Dell BSAFE: Usage of Apache Log4j by Dell BSAFE toolkits

Resumen: This article provides a list of security vulnerabilities that cannot be exploited with Dell BSAFE Crypto-J, SSL-J, or Cert-J, but which may be identified by security scanners.

Este artículo se aplica a Este artículo no se aplica a Este artículo no está vinculado a ningún producto específico. No se identifican todas las versiones del producto en este artículo.

Tipo de artículo de seguridad

Security KB

Identificador de CVE

CVE-2021-4104, CVE-2021-44228, CVE-2021-44832, CVE-2021-45046, CVE-2021-45105

Resumen del problema

Dell BSAFE Crypto-J, Dell BSAFE SSL-J, and Dell BSAFE Cert-J do not use Apache Log4j for logging, nor do they have any dependencies on Log4j at runtime.

Recomendaciones

Dell BSAFE Java toolkits, including Crypto-J, SSL-J, and Cert-J, do not use Apache Log4j for logging. If you are receiving the pre-compiled jar files from Dell, no action is necessary.

Some BSAFE customers may have a source code license agreement in place with Dell, allowing customers to receive a source code package and produce Crypto-J, SSL-J, or Cert-J jar files. Older versions of such source code packages had a dependency on a third-party package which, itself, had a dependency on Apache Log4j 1.2.x. Most recent versions of supported source code packages do not include any dependencies on Log4j 1.2.x or 2.x.
 
Product Last version impacted Remediation
BSAFE SSL-J source code package 6.2.7 SSL-J 6.3 and later are not impacted
BSAFE Crypto-J source code package 6.2.4 Crypto-J 6.2.5 and later are not impacted
BSAFE Cert-J source code package 6.2.4 Not Applicable

As BSAFE Cert-J reaches End Of Support Life in January 2022 with a migration path to use Crypto-J JCE, no new source code package will be created.

Customers still building the impacted BSAFE source code packages are advised to do one of the following:
  • Disable the build target called "confidence.coverage" to fully mitigate the issue; or
  • Upgrade the third-party component (Cobertura) having a dependency on Log4j; or
  • Upgrade their build environments to use the most recent source packages of SSL-J and / or Crypto-J

Productos afectados

BSAFE Cert-J, BSAFE Crypto-J, BSAFE SSL-J
Propiedades del artículo
Número del artículo: 000195054
Tipo de artículo: Security KB
Última modificación: 24 ene 2022
Versión:  1
Encuentre respuestas a sus preguntas de otros usuarios de Dell
Servicios de soporte
Compruebe si el dispositivo está cubierto por los servicios de soporte.