Just a query, my company occasionally does sweeps on applications on end user devices to ensure there are no files within that are vulnerable to being attacked.
Recently they have marked Rocket MV Basic’s extension file, ls4b.jar as vulnerable, and want to know if this file is dependent on the application, and if there is a possibility to update this file, or if this file will be staying as it is?
Thank you.
Best answer by Doug Averch
Since Rocket Software embedded log4j in ls4b.jar you would have to know what version it is. If log4j is version 2.17 or less then it needs to be upgraded. See this link. The current version of log4j is 2.26. It should be noted that Rocket Software does not standardize it logging throughout it products, for example, xAdmin uses slf4j or logback call all be problematic if you do not keep up on upgrades.
Since Rocket Software embedded log4j in ls4b.jar you would have to know what version it is. If log4j is version 2.17 or less then it needs to be upgraded. See this link. The current version of log4j is 2.26. It should be noted that Rocket Software does not standardize it logging throughout it products, for example, xAdmin uses slf4j or logback call all be problematic if you do not keep up on upgrades.