Dell BSAFE: Usage of Apache Log4j by Dell BSAFE toolkits
Resumen: This article provides a list of security vulnerabilities that cannot be exploited with Dell BSAFE Crypto-J, SSL-J, or Cert-J, but which may be identified by security scanners.
Este artículo se aplica a
Este artículo no se aplica a
Este artículo no está vinculado a ningún producto específico.
No se identifican todas las versiones del producto en este artículo.
Tipo de artículo de seguridad
Security KB
Identificador de CVE
CVE-2021-4104, CVE-2021-44228, CVE-2021-44832, CVE-2021-45046, CVE-2021-45105
Resumen del problema
Dell BSAFE Crypto-J, Dell BSAFE SSL-J, and Dell BSAFE Cert-J do not use Apache Log4j for logging, nor do they have any dependencies on Log4j at runtime.
Recomendaciones
Dell BSAFE Java toolkits, including Crypto-J, SSL-J, and Cert-J, do not use Apache Log4j for logging. If you are receiving the pre-compiled jar files from Dell, no action is necessary.
Some BSAFE customers may have a source code license agreement in place with Dell, allowing customers to receive a source code package and produce Crypto-J, SSL-J, or Cert-J jar files. Older versions of such source code packages had a dependency on a third-party package which, itself, had a dependency on Apache Log4j 1.2.x. Most recent versions of supported source code packages do not include any dependencies on Log4j 1.2.x or 2.x.
As BSAFE Cert-J reaches End Of Support Life in January 2022 with a migration path to use Crypto-J JCE, no new source code package will be created.
Customers still building the impacted BSAFE source code packages are advised to do one of the following:
Some BSAFE customers may have a source code license agreement in place with Dell, allowing customers to receive a source code package and produce Crypto-J, SSL-J, or Cert-J jar files. Older versions of such source code packages had a dependency on a third-party package which, itself, had a dependency on Apache Log4j 1.2.x. Most recent versions of supported source code packages do not include any dependencies on Log4j 1.2.x or 2.x.
| Product | Last version impacted | Remediation |
|---|---|---|
| BSAFE SSL-J source code package | 6.2.7 | SSL-J 6.3 and later are not impacted |
| BSAFE Crypto-J source code package | 6.2.4 | Crypto-J 6.2.5 and later are not impacted |
| BSAFE Cert-J source code package | 6.2.4 | Not Applicable |
As BSAFE Cert-J reaches End Of Support Life in January 2022 with a migration path to use Crypto-J JCE, no new source code package will be created.
Customers still building the impacted BSAFE source code packages are advised to do one of the following:
- Disable the build target called "confidence.coverage" to fully mitigate the issue; or
- Upgrade the third-party component (Cobertura) having a dependency on Log4j; or
- Upgrade their build environments to use the most recent source packages of SSL-J and / or Crypto-J
Descargo de responsabilidad
Productos afectados
BSAFE Cert-J, BSAFE Crypto-J, BSAFE SSL-JPropiedades del artículo
Número del artículo: 000195054
Tipo de artículo: Security KB
Última modificación: 24 ene 2022
Versión: 1
Encuentre respuestas a sus preguntas de otros usuarios de Dell
Servicios de soporte
Compruebe si el dispositivo está cubierto por los servicios de soporte.