ibmi-brunch-learn

Announcement

Collapse
No announcement yet.

Is IBMi IWS impacted due to log4J vulnerability

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • deep
    replied
    Thank you very much for the responses. That helped. IBM-I http server is listed in their product list as not impacted.

    Leave a comment:


  • Scott Klement
    replied
    IBM's official response to this is here: https://www.ibm.com/blogs/psirt/ they have a list of products that are affected/unaffected and are updating the list as they find others.

    Leave a comment:


  • JonBoy
    replied
    Simplest and most accurate answer will come from a Service call to IBM.

    I would expect to have seen warnings on IBM's web site if it were an issue but ...

    It wouldn't be a bad idea to dig out Scott Forstie's SQL query that digs into your IFS for any sign of the log4j code. You may have installed other things that use it that you are unaware of.

    Leave a comment:


  • deep
    started a topic Is IBMi IWS impacted due to log4J vulnerability

    Is IBMi IWS impacted due to log4J vulnerability

    Hi

    I could not find any information about IBM-I IWS vulnerability due to Log4J. We use IWS and wanted to know if it used apache Log4J logger and hence whether it is vulnerable. Appreciate any help.
Working...
X