Log4j Zero-Day Vulnerabilities (CVE-2021-44228, CVE-2021-45046, CVE-2021-45105)

In December 2021, several vulnerabilities were disclosed in Apache Log4j, a widely used Java logging library.

Notice Regarding the Apache Log4j Zero-Day Vulnerability (CVE-2021-44228)

All previous Chronicall, Avaya Call Reporting, and Xima CCaaS releases used Log4j 1 series versions without the JMS Appender class and were therefore not susceptible to this specific attack.

  • Regardless, Xima Software has updated to the latest Log4j patched version.
    • Version 4.4(0ah) and beyond now use Log4j version 2.17.1.

About the Vulnerabilities

For reference, the three CVEs associated with this disclosure are described below.

CVECommon NameDescription
CVE-2021-44228Log4ShellA remote code execution vulnerability affecting Log4j 2.x versions that improperly handle JNDI lookups embedded in log messages, allowing an attacker to execute arbitrary code on an affected server.
CVE-2021-45046An issue in certain non-default configurations where the original fix for CVE-2021-44228 was incomplete, which could allow a denial-of-service condition or, in some configurations, remote code execution.
CVE-2021-45105An uncontrolled recursion vulnerability in Log4j's handling of the Thread Context Map, which could allow an attacker to trigger a denial-of-service condition through crafted input data.

Affected Products

  • Chronicall
  • Avaya Call Reporting (ACR)
  • Xima CCaaS

Impact Summary

Because all previous releases of these products relied on the Log4j 1 series, and that series does not include the JMS Appender class exploited by CVE-2021-44228, these products were not susceptible to the specific attack vector described in that CVE. As a precautionary measure and to ensure ongoing protection, Xima Software has since updated its products to Log4j version 2.17.1, which addresses CVE-2021-44228, CVE-2021-45046, and CVE-2021-45105.

Recommended Action

Customers are encouraged to confirm they are running Version 4.4(0ah) or later to ensure their installation includes the patched Log4j version.