/
ABBYY - Log4J Vulnerability

ABBYY - Log4J Vulnerability

 

On December 10, 2021, a zero-day vulnerability was identified in the Apache Log4j logging software (CVE-2021-44228). The identified vulnerability allows remote code execution by unauthenticated threat actors. The severity of the vulnerability has been deemed critical.

ABBYY is aware of this vulnerability. In response, we immediately mobilized our Information Security and Product Engineering teams to investigate the issue and to determine any impact to ABBYY products.

Actions taken by ABBYY regarding CVE-2021-44228

ABBYY has performed a full review – including source code and production environments – and has determined that its Cloud and on-premise products are NOT affected by this vulnerability with the exception of two db connectors:


Affected components

− DBMS Connector for ABBYY Timeline. While the overall ABBYY Timeline core product is not affected by the log4j vulnerability, an auxiliary component, the db connector uses log4j. To avoid the CVE-2021-44228  vulnerability you should run the command line parameters with java -Dlog4j2.formatMsgNoLookups=true. Please refer to this article for more details.

− ABBYY FlexiCapture connector for Pega. While the overall ABBYY FlexiCapture core product is not affected, the FlexiCapture connector for Pega is affected by the vulnerability. ABBYY is actively developing a patch to address this vulnerability as quickly as possible, and is reaching out to affected customers.

 

Related content

Output Transformation Server - Log4J Vulnerability
Output Transformation Server - Log4J Vulnerability
More like this
PaperFlow - Log4J Vulnerability
PaperFlow - Log4J Vulnerability
More like this
ImageSilo - Log4J Vulnerability
ImageSilo - Log4J Vulnerability
More like this
PaperVision Enterprise - Log4J Vulnerability
PaperVision Enterprise - Log4J Vulnerability
More like this
Kofax Front Office - Log4J Security Exploit CVE-2021-44228 Does Not Affect Kofax Front Office Server
Kofax Front Office - Log4J Security Exploit CVE-2021-44228 Does Not Affect Kofax Front Office Server
More like this
PaperVision Capture - Log4J Vulnerability
PaperVision Capture - Log4J Vulnerability
More like this

Copyright © CASO Document Management

All product names, logos, brands, and trademarks featured or referred to on this page are the property of their respective trademark holders. These trademark holders are not affiliated with, nor do they sponsor or endorse this website or the products/services offered unless explicitly stated otherwise.