<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article FAQ for Log4J Vulnerabilities in Get Started</title>
    <link>https://community.qlik.com/t5/Get-Started/FAQ-for-Log4J-Vulnerabilities/ta-p/1893106</link>
    <description>&lt;P&gt;Please visit our &lt;A href="https://community.qlik.com/t5/Support-Updates-Blog/Vulnerability-Testing-Apache-Log4j-reference-CVE-2021-44228-also/ba-p/1869368" target="_blank" rel="noopener"&gt;Support Updates Blog&lt;/A&gt; detailing Affected Product Chart and Release Solutions.&lt;/P&gt;
&lt;P&gt;&lt;LI-TOC indent="15" liststyle="disc" maxheadinglevel="2"&gt;&lt;/LI-TOC&gt;&lt;/P&gt;
&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;H2&gt;Where can I find more information on the log4j vulnerabilities and what they mean?&lt;/H2&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;A:&amp;nbsp;&lt;A href="https://logging.apache.org/log4j/2.x/security.html" target="_blank" rel="noopener"&gt;https://logging.apache.org/log4j/2.x/security.html&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;During December 2021, the Apache Log4j 2.x vulnerabilities (&lt;A href="https://logging.apache.org/log4j/2.x/security.html" target="_blank" rel="noopener"&gt;https://logging.apache.org/log4j/2.x/security.html&lt;/A&gt;) were found:&lt;BR /&gt;&lt;BR /&gt;(1). CVE-2021-44228 (&lt;A href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2021-44228):" target="_blank" rel="noopener"&gt;https://cve.mitre.org/cgi-bin/cvename.cgi?name=2021-44228):&lt;/A&gt;&amp;nbsp;A remote code execution (RCE) vulnerability in Apache Log4j 2.x referred to as "Log4Shell". Log4j fix: 2.15.0&lt;BR /&gt;&lt;BR /&gt;(2). CVE-2021-45046 (&lt;A href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-45046):" target="_blank" rel="noopener"&gt;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-45046):&lt;/A&gt;&amp;nbsp;Under certain conditions, the library is open to DDoS attacks. Log4j fix: 2.16.0.&lt;BR /&gt;&lt;BR /&gt;(3). CVE-2021-45105 (&lt;A href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-45105):" target="_blank" rel="noopener"&gt;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-45105):&lt;/A&gt;&amp;nbsp;A&lt;BR /&gt;second way that allows the remote connection. Log4j fix: 2.17.0.&lt;BR /&gt;&lt;BR /&gt;(4). CVE-2021-44832 (&lt;A href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44832):" target="_blank" rel="noopener"&gt;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44832):&lt;/A&gt;&amp;nbsp;An Arbitrary Code Execution exploit. It is also an RCE vulnerability. Log4j fix: 2.17.1.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;H2&gt;When will patches be released?&lt;/H2&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;The immediate risks to the current vulnerabilities have been addressed, and further releases will become available with their regular release schedule.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;H2&gt;We are running Qlik Replicate (2021.5.0.1133) and Enterprise Manager (2021.5.0.465). If we upgrade to Qlik Replicate (2021.5.0.1272) and Enterprise Manager (2021.5.0.543) would address log4j vulnerability CVE-2021-44228?&lt;/H2&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;Yes. (00020378) CVE-2021-44228, CVE-2021-45046 - is fixed by 2.16.0&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;The above latest build of Replicate and Enterprise Manager contains log4j 2.16.0.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;If necessary, users may manually upgrade to log4j 2.17.1, the detailed steps are in article:&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;&lt;A href="https://community.qlik.com/t5/Knowledge/CVE-2021-45105-CVE-2021-44832-Update-to-log4j-2-17-1-for-Qlik/ta-p/1876190" target="_blank" rel="noopener"&gt;https://community.qlik.com/t5/Knowledge/CVE-2021-45105-CVE-2021-44832-Update-to-log4j-2-17-1-for-Qlik/ta-p/1876190&lt;/A&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;H2&gt;Are there any patches for Qlik Replicate and Enterprise Manager 2021.11?&lt;/H2&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;Yes. Please download Replicate 2021.11 SR1 (2021.11.0.165), QEM 2021.11 SP02 (2021.11.0.198)&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;- or -&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;&lt;A href="https://files.qlik.com/url/qr2021110165sp02" target="_blank" rel="noopener"&gt;https://files.qlik.com/url/qr2021110165sp02&lt;/A&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;(expires 3/31/2022)&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;&lt;A href="https://files.qlik.com/url/qem2021110198sp02" target="_blank" rel="noopener"&gt;https://files.qlik.com/url/qem2021110198sp02&lt;/A&gt; (expires 3/31/2022)&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;H2&gt;Are there any patches for Qlik Replicate and Enterprise Manager 2021.5?&lt;/H2&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;Yes. Please download Replicate 2021.5 SR5 (2021.5.0.1272), QEM 2021.5 SP09 (2021.5.0.543)&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;- or -&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;&lt;A href="https://files.qlik.com/url/qr2021501272sp09" target="_blank" rel="noopener"&gt;https://files.qlik.com/url/qr2021501272sp09&lt;/A&gt; &amp;nbsp;&amp;nbsp;(expires 3/31/2022)&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;&lt;A href="https://files.qlik.com/url/qem202150543sp09" target="_blank" rel="noopener"&gt;https://files.qlik.com/url/qem202150543sp09&lt;/A&gt; (expires 3/31/2022)&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;H2&gt;Are there any patches for Qlik Replicate and Enterprise Manager 7.0 (Nov 2020)?