Summary

On December 9, 2021, the following vulnerability in the Apache Log4j Java logging library affecting all Log4j2 versions prior to 2.15.0 was disclosed:

CVE-2021-44228: Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints

For a description of this vulnerability, see the Fixed in Log4j 2.15.0 section of the Apache Log4j Security Vulnerabilities page.

There is a new development (not uncommon in these situations). A newly discovered flaw in one of the updated versions of Log4j was discovered (that could cause a denial of service condition for services utilizing the library.

CVE-2021-45046: Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack

Fortunately an updated library was already available and we included that in much of our remediation work. Some additional work remains to address this new information. If any additional patches or updates are necessary, we will include that information on our status page.”

Affected Products

In response to the Log4Shell vulnerabilities announced on the Internet (with exploit code), Perforce examined the source code of all of our product lines to ensure that none of our products include the vulnerable Log4j open-source library.

We also have ensured that our infrastructure and back-end environments that support our teams and services have been patched where necessary to address the remote code execution issue introduced by the faulty library.

In a couple cases, a patch/upgrade is necessary to remediate this issue—the version numbers are included below.

Perforce is taking an aggressive approach to identify potentially affected systems and remediate them immediately. At this time, it is not anticipated that our users will experience any downtime as a result of our work.

Brand

Product

Initially Vulnerable?

Currently Vulnerable?

Version with Fix

Patch ETA

Customer Action Recommended

21 Labs

 

NO

NO

   

Akana

API Platform

NO

NO

   

Akana

SOLA Mainframe

NO

NO

   

BlazeMeter

BlazeData

NO

NO

   

BlazeMeter

Functional Testing

YES

NO - Upgrade Required for OnPrem Agent only

1.20.257

Available Now

Upgrade OnPrem Agent to the patch

BlazeMeter

Mock Services

YES

NO - Upgrade Required for OnPrem Agent only

5.0.10

Available Now

Upgrade OnPrem Agent to the patch

BlazeMeter

Performance Testing

YES

NO - Upgrade Required for OnPrem Agent only

1.20.257

Available Now

Upgrade OnPrem Agent to the patch

BlazeMeter

RunScope

NO

NO

   

Components

HostAccess

NO

NO

   

Components

HydraExpress

NO

NO

   

Components

IMSL

NO

NO

   

Components

JMSL

NO

NO

   

Components

JViews

NO

NO

   

Components

PV-WAVE

NO

NO

   

Components

SourcePro

NO

NO

   

Components

StingRay

NO

NO

   

Components

TotalView

NO

NO

   

Components

Views

NO

NO

   

Gliffy

All Products

NO

NO

   

Helix Plan

 

NO

NO

   

Helix ALM

Helix ALM

NO

NO

   

Helix ALM

Data Warehouse

NO

NO

   

Helix ALM

SurroundSCM

YES

YES - Upgrade Required if on 2021.1.0 or 2021.1.1

 

Available Now

Upgrade to new release 2021.1.2

Helix Core

Artifacts

YES

YES

2021.3

Available Now

Upgrade to new release

Helix Core

P4D

NO

NO

   

Helix Core

P4V

NO

NO

   

Helix Core

Search

YES

YES

2021.3
2021.4

Available Now

Upgrade to new release

Helix Core

Swarm

NO

NO

   

Helix Core

HTH

YES

NO - Remediated

  

On-prem installs need to update ElasticSearch

Helix Core

Sync

NO

NO

   

Helix Core

All Other Products

NO

NO

   

Helix QAC

 

NO

NO

   

Klocwork

 

NO

NO

   

Helix IPLM

IPLM

NO

NO

   

Helix IPLM

VersIC

NO

NO

   

Perfecto

 

YES

NO - Remediated

  

No Action Required

Rebel

JRebel

NO

NO

   

Rebel

XRebel

NO

NO

   

Rebel

Rebel License Server

YES

NO - Remediated

  

No Action Required

TestCraft

 

NO

NO

   

Zend

ZendPHP

NO

NO

   

