Broadcom Enterprise Software Security Advisory for Log4j 2 CVE-2021-44228 Vulnerability

19792

23 March 2022

10 December 2021

OPEN

CRITICAL

10.0

Security Advisory for Log4j 2 CVE-2021-44228 vulnerability

Issued: December 10th, 2021
Updated: March 23rd, 2022

Broadcom Software has investigated multiple Apache Log4j 2 vulnerabilities that were recently reported to Apache.  CVE identifiers CVE-2021-44228, CVE-2021-45046, CVE-2021-45105, and CVE-2021-4104 have been assigned to these vulnerabilities.  These vulnerabilities have a cumulative Critical risk rating, and exploit code is in the wild.  The Log4j team has addressed these vulnerabilities in Log4j 2.16.0.

Log4j Versions Affected: All versions from 2.0-beta9 to 2.16.0

Note that CVE-2021-4104 affects only Log4j 1.2, and does not impact the Log4j 2.x branch.

CVE-2021-44228 Description: Apache Log4j2 2.0-beta9 through 2.12.1 and 2.13.0 through 2.15.0 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0, this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.

CVE-2021-45046 Description: It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allow attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup or a Thread Context Map pattern to craft malicious input data using a JNDI Lookup pattern resulting in an information leak and remote code execution in some environments and local code execution in all environments. Log4j 2.16.0 (Java 8) and 2.12.2 (Java 7) fix this issue by removing support for message lookup patterns and disabling JNDI functionality by default.

CVE-2021-45105 Description: Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0 and 2.12.3.

CVE-2021-4104 Description: JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-44228. Note this issue only affects Log4j 1.2 when specifically configured to use JMSAppender, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.

We have investigated the impact to each product and published fixes for all affected products as of 2021-12-30.  In addition to checking this advisory for updates, customers can check individual product support pages for updates, or open a support case.

Risk Rating

CVE-2021-44228 - Critical
Base CVSS Score: 10.0
Vector String - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CVE-2021-45046 - Critical
Base CVSS Score: 9.0
Vector String - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

CVE-2021-45105 - High
Base CVSS Score: 7.5
Vector String - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVE-2021-4104 - High
Base CVSS Score: 8.1
Vector String - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products and Components

App Synthetic Monitor (ASM)
Application Delivery Analysis
Application Test
Automation Intelligence
Automic Applications Manager
Automic Continuous Delivery Automation
Automic One Automation
Automic Workload Automation
CA Productivity Accelerator
Clarity
Client Automation
dSeries
DX App Experience Analytics (AxA)
DX NetOps
DX NetOps Performance Management (DA/DC/DR/OI Connector)
DX NetOps Spectrum
DX Operational Intelligence
IT Asset Manager
IT Asset Manager Asset Portfolio Management
NIM (Normalized Integration Management)
Rally Adapter for Jira
Service Catalog
Service Desk Manager
Service Management
Service Management - Asset Portfolio Management
Service Operations Insight (SOI)
Service Virtualization
Unified Infrastructure Management (UIM)

Non-Affected Products and Components

2E
Agile Central (Rally) SaaS and OnPrem
Agile Requirements Designer (ARD)
Application Performance Management (APM), APM SaaS
Business Service Insight
Dollar Universe
CABI
Capacity Manager
CAPKI
Common Agents
Configuration Automation
Continuous Delivery Director
Continuous Delivery Director SAAS
DX NetOps Mediation Manager
DX NetOps Network Flow Analysis
DX NetOps Performance Management Portal, DA Proxy
DX NetOps Virtual Network Assurance
EEM
IT Process Automation
Mobile Device Manager
Nolio Release Automation
Plex
Software Change Manager (Harvest SCM)
Sysload
Systems Performance for Infrastructure Managers (SPIM)
Test Data Manager
Unified Communications Monitor
Unified Self Service (USS)
Virtual Assurance for Infrastructure Managers (VAIM)
Workload Automation AE - Business Agents (AutoSys)
Workload Automation AE - Scheduler (AutoSys)
Workload Automation AE - System Agent (AutoSys)
Workload Automation Agents
Workload Automation IXP

Solutions, Workarounds, KB Articles
(for both affected and non-affected products)

Note that solutions, workarounds, and KB articles for affected products will be provided as they are approved by each product team.

