<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ArcGIS Enterprise Log4j Vulnerability (CVE-2021-44228) Patch or Mitigation? in ArcGIS Enterprise Questions</title>
    <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1127044#M32028</link>
    <description>&lt;P&gt;Hi Cort, I looked at Server at both 10.3.1 and 10.6.1 for this issue earlier. Most likely 10.5 has no installs of log4j v2 (which is where the current vulnerability lies). However it most likely has installs of log4j v1 which is now deprecated, and has bugs of it's own (but not as severe). So the supplied patch won't do anything for your 10.5 install. I can only suggest following ESRI's advice in the blog re upgrades etc. Of course upgrading is often easier said than done, depending on your resources.&lt;/P&gt;</description>
    <pubDate>Fri, 17 Dec 2021 03:43:50 GMT</pubDate>
    <dc:creator>JohnGibson2</dc:creator>
    <dc:date>2021-12-17T03:43:50Z</dc:date>
    <item>
      <title>ArcGIS Enterprise Log4j Vulnerability (CVE-2021-44228) Patch or Mitigation?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125162#M31861</link>
      <description>&lt;P&gt;Good afternoon, is there any patches in the works or potential mitigation steps for the latest java log4j vulnerability (CVE-2021-44228)?&amp;nbsp; I know that GeoEvent server uses log4j and can assume some other enterprise server's or portal potentially do as well.&amp;nbsp; Any help would be appreciated in resolving this zero-day.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Wed, 15 Dec 2021 18:44:45 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125162#M31861</guid>
      <dc:creator>Carl_Flint</dc:creator>
      <dc:date>2021-12-15T18:44:45Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Enterprise Log4j Vulnerability (CVE-2021-44228) Patch or Mitigation?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125176#M31862</link>
      <description>&lt;P&gt;I'm also waiting to hear any news from ESRI about this.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 11 Dec 2021 21:16:37 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125176#M31862</guid>
      <dc:creator>IngaPlayle1</dc:creator>
      <dc:date>2021-12-11T21:16:37Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Enterprise Log4j Vulnerability (CVE-2021-44228) Patch or Mitigation?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125178#M31864</link>
      <description>&lt;P&gt;A quick filesystem search on a stand-alone ArcGIS Server installation shows numerous components using log4j.&amp;nbsp; This won't just be about patching a file, but lots of files involving multiple components of multiple products.&amp;nbsp; A not-so-happy holidays for Esri dev teams.&lt;/P&gt;</description>
      <pubDate>Sat, 11 Dec 2021 21:31:01 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125178#M31864</guid>
      <dc:creator>JoshuaBixby</dc:creator>
      <dc:date>2021-12-11T21:31:01Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Enterprise Log4j Vulnerability (CVE-2021-44228) Patch or Mitigation?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125183#M31865</link>
      <description>&lt;P&gt;Really interested on this topic too.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 12 Dec 2021 01:01:10 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125183#M31865</guid>
      <dc:creator>AndresEcheverri</dc:creator>
      <dc:date>2021-12-12T01:01:10Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Enterprise Log4j Vulnerability (CVE-2021-44228) Patch or Mitigation?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125184#M31866</link>
      <description>&lt;P&gt;I found it here on my Portal for ArcGIS server:&lt;/P&gt;&lt;P&gt;E:\arcgisportal\upgrade-backup\10.5.1\dsdata\elasticsearch_2.3.2\lib&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;File Name:&lt;/P&gt;&lt;P&gt;apache-log4j-extras-1.2.17.jar&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The file is located in a 10.5.1 backup folder. I am currently running 10.8.1. Does it matter?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 12 Dec 2021 01:34:49 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125184#M31866</guid>
      <dc:creator>JohnBrockwell</dc:creator>
      <dc:date>2021-12-12T01:34:49Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Enterprise Log4j Vulnerability (CVE-2021-44228) Patch or Mitigation?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125189#M31867</link>
      <description>&lt;P&gt;also interested&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 12 Dec 2021 07:31:13 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125189#M31867</guid>
      <dc:creator>OmerBen-Asher</dc:creator>
      <dc:date>2021-12-12T07:31:13Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Enterprise Log4j Vulnerability (CVE-2021-44228) Patch or Mitigation?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125195#M31868</link>
      <description>&lt;P&gt;Following. &amp;nbsp;Thanks for raising. &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 12 Dec 2021 09:29:41 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125195#M31868</guid>
      <dc:creator>Scott_Tansley</dc:creator>
