AEM - log4j | Community
Skip to main content
This post is no longer active and is closed to new replies. Need help? Start a new post to ask your question.
Best answer by joerghoh

Please report this to the support, that this page should be amended with these 2 additional CVEs.

2 replies

Raja-Karuppsamy
Community Advisor
Community Advisor
January 5, 2022

@brentd5354857 

Navigate to OSGi bundles console - look for log4j bundle version -> All versions from all from 2.0-beta9 to 2.14.1 are impacted.

Please refer this article for AEM log4j vulnerability (CVE-2021-44228) :
https://www.albinsblog.com/2021/12/apache-log4j2-remote-code-execution-through-JNDI-endpoints.html

 

 

January 5, 2022

First off thats a 3RD PARTY!  Second off it doesn't even list the 4th CVE-2021-44228.

 

We pay Adobe money for this product, THEY need to list details about ALL 4 CVE's for log4j.

joerghoh
Adobe Employee
joerghohAdobe EmployeeAccepted solution
Adobe Employee
January 5, 2022

Please report this to the support, that this page should be amended with these 2 additional CVEs.