Summary
On December 9, 2021, the following vulnerability in the Apache Log4j Java logging library affecting all Log4j2 versions prior to 2.15.0 was disclosed:
CVE-2021-44228: Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
For a description of this vulnerability, see the Fixed in Log4j 2.15.0 section of the Apache Log4j Security Vulnerabilities page.
There is a new development (not uncommon in these situations). A newly discovered flaw in one of the updated versions of Log4j was discovered (that could cause a denial of service condition for services utilizing the library.
CVE-2021-45046: Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
Fortunately an updated library was already available and we included that in much of our remediation work. Some additional work remains to address this new information. If any additional patches or updates are necessary, we will include that information on our status page.”
Affected Products
In response to the Log4Shell vulnerabilities announced on the Internet (with exploit code), Perforce examined the source code of all of our product lines to ensure that none of our products include the vulnerable Log4j open-source library.
We also have ensured that our infrastructure and back-end environments that support our teams and services have been patched where necessary to address the remote code execution issue introduced by the faulty library.
In a couple cases, a patch/upgrade is necessary to remediate this issue—the version numbers are included below.
Perforce is taking an aggressive approach to identify potentially affected systems and remediate them immediately. At this time, it is not anticipated that our users will experience any downtime as a result of our work.
Brand | Product | Initially Vulnerable? | Currently Vulnerable? | Version with Fix | Patch ETA | Customer Action Recommended |
21 Labs | NO | NO | ||||
Akana | API Platform | NO | NO | |||
Akana | SOLA Mainframe | NO | NO | |||
BlazeMeter | BlazeData | NO | NO | |||
BlazeMeter | Functional Testing | YES | NO - Upgrade Required for OnPrem Agent only | 1.20.257 | Available Now | Upgrade OnPrem Agent to the patch |
BlazeMeter | Mock Services | YES | NO - Upgrade Required for OnPrem Agent only | 5.0.10 | Available Now | Upgrade OnPrem Agent to the patch |
BlazeMeter | Performance Testing | YES | NO - Upgrade Required for OnPrem Agent only | 1.20.257 | Available Now | Upgrade OnPrem Agent to the patch |
BlazeMeter | RunScope | NO | NO | |||
Components | HostAccess | NO | NO | |||
Components | HydraExpress | NO | NO | |||
Components | IMSL | NO | NO | |||
Components | JMSL | NO | NO | |||
Components | JViews | NO | NO | |||
Components | PV-WAVE | NO | NO | |||
Components | SourcePro | NO | NO | |||
Components | StingRay | NO | NO | |||
Components | TotalView | NO | NO | |||
Components | Views | NO | NO | |||
Gliffy | All Products | NO | NO | |||
Helix Plan | NO | NO | ||||
Helix ALM | Helix ALM | NO | NO | |||
Helix ALM | Data Warehouse | NO | NO | |||
Helix ALM | SurroundSCM | YES | YES - Upgrade Required if on 2021.1.0 or 2021.1.1 | Available Now | Upgrade to new release 2021.1.2 | |
Helix Core | Artifacts | YES | YES | 2021.3 | Available Now | Upgrade to new release |
Helix Core | P4D | NO | NO | |||
Helix Core | P4V | NO | NO | |||
Helix Core | Search | YES | YES | 2021.3 | Available Now | Upgrade to new release |
Helix Core | Swarm | NO | NO | |||
Helix Core | HTH | YES | NO - Remediated | On-prem installs need to update ElasticSearch | ||
Helix Core | Sync | NO | NO | |||
Helix Core | All Other Products | NO | NO | |||
Helix QAC | NO | NO | ||||
Klocwork | NO | NO | ||||
Helix IPLM | IPLM | NO | NO | |||
Helix IPLM | VersIC | NO | NO | |||
Perfecto | YES | NO - Remediated | No Action Required | |||
Rebel | JRebel | NO | NO | |||
Rebel | XRebel | NO | NO | |||
Rebel | Rebel License Server | YES | NO - Remediated | No Action Required | ||
TestCraft | NO | NO | ||||
Zend | ZendPHP | NO | NO | |||
Zend | Zend Server | NO | NO |
Brand | Product | Initially Vulnerable? | Currently Vulnerable? | Version with Fix | Patch ETA | Customer Action Recommended |
21 Labs | NO | NO | ||||
Akana | API Platform | NO | NO | |||
Akana | SOLA Mainframe | NO | NO | |||
BlazeMeter | BlazeData | NO | NO | |||