2E: https://knowledge.broadcom.com/external/article?articleId=230307

Agile Central (Rally) SaaS and OnPrem: https://knowledge.broadcom.com/external/article?articleId=230390

Agile Requirements Designer (ARD): https://knowledge.broadcom.com/external/article?articleId=230300

App Synthetic Monitor (ASM):
https://knowledge.broadcom.com/external/article?articleId=230401
Security Advisory: CVE-2021-44228 - Log4j Vulnerability and Broadcom CA App Synthetic Monitor (ASM)

Application Delivery Analysis: https://knowledge.broadcom.com/external/article?articleId=230341 

Application Performance Management (APM), APM SaaS:
https://knowledge.broadcom.com/external/article?articleId=230324
Security Advisory: CVE-2021-44228 - log4j vulnerability and Broadcom CA APM
Security Advisory: CVE-2019-17571 and CVE-2021-4104 log4j 1.2 vulnerability and Broadcom CA APM

Application Test: https://knowledge.broadcom.com/external/article?articleId=230299

Automation Intelligence: https://knowledge.broadcom.com/external/article?articleId=230310

Automic Applications Manager: https://knowledge.broadcom.com/external/article?articleId=230316

Automic Continuous Delivery Automation: https://knowledge.broadcom.com/external/article?articleId=230308

Automic One Automation:
https://knowledge.broadcom.com/external/article?articleId=230308
https://knowledge.broadcom.com/external/article?articleId=230967

Automic Workload Automation: https://knowledge.broadcom.com/external/article?articleId=230308

Business Service Insight: https://knowledge.broadcom.com/external/article?articleId=230317

CABI: https://knowledge.broadcom.com/external/article?articleId=230258

Capacity Manager: https://knowledge.broadcom.com/external/article?articleId=230312

CAPKI: https://knowledge.broadcom.com/external/article?articleId=230417

CA Productivity Accelerator: https://knowledge.broadcom.com/external/article?articleId=237615

Clarity SaaS and Clarity On Premise: https://knowledge.broadcom.com/external/article?articleId=230248

Client Automation:
https://knowledge.broadcom.com/external/article?articleId=230320
https://knowledge.broadcom.com/external/article?articleId=230417

Common Agents: https://knowledge.broadcom.com/external/article?articleId=230309

Configuration Automation:
https://knowledge.broadcom.com/external/article?articleId=230298
https://knowledge.broadcom.com/external/article?articleId=230321

Continuous Delivery Director
Continuous Delivery Director SAAS
https://knowledge.broadcom.com/external/article?articleId=230303

dSeries: https://knowledge.broadcom.com/external/article?articleId=230329

Dollar Universe: https://knowledge.broadcom.com/external/article?articleId=230304

DX App Experience Analytics (AXA): 
https://knowledge.broadcom.com/external/article?articleId=230678
CVE-2021-44228 & CVE-2021-45046: DX App Experience Analytics - Log4j vulnerability

DX NetOps (Spectrum, Performance Management (CAPM), Virtual Network Assurance (VNA), Mediation Manager (MM) and Network Flow Analysis (NFA)):
https://knowledge.broadcom.com/external/article?articleId=230391

DX Operational Intelligence: https://knowledge.broadcom.com/external/article/230524

EEM: https://knowledge.broadcom.com/external/article?articleId=230311

IT Asset Manager
IT Asset Manager Asset Portfolio Management
Service Management - Asset Portfolio Management
https://knowledge.broadcom.com/external/article?articleId=230318

IT Process Automation: https://knowledge.broadcom.com/external/article?articleId=230306

NIM (Normalized Integration Management): https://knowledge.broadcom.com/external/article?articleId=230345

Nolio Release Automation: https://knowledge.broadcom.com/external/article?articleId=230302

Plex: https://knowledge.broadcom.com/external/article?articleId=230307

Rally Adapter for Jira: https://knowledge.broadcom.com/external/article?articleId=230390

Service Catalog:
https://knowledge.broadcom.com/external/article?articleId=230314
https://knowledge.broadcom.com/external/article?articleId=230315

Service Desk Manager
Service Management - xFlow
Service Management - Jasper
https://knowledge.broadcom.com/external/article?articleId=230322
https://knowledge.broadcom.com/external/article?articleId=230323
https://knowledge.broadcom.com/external/article?articleId=230331
https://knowledge.broadcom.com/external/article?articleId=230332
https://knowledge.broadcom.com/external/article?articleId=230417
https://knowledge.broadcom.com/external/article?articleId=230311

Service Operations Insight (SOI):
https://knowledge.broadcom.com/external/article?articleId=230292
https://knowledge.broadcom.com/external/article?articleId=230345

Service Virtualization:
https://knowledge.broadcom.com/external/article?articleId=230299
https://knowledge.broadcom.com/external/article?articleId=231043

Software Change Manager (Harvest SCM): https://knowledge.broadcom.com/external/article?articleId=230313

Systems Performance for Infrastructure Managers (SPIM): https://knowledge.broadcom.com/external/article?articleId=230373

Test Data Manager: https://knowledge.broadcom.com/external/article?articleId=230297

Unified Communications Monitor: https://knowledge.broadcom.com/external/article?articleId=230328

Unified Infrastructure Management (UIM):
https://knowledge.broadcom.com/external/article?articleId=230333
https://knowledge.broadcom.com/external/article?articleId=230345
https://knowledge.broadcom.com/external/article?articleId=230417