      <dc:date>2021-12-12T09:29:41Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Enterprise Log4j Vulnerability (CVE-2021-44228) Patch or Mitigation?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125201#M31869</link>
      <description>&lt;P&gt;Also following.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 12 Dec 2021 11:05:26 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125201#M31869</guid>
      <dc:creator>MarkusRuottinen</dc:creator>
      <dc:date>2021-12-12T11:05:26Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Enterprise Log4j Vulnerability (CVE-2021-44228) Patch or Mitigation?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125202#M31870</link>
      <description>&lt;P&gt;ArcGIS Enterprise base deployment shows more then 50 affected .jar files (Esri and 3rd party like Elasticsearch).&lt;BR /&gt;&lt;BR /&gt;Looking forward to any updates/patches/support.&lt;BR /&gt;&lt;BR /&gt;Cheers&lt;BR /&gt;Kai&lt;/P&gt;</description>
      <pubDate>Sun, 12 Dec 2021 11:10:28 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125202#M31870</guid>
      <dc:creator>Kai_Ole_Rogge_Allianz</dc:creator>
      <dc:date>2021-12-12T11:10:28Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Enterprise Log4j Vulnerability (CVE-2021-44228) Patch or Mitigation?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125209#M31871</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Do you know is it possible to set environment variables which ArcGIS Server uses in windows server.?&lt;/P&gt;&lt;P&gt;I ask this because &lt;A href="https://logging.apache.org/log4j/2.x/security.html" target="_blank" rel="noopener"&gt;https://logging.apache.org/log4j/2.x/security.html&lt;/A&gt; says: &lt;EM&gt;"Mitigation: In releases &amp;gt;=2.10, this behavior can be mitigated by setting either the system property log4j2.formatMsgNoLookups or the environment variable LOG4J_FORMAT_MSG_NO_LOOKUPS to true.&lt;/EM&gt; "&lt;/P&gt;&lt;P&gt;I just ask, I don't know is this correct solution.&lt;/P&gt;&lt;P&gt;Br&lt;/P&gt;&lt;P&gt;Markus&lt;/P&gt;</description>
      <pubDate>Sun, 12 Dec 2021 12:02:21 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125209#M31871</guid>
      <dc:creator>MarkusRuottinen</dc:creator>
      <dc:date>2021-12-12T12:02:21Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Enterprise Log4j Vulnerability (CVE-2021-44228) Patch or Mitigation?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125223#M31872</link>
      <description>&lt;P&gt;Do we have any updates on this?&amp;nbsp; &amp;nbsp;Do we have to shutdown the portal and server services as a precaution?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 12 Dec 2021 14:17:56 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125223#M31872</guid>
      <dc:creator>Swani_Jesus_Captonsiluvairajan</dc:creator>
      <dc:date>2021-12-12T14:17:56Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Enterprise Log4j Vulnerability (CVE-2021-44228) Patch or Mitigation?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125243#M31874</link>
      <description>&lt;P&gt;Our current statement is available on &lt;A href="https://trust.arcgis.com" target="_blank"&gt;https://trust.arcgis.com&lt;/A&gt;. Look for more updates as this issue evolves.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 12 Dec 2021 19:40:35 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125243#M31874</guid>
      <dc:creator>RandallWilliams</dc:creator>
      <dc:date>2021-12-12T19:40:35Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Enterprise Log4j Vulnerability (CVE-2021-44228) Patch or Mitigation?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125246#M31875</link>
      <description>&lt;P&gt;Following.&lt;/P&gt;</description>
      <pubDate>Sun, 12 Dec 2021 21:11:20 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125246#M31875</guid>
      <dc:creator>PhilipOrlando</dc:creator>
      <dc:date>2021-12-12T21:11:20Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Enterprise Log4j Vulnerability (CVE-2021-44228) Patch or Mitigation?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125307#M31880</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;we use some older installs of ArcGIS Server (10.3.1 and 10.6.1). Scanning the install for log4j shows only older versions of log4j under&amp;nbsp;C:\Program Files\ArcGIS\Server\framework dated 2005 and with version 1.2.12 in the manifest. I could not find any reference to the class or function names cited in the&amp;nbsp;CVE-2021-44228 advisory. My initial thought is that these versions of ArcGIS Server do not use log4j v2 and may not be vulnerable as a result.&lt;/P&gt;&lt;P&gt;I used this command from CMD using the Java SDK utility jar.exe to list the Java classes :&lt;/P&gt;&lt;P&gt;C:\Program Files\ArcGIS\Server\framework&amp;gt;forfiles /S /M *.jar /C "cmd /c jar -tvf @file | findstr /C:"log4j" &amp;amp;&amp;amp; echo @path" &amp;gt; C:\Temp\log4j_info.txt&amp;nbsp;&lt;/P&gt;&lt;P&gt;(see&amp;nbsp;&lt;A href="https://www.windows-commandline.com/search-classes-in-jar-file/" target="_blank"&gt;https://www.windows-commandline.com/search-classes-in-jar-file/&lt;/A&gt;)&lt;/P&gt;&lt;P&gt;Unzipping a copy of a Jar file (rename &amp;amp; unzip) shows the version in the manifest.mf file&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 06:27:40 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125307#M31880</guid>
