General Discussion & Announcements

 View Only
  • 1.  Log4j Vulnerability Update

    ROCKETEER
    Posted 12-14-2021 13:18

    Customer Security is a top priority for Rocket Software and is an essential part our customer experience. We are constantly improving our capabilities, practices, and our people to deliver products and services that meet the highest security standards. 

    However, even with this commitment to security excellence, there are still cases where vulnerabilities can be present.

    The Rocket Software Security Teams were recently made aware of a vulnerability in the widely utilized Apache Java logging library Log4j2 package that can allow an attacker unauthenticated remote code execution (RCE) access to the servers that the run this software. This vulnerability has been tracked as CVE-2021-44228 and is classified as severe.

    With regard to Rocket Software's products, we have identified which software platforms and versions contain the vulnerable Log4j2 utility code and are actively remediating the affected products.  Rocket Software highly recommends that customers running impacted software packages follow the Apache recommended mitigation process which can be found here.

    Rocket Software's information security team has implemented preliminary mitigations to protect our enterprise resources against this threat. We continue to evaluate this evolving risk and will deploy additional preventive and detective capabilities within our enterprise technology environment.

    Security within our products, services and enterprise is of the upmost importance to Rocket Software. If you have any additional questions or need assistance, please contact Rocket Customer Support or ASG Customer Support.

    ------------------------------
    David Andrews
    Head of Customer Advocacy
    Rocket Software
    South Salem NY US
    ------------------------------


  • 2.  RE: Log4j Vulnerability Update

    PARTNER
    Posted 12-15-2021 10:49

    Hi David,

    You said:
    With regard to Rocket Software's products, we have identified which software platforms and versions contain the vulnerable Log4j2 utility code and are actively remediating the affected products.  Rocket Software highly recommends that customers running impacted software packages follow the Apache recommended mitigation process which can be found here.

    Okay - how do I as a customer determine if I'm running an "impacted software package"? 

    I asked earlier today in the Universe specific forum if Universe was affected.   My post was promptly responded to, telling me that Universe isn't affected, but that an official statement would be forthcoming.

    If your statement is "the official statement" from Rocket - it's unfortunately lacking the detail I need to respond to my management with.

    Thanks in advance for any further clarification you can provide.



    ------------------------------
    Allen Egerton
    Developer
    SS&C Technologies Inc
    CT US
    ------------------------------



  • 3.  RE: Log4j Vulnerability Update

    ROCKETEER
    Posted 12-15-2021 15:06
    Edited by David Andrews 12-15-2021 15:06
    Allen,

    Chris posted a detailed response in the UniVerse and UniData thread that explained what the situation is for all of the MV products. If that did not answer your question then please log a case with support and we will respond to you.

    Thanks
    Kevin.

    ------------------------------
    Kevin Drury
    Senior Manager, Technical Support Engineering
    Rocket Internal - All Brands
    Denver CO US
    ------------------------------



  • 4.  RE: Log4j Vulnerability Update

    PARTNER
    Posted 12-15-2021 10:49
    Which products are affected?

    ------------------------------
    Chris Wolcz
    Senior Software Developer
    Execontrol Global Solutions
    Clifton Park NY US
    ------------------------------



  • 5.  RE: Log4j Vulnerability Update

    ROCKETEER
    Posted 12-15-2021 15:06
    Edited by David Andrews 12-15-2021 15:06
    Chris,

    Each of the product areas has a response that pertains to the products in that area. Here's the summary for the products I suspect you are interested in.

    Thanks
    Kevin.

    ------------------------------
    Kevin Drury
    Senior Manager, Technical Support Engineering
    Rocket Internal - All Brands
    Denver CO US
    ------------------------------