Apache Log4j Security Alert CVE-2021-44228/CVE-2021-45046/CVE-2021-45105/CVE-2021-44832 on Oracle AutoVue
(Doc ID 2828263.1)
Last updated on MAY 09, 2023
Applies to:
Oracle AutoVue Office - Version 21.0.1 to 21.0.2 [Release 21.0]Oracle Autovue for Agile Product Lifecycle Management - Version 21.0.1 to 21.0.2 [Release 21.0]
Oracle AutoVue EDA Professional - Version 21.0.1 to 21.0.2 [Release 21.0]
Oracle AutoVue Electro-Mechanical Professional - Version 21.0.1 to 21.0.2 [Release 21.0]
Oracle AutoVue 2D Professional - Version 21.0.1 to 21.0.2 [Release 21.0]
Information in this document applies to any platform.
Purpose
In response to Security Alert CVE-2021-44228, Oracle has released patches for Oracle AutoVue. This document provides you information on how to obtain and apply these security updates. Please note that these patches address both vulnerabilities CVE-2021-44228, CVE-2021-45046, CVE-2021-45105 and CVE-2021-44832.
Additionally, the Apache Software Foundation has published a number of mitigation steps in response to the Log4j vulnerabilities CVE-2021-44228, CVE-2021-45046, CVE-2021-45105 and CVE-2021-44832. These mitigations are published here. This document provides information to assist you in implementing the recommended Apache Mitigations in Oracle AutoVue. However, Oracle recommends that you apply the necessary patches as soon as possible to permanently address these vulnerabilities.
Scope
This document applies to all versions of Oracle AutoVue 21.0.2, and Oracle AutoVue 21.0.1.4 to AutoVue 21.0.1.6.
The list of AutoVue versions affected are:
AutoVue 21.0.2.6
AutoVue 21.0.2.5
AutoVue 21.0.2.4
AutoVue 21.0.2.3
AutoVue 21.0.2.2
AutoVue 21.0.2.1
AutoVue 21.0.2
AutoVue 21.0.1.6
AutoVue 21.0.1.5
AutoVue 21.0.1.4
Log4J 2 is used for logging within the AutoVue server, so one of the following mitigations should be used to remove the vulnerability.
Details
To view full details, sign in with your My Oracle Support account. |
|
Don't have a My Oracle Support account? Click to get started! |
In this Document
Purpose |
Scope |
Details |
Mitigations Options |
Update log4j jar files with patch |
References |