      <dc:creator>Anonymous User</dc:creator>
      <dc:date>2021-12-13T06:27:40Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Enterprise Log4j Vulnerability (CVE-2021-44228) Patch or Mitigation?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125360#M31882</link>
      <description>&lt;P&gt;Hi Randall,&lt;/P&gt;&lt;P&gt;the statement does not make clear a couple of important points:&lt;/P&gt;&lt;P&gt;- does 10.9.1 version definitevely solves the problem ?&lt;/P&gt;&lt;P&gt;- is the problem only for ArcGIS Enterprise JAVA version or also for .Net one ?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Gianni&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 11:18:29 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125360#M31882</guid>
      <dc:creator>GianniCampanile2</dc:creator>
      <dc:date>2021-12-13T11:18:29Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Enterprise Log4j Vulnerability (CVE-2021-44228) Patch or Mitigation?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125367#M31883</link>
      <description>&lt;P&gt;looking at my servers, some have log4j 2.x, some don't - I realize it is still early on this, but an exact matrix of what does and doens't have this would be really useful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 12:50:43 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125367#M31883</guid>
      <dc:creator>AdrianMarsden</dc:creator>
      <dc:date>2021-12-13T12:50:43Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Enterprise Log4j Vulnerability (CVE-2021-44228) Patch or Mitigation?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125385#M31884</link>
      <description>&lt;P&gt;I am on ArcGIS Server 10.6.1&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have found this Jar, which I think is affected :&lt;/P&gt;&lt;P&gt;&lt;EM&gt;"C:\Program Files\ArcGIS\Server\framework\lib\shared\log4j-core-2.8.2.jar"&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Following the suggestions from&lt;/P&gt;&lt;P&gt;&lt;A href="https://blog.cloudflare.com/inside-the-log4j2-vulnerability-cve-2021-44228/" target="_blank" rel="noopener"&gt;https://blog.cloudflare.com/inside-the-log4j2-vulnerability-cve-2021-44228/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I am going to delete from that Jar:&lt;/P&gt;&lt;PRE&gt;org/apache/logging/log4j/core/lookup/JndiLookup.class&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;I am also going to add the System environment variable&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;LOG4J_FORMAT_MSG_NO_LOOKUPS=true&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Then reboot&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Question: Are there any other Jars to fix or reconfigure?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 13:29:12 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125385#M31884</guid>
      <dc:creator>SPisOs</dc:creator>
      <dc:date>2021-12-13T13:29:12Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Enterprise Log4j Vulnerability (CVE-2021-44228) Patch or Mitigation?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125393#M31886</link>
      <description>&lt;P&gt;the blog says "mitigated" with 10.9 - "&lt;SPAN&gt;to make (something) less severe, harmful, or painful.&amp;nbsp;"&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 13:53:44 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125393#M31886</guid>
      <dc:creator>AdrianMarsden</dc:creator>
      <dc:date>2021-12-13T13:53:44Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Enterprise Log4j Vulnerability (CVE-2021-44228) Patch or Mitigation?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125395#M31887</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How do I check the Log4j Vulnerability to my current system? As I am currently using&amp;nbsp; ESRI Enterprise 10.4&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 14:03:01 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125395#M31887</guid>
      <dc:creator>SreehariGomasani</dc:creator>
      <dc:date>2021-12-13T14:03:01Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Enterprise Log4j Vulnerability (CVE-2021-44228) Patch or Mitigation?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125397#M31888</link>
      <description>&lt;P&gt;Hi Adrian,&lt;/P&gt;&lt;P&gt;the mitigation statement is for 10.8.1 version, while regarding 10.9 it says "We recommend updating to the latest version of 10.9.1 for the strongest security posture" and I can't figure out if it's a solution or just a generic recommendation.&lt;/P&gt;&lt;P&gt;Gianni&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 14:08:43 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-enterprise-log4j-vulnerability-cve-2021/m-p/1125397#M31888</guid>
      <dc:creator>GianniCampanile2</dc:creator>
      <dc:date>2021-12-13T14:08:43Z</dc:date>
    </item>
  </channel>
</rss>

