Security Bulletin
Summary
IBM Security Verify Privilege Products NOT Affected by CVE-2021-44228 Exploit.
Vulnerability Details
OEM partner ThycoticCentrify, after conducting extensive research product code base, it is determined that none of the products outlined below are using the vulnerable Java library log4j with JNDI exploit (CVE-2021-44228). Additionally, none of the products outlined below are built on the Java programming language, preventing the library to be present.
- IBM Security Verify Privilege Vault
- IBM Security Verify Privilege Manager
- IBM Security Verify Privilege Account Lifecycle Manager
- IBM Security Verify Privilege Behavior Analytics
- IBM Security Verify Privilege DevOps Vault
- IBM Security Verify Privilege Vault Remote
- IBM Security Verify Privilege Server Suite
Get Notified about Future Security Bulletins
References
*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.
Disclaimer
Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.
Document Location
Worldwide
Was this topic helpful?
Document Information
Modified date:
13 December 2021
UID
ibm16525770