Whole Tomato Software Forums
Whole Tomato Software Forums
Main Site | Profile | Register | Active Topics | Members | Search | FAQ
User name:
Password:
Save Password
Forgot your password?

 All Forums
 Visual Assist
 Technical Support
 log4j vulnerability in VAssist license server
 New Topic  Reply to Topic
 Printer Friendly
Author Previous Topic Topic Next Topic  

TableauBen
New Member

USA
6 Posts

Posted - Feb 04 2022 :  5:33:40 PM  Show Profile  Reply with Quote
Hello all,

We use a Visual Assist license server, and our security scanning software has flagged it as being vulnerable to the recent log4j exploit:
PluginOutput:

Path : C:\Program Files\Embarcadero\ELC5.33\LicenseCenter\lib\log4j-1.2.15.jar
Installed version : 1.2.15


Path : C:\Program Files\Embarcadero\ELC5.33\ReportingEngine\lib\log4j-1.2.15.jar
Installed version : 1.2.15

Apache Log4j 1.2 JMSAppender Remote Code Execution (CVE-2021-4104)

I've emailed [email protected] for guidance, but I haven't received a response. Does anyone know if there is a more recent version of license server software with the patched version of log4j?

Thanks,
Ben

ChrisG
Whole Tomato Software

USA
299 Posts

Posted - Feb 04 2022 :  7:57:08 PM  Show Profile  Reply with Quote
Hello Ben,

I'm sorry you didn't receive a response from support. I emailed you back, but it could have gone to spam.

I checked with the licensing server team. Here is their response.

"Log4J version 1.2.15 used by license server ELC and reporting engine ERE has not been compromised and does not pose security risk. There is a specific case that is problematic if a specific Log4J functionality is used. Neither ELC nor ERE use that functionality."

If we have any further updates, I will be sure to post them here.
Go to Top of Page

TableauBen
New Member

USA
6 Posts

Posted - Feb 17 2022 :  1:08:19 PM  Show Profile  Reply with Quote
Hi Chris,

Thank you for the response. Unfortunately, even with this assurance, we cannot continue to run a server with a known vulnerability. Do you have a time frame for when you will have a patch for the issue? Alternatively, what other options do we have to administer our licenses?
Go to Top of Page

TableauBen
New Member

USA
6 Posts

Posted - Nov 29 2022 :  4:28:29 PM  Show Profile  Reply with Quote
Hi Chris, do you know if you've released an update to the server that uses a version of log4j that has addressed the security issue from last year?
Go to Top of Page

ChrisG
Whole Tomato Software

USA
299 Posts

Posted - Nov 29 2022 :  5:55:32 PM  Show Profile  Reply with Quote
We have. I should have noted that in this thread, and I apologize for not.
Go to Top of Page

TableauBen
New Member

USA
6 Posts

Posted - Nov 29 2022 :  6:25:11 PM  Show Profile  Reply with Quote
No worries! How do I go about getting the updated version?
Go to Top of Page

feline
Whole Tomato Software

United Kingdom
18750 Posts

Posted - Dec 06 2022 :  10:27:56 AM  Show Profile  Reply with Quote
You can download the latest version of the license server from here:

https://docwiki.embarcadero.com/ELC/53/en/ELC_Quick_Start

zen is the art of being at one with the two'ness
Go to Top of Page

TableauBen
New Member

USA
6 Posts

Posted - Dec 09 2022 :  2:50:07 PM  Show Profile  Reply with Quote
Thanks for the link.

I'm upgrading from v5.33 to the latest 5.36. Do I need to uninstall the prior version first? Will my existing settings (license and named users) be migrated?
Go to Top of Page

ChrisG
Whole Tomato Software

USA
299 Posts

Posted - Dec 09 2022 :  3:02:33 PM  Show Profile  Reply with Quote
As the license server is maintained by another team, it would be best to direct that question to [email protected].
Go to Top of Page

TableauBen
New Member

USA
6 Posts

Posted - Dec 09 2022 :  3:03:36 PM  Show Profile  Reply with Quote
It seemed to offer the option to migrate settings from 5.33.

Unfortunately, even the latest version continues to use log4j 1.12.15, which was end-of-lifed back in 2015 and has numerous, unpatched security vulnerabilities: https://logging.apache.org/log4j/1.2/

Is there a timeline for a license server that uses a current version of log4j?
Go to Top of Page

ChrisG
Whole Tomato Software

USA
299 Posts

Posted - Dec 09 2022 :  3:09:51 PM  Show Profile  Reply with Quote
> Is there a timeline for a license server that uses a current version of log4j?
Not that I am aware of. I have directed your concern to the team responsible for the license server.
Go to Top of Page

ChrisG
Whole Tomato Software

USA
299 Posts

Posted - Dec 12 2022 :  5:23:53 PM  Show Profile  Reply with Quote
I spoke with the ELC team, and they had some good news.

"ELC version 5.41 uses Log4J 2.17.2"

So, the issue is 5.36 wasn't the latest version. You can download the latest version here:
https://docwiki.embarcadero.com/ELC/54/en/ELC_Quick_Start
Go to Top of Page
  Previous Topic Topic Next Topic  
 New Topic  Reply to Topic
 Printer Friendly
Jump To:
© 2023 Whole Tomato Software, LLC Go To Top Of Page
Snitz Forums 2000