Zend

Zend Server

NO

NO

   
BrandProductInitially Vulnerable?Currently Vulnerable?Version with FixPatch ETACustomer Action Recommended
21 Labs NONO   
AkanaAPI PlatformNONO   
AkanaSOLA MainframeNONO   
BlazeMeterBlazeDataNONO   
BlazeMeterFunctional TestingYESNO - Upgrade Required for OnPrem Agent1.20.257Available NowUpgrade OnPrem Agent to the patch
BlazeMeterMock ServicesYESNO - Upgrade Required for OnPrem Agent5.0.10Available NowUpgrade OnPrem Agent to the patch
BlazeMeterPerformance TestingYESNO - Upgrade Required for OnPrem Agent1.20.257Available NowUpgrade OnPrem Agent to the patch
BlazeMeterRunScopeNONO   
ComponentsHostAccessNONO   
ComponentsHydraExpressNONO   
ComponentsIMSLNONO   
ComponentsJMSLNONO   
ComponentsJViewsNONO   
ComponentsPV-WAVENONO   
ComponentsSourceProNONO   
ComponentsStingRayNONO   
ComponentsTotalViewNONO   
ComponentsViewsNONO   
GliffyAll ProductsNONO   
Hansoft NONO   
Helix ALMHelix ALMNONO   
Helix ALMData WarehouseNONO   
Helix ALMSurroundSCMYESYES - Upgrade Required if on 2021.1.0 or 2021.1.1 Available NowUpgrade to new release 2021.1.2
Helix CoreArtifactsYESYES2021.3Available NowUpgrade to new release
Helix CoreP4DNONO   
Helix CoreP4VNONO   
Helix CoreSearchYESYES2021.3
2021.4
Available NowUpgrade to new release
Helix CoreSwarmNONO   
Helix CoreHTHYESNO - Remediated  On-prem installs need to update ElasticSearch
Helix CoreSyncNONO   
Helix CoreAll Other ProductsNONO   
Helix QAC NONO   
Klocwork NONO   
MethodicsIPLMNONO   
MethodicsVersICNONO   
Perfecto YESNO - Remediated  No Action Required
RebelJRebelNONO   
RebelXRebelNONO   
RebelRebel License ServerYESNO - Remediated  No Action Required
TestCraft NONO   
ZendZendPHPNONO   
ZendZend ServerNONO   
BrandProductInitially Vulnerable?Currently Vulnerable?Version with FixPatch ETACustomer Action Recommended
21 Labs NONO   
AkanaAPI PlatformNONO   
AkanaSOLA MainframeNONO   
BlazeMeterBlazeDataNONO   
BlazeMeterFunctional TestingYESNO - Upgrade Required for OnPrem Agent1.20.261Available NowUpgrade OnPrem Agent to the patch
BlazeMeterMock ServicesYESNO - Upgrade Required for OnPrem Agent5.0.11Available NowUpgrade OnPrem Agent to the patch
BlazeMeterPerformance TestingYESNO - Upgrade Required for OnPrem Agent1.20.261Available NowUpgrade OnPrem Agent to the patch
BlazeMeterRunScopeNONO   
ComponentsHostAccessNONO   
ComponentsHydraExpressNONO   
ComponentsIMSLNONO   
ComponentsJMSLNONO   
ComponentsJViewsNONO   
ComponentsPV-WAVENONO   
ComponentsSourceProNONO   
ComponentsStingRayNONO   
ComponentsTotalViewNONO   
ComponentsViewsNONO   
GliffyAll ProductsNONO   
Hansoft NONO   
Helix ALMHelix ALMNONO   
Helix ALMData WarehouseNONO   
Helix ALMSurroundSCMYESYES - Upgrade Required if on 2021.1.0 or 2021.1.1 Available NowUpgrade to new release 2021.1.2
Helix CoreArtifactsYESYES2021.3Available NowUpgrade to new release
Helix CoreP4DNONO   
Helix CoreP4VNONO   
Helix CoreSearchYESYES2021.3
2021.4
Available NowUpgrade to new release
Helix CoreSwarmNONO   
Helix CoreHTHYESNO - Remediated  On-prem installs need to update ElasticSearch
Helix CoreSyncNONO   
Helix CoreAll Other ProductsNONO   
Helix QAC NONO   
Klocwork NONO   
MethodicsIPLMNONO   
MethodicsVersICNONO   
Perfecto YESNO - Remediated  No Action Required
RebelJRebelNONO   
RebelXRebelNONO   
RebelRebel License ServerYESNO - Remediated  No Action Required
TestCraft NONO   
ZendZendPHPNONO   
ZendZend ServerNONO