Security Bulletin
Summary
IBM Security Verify Governance Products NOT Affected by CVE-2021-44228 Exploit
Vulnerability Details
After conducting extensive research product code base, it is determined that none of the products outlined below are using the vulnerable Java library log4j version with JNDI exploit (CVE-2021-44228)
- IBM Security Identity Governance and Intelligence*
- IBM Security Identity Manager*
- IBM Security Verify Governance*
* All supported versions and all their add-on components such as Adapters and Information Queue
Updated Tuesday, Dec 21 2021
Clarification for customers running IBM Security Verify Governance Products (Identity Manager) mentioned in this bulletin deployed as Software Stack (not Virtual Appliance):
- Apply the WebSphere Application Server Interim Fix for your existing FP level. Don’t apply WebSphere Application Server 9.0.5.10 ( https://www.ibm.com/support/pages/node/6526686 )
Updated Monday, Dec 20 2021
Refer to the WebSphere Application Server security bulletins for additional information:
- Customers running IBM Security Verify Governance Products (Identity Manager) mentioned in this bulletin deployed as Software Stack (not Virtual Appliance) must refer to WebSphere Application Server security bulletin and apply the required WebSphere patches.
- IBM Security Verify Governance Products mentioned in this bulletin deployed as Virtual Appliances do not use the WebSphere Application Server Admin Console or the UDDI Registry application, therefore they are not affected by the WebSphere Application Server vulnerability.
Get Notified about Future Security Bulletins
References
Off
*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.
Disclaimer
Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.
Document Location
Worldwide
[{"Line of Business":{"code":"LOB24","label":"Security Software"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSBM27","label":"IBM Security Verify Governance"},"ARM Category":[{"code":"a8m0z0000001hXBAAY","label":"Identity Governance \u0026 Intelligence"},{"code":"a8m0z0000001hXGAAY","label":"Identity Manager"}],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"All Versions","Type":"MASTER"},{"Type":"MASTER","Line of Business":{"code":"LOB24","label":"Security Software"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSGHJR","label":"IBM Security Identity Governance and Intelligence"},"ARM Category":[{"code":"a8m0z0000001hXBAAY","label":"Identity Governance \u0026 Intelligence"},{"code":"a8m0z0000001hXGAAY","label":"Identity Manager"}],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"All Versions"},{"Type":"MASTER","Line of Business":{"code":"LOB24","label":"Security Software"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSRMWJ","label":"IBM Security Identity Manager"},"ARM Category":[{"code":"a8m0z0000001hXGAAY","label":"Identity Manager"}],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"All Versions"}]
Was this topic helpful?
Document Information
Modified date:
04 April 2022
UID
ibm16526752