IBM Support

Security Bulletin: IBM Security Verify Privilege Products NOT Affected by CVE-2021-44228 Exploit

Created by Raghavan Arun on
Published URL:
https://www.ibm.com/support/pages/node/6525770
6525770

Security Bulletin


Summary

IBM Security Verify Privilege Products NOT Affected by CVE-2021-44228 Exploit.

Vulnerability Details

OEM partner ThycoticCentrify, after conducting extensive research product code base, it is determined that none of the products outlined below are using the vulnerable Java library log4j with JNDI exploit (CVE-2021-44228). Additionally, none of the products outlined below are built on the Java programming language, preventing the library to be present.

  • IBM Security Verify Privilege Vault
  • IBM Security Verify Privilege Manager
  • IBM Security Verify Privilege Account Lifecycle Manager
  • IBM Security Verify Privilege Behavior Analytics
  • IBM Security Verify Privilege DevOps Vault
  • IBM Security Verify Privilege Vault Remote
  • IBM Security Verify Privilege Server Suite

Get Notified about Future Security Bulletins

References

Off
https://docs.thycotic.com/bulletins/current/2021/cve-2021-44228-exploit.md
https://nvd.nist.gov/vuln/detail/CVE-2021-44228

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

Document Location

Worldwide

[{"Type":"MASTER","Line of Business":{"code":"LOB24","label":"Security Software"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SS2N2U","label":"IBM Security Verify Privilege"},"ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"All Versions"}]

Document Information

Modified date:
13 December 2021

UID

ibm16525770