Unified Self Service (USS): https://knowledge.broadcom.com/external/article?articleId=230375

Virtual Assurance for Infrastructure Managers (VAIM): https://knowledge.broadcom.com/external/article?articleId=230373

Workload Automation AE - Business Agents (AutoSys)
Workload Automation AE - Scheduler (AutoSys)
Workload Automation AE - System Agent (AutoSys)
Workload Automation Agents
Workload Automation IXP
https://knowledge.broadcom.com/external/article?articleId=230309
https://knowledge.broadcom.com/external/article?articleId=230417
https://knowledge.broadcom.com/external/article?articleId=230680
https://knowledge.broadcom.com/external/article?articleId=230677

References

CVE:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44228
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-45046
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-45105
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4104
NVD:
https://nvd.nist.gov/vuln/detail/CVE-2021-44228
https://nvd.nist.gov/vuln/detail/CVE-2021-45046
https://nvd.nist.gov/vuln/detail/CVE-2021-45105
https://nvd.nist.gov/vuln/detail/CVE-2021-4104
Apache Log4j 2:  https://logging.apache.org/log4j/2.x/
Apache Log4j Security Vulnerabilities:  https://logging.apache.org/log4j/2.x/security.html
CISA Apache Log4j Vulnerability Guidance: https://www.cisa.gov/uscert/apache-log4j-vulnerability-guidance

Change History

Version 1.0: 2021-12-10 - Initial Release
Version 1.1: 2021-12-11 0200 CT - Products, Solutions, Workarounds, KBs added
Version 1.2: 2021-12-11 0900 CT - More Products, Solutions, Workarounds, KBs added
Version 1.3: 2021-12-11 1000 CT - More updates
Version 1.4: 2021-12-11 1315 CT - More updates
Version 1.5: 2021-12-11 1330 CT - SDM and APM updates
Version 1.6: 2021-12-11 1600 CT - APM KB link, formatting
Version 1.7: 2021-12-11 1830 CT - dSeries
Version 2.0: 2021-12-11 2030 CT - Added SM – Japser; changed formatting
Version 2.1: 2021-12-12 1015 CT - Added UCM KB, UIM KB, SDM xFlow KB
Version 2.2: 2021-12-12 2230 CT - Added ADA KB
Version 2.3: 2021-12-13 0100 CT - Added USS
Version 2.4: 2021-12-13 0900 CT - Added USS KB, Sysload, Clarity update
Version 2.5: 2021-12-13 0945 CT - Added AXA update
Version 2.6: 2021-12-13 1115 CT - Added CAPKI KB
Version 2.7: 2021-12-13 1115 CT - Added NIM KB
Version 2.8: 2021-12-13 1245 CT - Added Rally SaaS and OnPrem
Version 2.9: 2021-12-13 1615 CT - DX NetOps updates and consolidations; multiple dependency KBs added
Version 3.0: 2021-12-14 0900 CT - Added VAIM, SPIM
Version 3.1: 2021-12-14 1030 CT - Added DX NetOps updates
Version 3.2: 2021-12-14 1100 CT - Added DX OI update
Version 3.3: 2021-12-14 1250 CT - Added Agile Central (Rally) KB; CISA reference
Version 3.4: 2021-12-14 1615 CT - Added ASM
Version 4.0: 2021-12-15 1015 CT - Added CVE-2021-45046 and CVE-2021-4104
Version 4.1: 2021-12-15 1815 CT - Added DX AxA, ASM advisory, APM advisory, AxA advisory, Workload Automation KBs
Version 4.2: 2021-12-16 0930 CT - Updated CVE descriptions, Service Virtualization KB is updated with patch, Clarity KB updated
Version 4.3: 2021-12-17 1050 CT - Updated CVSS for 4104 and 45046, updated affected log4j versions, added Rally Adapter for Jira
Version 4.4: 2021-12-18 0620 CT - Added CVE-2021-45105
Version 4.5: 2021-12-23 1045 CT - Updated APM, Service Virtualization, Automic One Automation, CVE-2021-45046 description, CVE-2021-45105 description
Version 5.0: 2022-01-09 2100 CT - Updated to note that fixes for all affected products were published by 2021-12-30.
Version 5.1: 2022-03-23 1200 CT - Added CA Productivity Accelerator

Broadcom Software customers may receive product alerts and advisories by subscribing to Proactive Notifications.

Customers who require additional information about this notice may contact Broadcom Software Support at https://support.broadcom.com/.

To report a suspected vulnerability in a CA Technologies product, please send a summary to the CA Technologies Product Vulnerability Response Team.

Copyright © 2022 Broadcom. All Rights Reserved. The term “Broadcom” refers to Broadcom Inc. and/or its subsidiaries. Broadcom, the pulse logo, Connecting everything, CA Technologies and the CA technologies logo are among the trademarks of Broadcom. All trademarks, trade names, service marks and logos referenced herein belong to their respective companies.