Log4j Zero-Day Vulnerabilities (CVE-2021-44228, CVE-2021-45046, CVE-2021-45105)
In December 2021, several vulnerabilities were disclosed in Apache Log4j, a widely used Java logging library.
Notice Regarding the Apache Log4j Zero-Day Vulnerability (CVE-2021-44228)
All previous Chronicall, Avaya Call Reporting, and Xima CCaaS releases used Log4j 1 series versions without the JMS Appender class and were therefore not susceptible to this specific attack.
- Regardless, Xima Software has updated to the latest Log4j patched version.
- Version 4.4(0ah) and beyond now use Log4j version 2.17.1.
About the Vulnerabilities
For reference, the three CVEs associated with this disclosure are described below.
| CVE | Common Name | Description |
|---|---|---|
| CVE-2021-44228 | Log4Shell | A remote code execution vulnerability affecting Log4j 2.x versions that improperly handle JNDI lookups embedded in log messages, allowing an attacker to execute arbitrary code on an affected server. |
| CVE-2021-45046 | — | An issue in certain non-default configurations where the original fix for CVE-2021-44228 was incomplete, which could allow a denial-of-service condition or, in some configurations, remote code execution. |
| CVE-2021-45105 | — | An uncontrolled recursion vulnerability in Log4j's handling of the Thread Context Map, which could allow an attacker to trigger a denial-of-service condition through crafted input data. |
Affected Products
- Chronicall
- Avaya Call Reporting (ACR)
- Xima CCaaS
Impact Summary
Because all previous releases of these products relied on the Log4j 1 series, and that series does not include the JMS Appender class exploited by CVE-2021-44228, these products were not susceptible to the specific attack vector described in that CVE. As a precautionary measure and to ensure ongoing protection, Xima Software has since updated its products to Log4j version 2.17.1, which addresses CVE-2021-44228, CVE-2021-45046, and CVE-2021-45105.
Recommended Action
Customers are encouraged to confirm they are running Version 4.4(0ah) or later to ensure their installation includes the patched Log4j version.
- To update your installation, see Updating Chronicall.
- It is recommended to perform a database backup and run updates during a scheduled maintenance window.
- Current release downloads are available from the appropriate download page for your product:
- Chronicall: Chronicall Download Page
- Avaya Call Reporting: Avaya Call Reporting Download Page
Updated about 2 hours ago