BlazeMeter | Functional Testing | YES | NO - Upgrade Required for OnPrem Agent | 1.20.257 | Available Now | Upgrade OnPrem Agent to the patch |
BlazeMeter | Mock Services | YES | NO - Upgrade Required for OnPrem Agent | 5.0.10 | Available Now | Upgrade OnPrem Agent to the patch |
BlazeMeter | Performance Testing | YES | NO - Upgrade Required for OnPrem Agent | 1.20.257 | Available Now | Upgrade OnPrem Agent to the patch |
BlazeMeter | RunScope | NO | NO | |||
Components | HostAccess | NO | NO | |||
Components | HydraExpress | NO | NO | |||
Components | IMSL | NO | NO | |||
Components | JMSL | NO | NO | |||
Components | JViews | NO | NO | |||
Components | PV-WAVE | NO | NO | |||
Components | SourcePro | NO | NO | |||
Components | StingRay | NO | NO | |||
Components | TotalView | NO | NO | |||
Components | Views | NO | NO | |||
Gliffy | All Products | NO | NO | |||
Hansoft | NO | NO | ||||
Helix ALM | Helix ALM | NO | NO | |||
Helix ALM | Data Warehouse | NO | NO | |||
Helix ALM | SurroundSCM | YES | YES - Upgrade Required if on 2021.1.0 or 2021.1.1 | Available Now | Upgrade to new release 2021.1.2 | |
Helix Core | Artifacts | YES | YES | 2021.3 | Available Now | Upgrade to new release |
Helix Core | P4D | NO | NO | |||
Helix Core | P4V | NO | NO | |||
Helix Core | Search | YES | YES | 2021.3 2021.4 | Available Now | Upgrade to new release |
Helix Core | Swarm | NO | NO | |||
Helix Core | HTH | YES | NO - Remediated | On-prem installs need to update ElasticSearch | ||
Helix Core | Sync | NO | NO | |||
Helix Core | All Other Products | NO | NO | |||
Helix QAC | NO | NO | ||||
Klocwork | NO | NO | ||||
Methodics | IPLM | NO | NO | |||
Methodics | VersIC | NO | NO | |||
Perfecto | YES | NO - Remediated | No Action Required | |||
Rebel | JRebel | NO | NO | |||
Rebel | XRebel | NO | NO | |||
Rebel | Rebel License Server | YES | NO - Remediated | No Action Required | ||
TestCraft | NO | NO | ||||
Zend | ZendPHP | NO | NO | |||
Zend | Zend Server | NO | NO |
Brand | Product | Initially Vulnerable? | Currently Vulnerable? | Version with Fix | Patch ETA | Customer Action Recommended |
21 Labs | NO | NO | ||||
Akana | API Platform | NO | NO | |||
Akana | SOLA Mainframe | NO | NO | |||
BlazeMeter | BlazeData | NO | NO | |||
BlazeMeter | Functional Testing | YES | NO - Upgrade Required for OnPrem Agent | 1.20.261 | Available Now | Upgrade OnPrem Agent to the patch |
BlazeMeter | Mock Services | YES | NO - Upgrade Required for OnPrem Agent | 5.0.11 | Available Now | Upgrade OnPrem Agent to the patch |
BlazeMeter | Performance Testing | YES | NO - Upgrade Required for OnPrem Agent | 1.20.261 | Available Now | Upgrade OnPrem Agent to the patch |
BlazeMeter | RunScope | NO | NO | |||
Components | HostAccess | NO | NO | |||
Components | HydraExpress | NO | NO | |||
Components | IMSL | NO | NO | |||
Components | JMSL | NO | NO | |||
Components | JViews | NO | NO | |||
Components | PV-WAVE | NO | NO | |||
Components | SourcePro | NO | NO | |||
Components | StingRay | NO | NO | |||
Components | TotalView | NO | NO | |||
Components | Views | NO | NO | |||
Gliffy | All Products | NO | NO | |||
Hansoft | NO | NO | ||||
Helix ALM | Helix ALM | NO | NO | |||
Helix ALM | Data Warehouse | NO | NO | |||
Helix ALM | SurroundSCM | YES | YES - Upgrade Required if on 2021.1.0 or 2021.1.1 | Available Now | Upgrade to new release 2021.1.2 | |
Helix Core | Artifacts | YES | YES | 2021.3 | Available Now | Upgrade to new release |
Helix Core | P4D | NO | NO | |||
Helix Core | P4V | NO | NO | |||
Helix Core | Search | YES | YES | 2021.3 2021.4 | Available Now | Upgrade to new release |
Helix Core | Swarm | NO | NO | |||
Helix Core | HTH | YES | NO - Remediated | On-prem installs need to update ElasticSearch | ||
Helix Core | Sync | NO | NO | |||
Helix Core | All Other Products | NO | NO | |||
Helix QAC | NO | NO | ||||
Klocwork | NO | NO | ||||
Methodics | IPLM | NO | NO | |||
Methodics | VersIC | NO | NO | |||
Perfecto | YES | NO - Remediated | No Action Required | |||
Rebel | JRebel | NO | NO | |||
Rebel | XRebel | NO | NO | |||
Rebel | Rebel License Server | YES | NO - Remediated | No Action Required | ||
TestCraft | NO | NO | ||||
Zend | ZendPHP | NO | NO | |||
Zend | Zend Server | NO | NO |