P&gt;Our current statement is available on &lt;A href="https://trust.arcgis.com" target="_blank"&gt;https://trust.arcgis.com&lt;/A&gt;. Look for more updates as this issue evolves.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 12 Dec 2021 19:40:35 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125243#M31874</guid>
      <dc:creator>RandallWilliams</dc:creator>
      <dc:date>2021-12-12T19:40:35Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Enterprise Log4j Vulnerability (CVE-2021-44228) Patch or Mitigation?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125246#M31875</link>
      <description>&lt;P&gt;Following.&lt;/P&gt;</description>
      <pubDate>Sun, 12 Dec 2021 21:11:20 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125246#M31875</guid>
      <dc:creator>PhilipOrlando</dc:creator>
      <dc:date>2021-12-12T21:11:20Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Enterprise Log4j Vulnerability (CVE-2021-44228) Patch or Mitigation?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125307#M31880</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;we use some older installs of ArcGIS Server (10.3.1 and 10.6.1). Scanning the install for log4j shows only older versions of log4j under&amp;nbsp;C:\Program Files\ArcGIS\Server\framework dated 2005 and with version 1.2.12 in the manifest. I could not find any reference to the class or function names cited in the&amp;nbsp;CVE-2021-44228 advisory. My initial thought is that these versions of ArcGIS Server do not use log4j v2 and may not be vulnerable as a result.&lt;/P&gt;&lt;P&gt;I used this command from CMD using the Java SDK utility jar.exe to list the Java classes :&lt;/P&gt;&lt;P&gt;C:\Program Files\ArcGIS\Server\framework&amp;gt;forfiles /S /M *.jar /C "cmd /c jar -tvf @file | findstr /C:"log4j" &amp;amp;&amp;amp; echo @path" &amp;gt; C:\Temp\log4j_info.txt&amp;nbsp;&lt;/P&gt;&lt;P&gt;(see&amp;nbsp;&lt;A href="https://www.windows-commandline.com/search-classes-in-jar-file/" target="_blank"&gt;https://www.windows-commandline.com/search-classes-in-jar-file/&lt;/A&gt;)&lt;/P&gt;&lt;P&gt;Unzipping a copy of a Jar file (rename &amp;amp; unzip) shows the version in the manifest.mf file&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 06:27:40 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125307#M31880</guid>
      <dc:creator>Anonymous User</dc:creator>
      <dc:date>2021-12-13T06:27:40Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Enterprise Log4j Vulnerability (CVE-2021-44228) Patch or Mitigation?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125360#M31882</link>
      <description>&lt;P&gt;Hi Randall,&lt;/P&gt;&lt;P&gt;the statement does not make clear a couple of important points:&lt;/P&gt;&lt;P&gt;- does 10.9.1 version definitevely solves the problem ?&lt;/P&gt;&lt;P&gt;- is the problem only for ArcGIS Enterprise JAVA version or also for .Net one ?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Gianni&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 11:18:29 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125360#M31882</guid>
      <dc:creator>GianniCampanile2</dc:creator>
      <dc:date>2021-12-13T11:18:29Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Enterprise Log4j Vulnerability (CVE-2021-44228) Patch or Mitigation?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125367#M31883</link>
      <description>&lt;P&gt;looking at my servers, some have log4j 2.x, some don't - I realize it is still early on this, but an exact matrix of what does and doens't have this would be really useful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 12:50:43 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125367#M31883</guid>
      <dc:creator>AdrianMarsden</dc:creator>
      <dc:date>2021-12-13T12:50:43Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Enterprise Log4j Vulnerability (CVE-2021-44228) Patch or Mitigation?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125385#M31884</link>
      <description>&lt;P&gt;I am on ArcGIS Server 10.6.1&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have found this Jar, which I think is affected :&lt;/P&gt;&lt;P&gt;&lt;EM&gt;"C:\Program Files\ArcGIS\Server\framework\lib\shared\log4j-core-2.8.2.jar"&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Following the suggestions from&lt;/P&gt;&lt;P&gt;&lt;A href="https://blog.cloudflare.com/inside-the-log4j2-vulnerability-cve-2021-44228/" target="_blank" rel="noopener"&gt;https://blog.cloudflare.com/inside-the-log4j2-vulnerability-cve-2021-44228/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I am going to delete from that Jar:&lt;/P&gt;&lt;PRE&gt;org/apache/logging/log4j/core/lookup/JndiLookup.class&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;I am also going to add the System environment variable&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;LOG4J_FORMAT_MSG_NO_LOOKUPS=true&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Then reboot&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Question: Are there any other Jars to fix or reconfigure?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 13:29:12 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125385#M31884</guid>
      <dc:creator>SPisOs</dc:creator>
      <dc:date>2021-12-13T13:29:12Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Enterprise Log4j Vulnerability (CVE-2021-44228) Patch or Mitigation?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125393#M31886</link>
      <description>&lt;P&gt;the blog says "mitigated" with 10.9 - "&lt;SPAN&gt;to make (something) less severe, harmful, or painful.&amp;nbsp;"&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 13:53:44 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125393#M31886</guid>
      <dc:creator>AdrianMarsden</dc:creator>
      <dc:date>2021-12-13T13:53:44Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Enterprise Log4j Vulnerability (CVE-2021-44228) Patch or Mitigation?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125395#M31887</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How do I check the Log4j Vulnerability to my current system? As I am currently using&amp;nbsp; ESRI Enterprise 10.4&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 14:03:01 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125395#M31887</guid>
      <dc:creator>SreehariGomasani</dc:creator>
      <dc:date>2021-12-13T14:03:01Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Enterprise Log4j Vulnerability (CVE-2021-44228) Patch or Mitigation?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125397#M31888</link>
      <description>&lt;P&gt;Hi Adrian,&lt;/P&gt;&lt;P&gt;the mitigation statement is for 10.8.1 version, while regarding 10.9 it says "We recommend updating to the latest version of 10.9.1 for the strongest security posture" and I can't figure out if it's a solution or just a generic recommendation.&lt;/P&gt;&lt;P&gt;Gianni&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 14:08:43 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125397#M31888</guid>
      <dc:creator>GianniCampanile2</dc:creator>
      <dc:date>2021-12-13T14:08:43Z</dc:date>
    </item>
  </channel>
</rss>

