Dutch

English

Information about the vulnerability in Apache Log4j 2

This FAQ lists the vulnerabilities in Apache Log4J 2 across various software packages. 

News reports are warning about the vulnerability in Apache Log4j 2.

Many customers ask us whether this affects their organization. In this post, we’ll briefly explain what we know so far. 

The problem lies with the so-called Apache Log4j tool. This is software used to keep application logs. Companies do this, for example, to see what’s going wrong when a computer program returns an error.

The vulnerability, which has been named Log4Shell, allows hackers to gain access to computer servers and execute malicious software. The National Cyber Security Center (NCSC) expects that the vulnerability will be exploited in the near future, potentially affecting thousands of organizations.

Apache Software has since released an update to fix the vulnerability. Companies and users are urged to install this update as soon as possible to prevent hackers from taking advantage of the vulnerability.

Exact Business Software has issued a general statement: https://www.exact.com/nl/nieuws/algemeen-statement-apache-lek

What does this mean at this time [as of December 14, 2021]?

Exact Globe

Exact Globe should never be exposed to the outside world and is therefore protected against these types of attacks. Log4J is used in Exact Globe, but only in highly specialized components; however, in all cases, it requires the explicit installation of the Java runtime environment. Examples include: Facturae, MIPF, the IRmark software application, and 390_2011.

Synergy Enterprise

On Synergy Enterprise, Windows authentication is used in (virtually) all cases; this means that users log in with their Windows (AD) username and password. In that case, it is impossible for Synergy Enterprise to be susceptible to this vulnerability; IIS only grants access to the application folder after a user has been successfully authenticated.

In (highly) unusual scenarios, where Synergy Enterprise environments are open to users who do not need to log in (with Windows credentials) (or, Anonymous or Forms authentication), you must verify whether ElasticSearch has been installed for Synergy Enterprise. ElasticSearch is a component that can be installed optionally (in most Synergy Enterprise environments, it is not installed). In this highly specific scenario, we ask that you contact our service desk to rule out any potential vulnerabilities.

Alistar and Custom Solutions

Log4j has been ported to other platforms, including .NET. This technology has been used in Nlog and Log4Net, among others. We use these components in various Custom and Alistar Solutions. Based on reports in forums, it appears that this vulnerability does not affect .NET. Based on our own analysis as well, we have no reason to doubt those reports. Ports of log4j to other non-Java languages (log4perl, log4php, log4net, and log4r, etc.) – likely unaffected because this vulnerability is specific to Java

Exact Financials Enterprise

Based on Progress's statement, Exact Financials is not affected by this vulnerability: https://www.progress.com/security The only potential issue might arise if Apache Tomcat is installed for SOAP web services or AIA and Tomcat is configured differently to use Log4j instead of the default Tomcat logging. We are not aware of any environments where this is the case.

Scan Sys

Response from Scan Sys: “The following concerns a vulnerability in a component that can be used in Java applications. That is, applications that use the JRE—which our application does not.”

Elvy

Response from Elvy: “We do not use Apache log4j in our software. No action is required on our part—and therefore on the part of our customers.”

Sumatra

Response from Sumatra: “Sumatra doesn’t use this; our development department has confirmed this. So it has no effect on Sumatra.”

All announcements are based on the information currently available. Alistar has taken great care in compiling the above announcement; however, we are still awaiting official statements from several of our suppliers.

Questions?

Do you have questions about an FAQ article, or do you need further assistance? Please contact Support.