LOG4J: GeoEvent Server Vulnerable - JAR files return with vulnerabilities every day

396
1
09-28-2022 09:30 AM
Labels (2)
PatrickBurwell
New Contributor

.\ArcGIS\Server\GeoEvent\system\org\ops4j\pax\logging\pax-logging-log4j2\1.10.1\pax-logging-log4j2-1.10.1.jar file keeps returning after we delete the folder. Whatever is creating the file is what is vulnerable.

ArcGIS GeoEvent Server 10.7.1
Installed 9/22 

Tags (1)
0 Kudos
1 Reply
George_Thompson
Esri Frequent Contributor

May want to look at this blog: https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/arcgis-software-and-cve-2... under Security Scanner False Positives & https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/arcgis-enterprise-log4j-securi... 

Otherwise I recommend contacting Esri technical support for more guidance.

--- George T.
0 Kudos