My Oracle Support Banner

Apache Log4j Security Alert CVE-2021-44228/CVE-2021-45046/CVE-2021-45105/CVE-2021-44832 on Oracle AutoVue (Doc ID 2828263.1)

Last updated on MAY 09, 2023

Applies to:

Oracle AutoVue Office - Version 21.0.1 to 21.0.2 [Release 21.0]
Oracle Autovue for Agile Product Lifecycle Management - Version 21.0.1 to 21.0.2 [Release 21.0]
Oracle AutoVue EDA Professional - Version 21.0.1 to 21.0.2 [Release 21.0]
Oracle AutoVue Electro-Mechanical Professional - Version 21.0.1 to 21.0.2 [Release 21.0]
Oracle AutoVue 2D Professional - Version 21.0.1 to 21.0.2 [Release 21.0]
Information in this document applies to any platform.

Purpose

In response to Security Alert CVE-2021-44228, Oracle has released patches for Oracle AutoVue. This document provides you information on how to obtain and apply these security updates. Please note that these patches address both vulnerabilities CVE-2021-44228, CVE-2021-45046, CVE-2021-45105 and CVE-2021-44832.

Additionally, the Apache Software Foundation has published a number of mitigation steps in response to the Log4j vulnerabilities CVE-2021-44228, CVE-2021-45046, CVE-2021-45105 and CVE-2021-44832. These mitigations are published here. This document provides information to assist you in implementing the recommended Apache Mitigations in Oracle AutoVue. However, Oracle recommends that you apply the necessary patches as soon as possible to permanently address these vulnerabilities.

Scope

This document applies to all versions of Oracle AutoVue 21.0.2, and Oracle AutoVue 21.0.1.4 to AutoVue 21.0.1.6.

The list of AutoVue versions affected are:

AutoVue 21.0.2.6
AutoVue 21.0.2.5
AutoVue 21.0.2.4
AutoVue 21.0.2.3
AutoVue 21.0.2.2
AutoVue 21.0.2.1
AutoVue 21.0.2
AutoVue 21.0.1.6
AutoVue 21.0.1.5
AutoVue 21.0.1.4

Log4J 2 is used for logging within the AutoVue server, so one of the following mitigations should be used to remove the vulnerability.

Details

To view full details, sign in with your My Oracle Support account.

Don't have a My Oracle Support account? Click to get started!


In this Document
Purpose
Scope
Details
 Mitigations Options
 Update log4j jar files with patch
References

My Oracle Support provides customers with access to over a million knowledge articles and a vibrant support community of peers and Oracle experts.