&lt;/H2&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;Yes. Please download Replicate 7.0 SR5 (7.0.0.1221) and QEM SR5 (7.0.0.1607)&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;- Or -&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;&lt;A href="https://files.qlik.com/url/qr700967sp10" target="_blank" rel="noopener"&gt;https://files.qlik.com/url/qr700967sp10&lt;/A&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (expires 04/30/2022)&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;&lt;A href="https://files.qlik.com/url/qem7001602sp10" target="_blank" rel="noopener"&gt;https://files.qlik.com/url/qem7001602sp10&lt;/A&gt; (expires 04/30/2022)&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;H2&gt;Are there any patches for Qlik Replicate and Enterprise Manager 6.6 (Apr 2020)?&lt;/H2&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;Yes. Please download Replicate 6.6 SR6 (6.6.0.904) and QEM SR3 (6.6.0.790)&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;- Or -&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;&lt;A href="https://files.qlik.com/url/qr660904sp14" target="_blank" rel="noopener"&gt;https://files.qlik.com/url/qr660904sp14&lt;/A&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (expires 4/30/2022)&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;&lt;A href="https://files.qlik.com/url/qem660790sp12" target="_blank" rel="noopener"&gt;https://files.qlik.com/url/qem660790sp12&lt;/A&gt; (expires 4/30/2022)&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;H2&gt;Are there any patches for Qlik Replicate and Enterprise Manger 5.5/6.2/6.3/6.4/6.5?&lt;/H2&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;No. These versions are no longer being supported so it will not be patched for the log4j vulnerability. Please consider upgrading to supported versions.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;Take note the upgrade should be 2 steps: 6.x&amp;nbsp; &lt;STRONG&gt;&amp;gt;&amp;nbsp;&lt;/STRONG&gt; 6.6 &lt;STRONG&gt;&amp;gt;&lt;/STRONG&gt; 2021.5 or 2021.11&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;Replicate 6.2 does not have this folder because it does not support endpoint server yet.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;If you are upgrading from Replicate 5.5, please contact Qlik Support.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;For more information, see the product lifecycle:&amp;nbsp;&lt;A href="https://community.qlik.com/t5/Product-Support-Lifecycle/Qlik-Replicate-Product-Lifecycle/ta-p/1837201" target="_blank" rel="noopener"&gt;https://community.qlik.com/t5/Product-Support-Lifecycle/Qlik-Replicate-Product-Lifecycle/ta-p/1837201&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;For mitigation steps, please see:&amp;nbsp;&lt;A href="https://community.qlik.com/t5/Knowledge/CVE-2021-44228-Handling-the-log4j-lookups-critical-vulnerability/ta-p/1869996" target="_blank" rel="noopener"&gt;https://community.qlik.com/t5/Knowledge/CVE-2021-44228-Handling-the-log4j-lookups-critical-vulnerability/ta-p/1869996&lt;/A&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;H2&gt;We are running Replicate 6.3/6.4. Does Log4j vulnerabilities impact the installation?&lt;/H2&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;Replicate v6.3/6.4 does not include Endpoint Server and it is no longer supported. Please consider upgrading to supported versions.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;The product lifecycle:&amp;nbsp;&lt;A href="https://community.qlik.com/t5/Product-Support-Lifecycle/Qlik-Replicate-Product-Lifecycle/ta-p/1837201" target="_blank" rel="noopener"&gt;https://community.qlik.com/t5/Product-Support-Lifecycle/Qlik-Replicate-Product-Lifecycle/ta-p/1837201&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;or mitigation steps:&amp;nbsp;&lt;A href="https://community.qlik.com/t5/Knowledge/CVE-2021-44228-Handling-the-log4j-lookups-critical-vulnerability/ta-p/1869996" target="_blank" rel="noopener"&gt;https://community.qlik.com/t5/Knowledge/CVE-2021-44228-Handling-the-log4j-lookups-critical-vulnerability/ta-p/1869996&lt;/A&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;H2&gt;Why do customers need to manually upgrade to 2.17.1?&lt;/H2&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;We have reviewed a third Log4j vulnerability, CVE-2021-45105, and determined the relevant products (Replicate, Compose, QEM and GeoAnalytics) do not use the logging feature and context string defined in the CVE. Qlik considers the risks of Denial-Of-Service to be low and will address this in future regularly scheduled patch releases.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;For Catalog, Qlik has published service releases for May, August, and November 2021 versions with upgraded Log4j 2.17.0 to the downloads page.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;H2&gt;Do we need to manually upgrade to 2.17.1 for Replicate/Enterprise Manager?&lt;/H2&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;Yes. Customers who require 2.17.1 will need to upgrade log4j manually. You can find instructions here: &lt;A href="https://community.qlik.com/t5/Knowledge/CVE-2021-45105-CVE-2021-44832-Update-to-log4j-2-17-1-for-Qlik/ta-p/1876190" target="_blank" rel="noopener"&gt;https://community.qlik.com/t5/Knowledge/CVE-2021-45105-CVE-2021-44832-Update-to-log4j-2-17-1-for-Qlik/ta-p/1876190&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;&lt;STRONG&gt;Replicate:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;Location to replace jar files: &amp;lt;installation-root&amp;gt;\Replicate\endpoint_srv\externals\ (Default location:C:\Program Files\Attunity\Replicate\endpoint_srv\externals)&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;&lt;STRONG&gt;QEM:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;Location to replace jar files: &amp;lt;installation-root&amp;gt;\Enterprise Manager\java\external (Default location:C:\Program Files\Attunity\Enterprise Manager\java\external)&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;&lt;STRONG&gt;Qlik Compose:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;Location to replace jar files: &amp;lt;installation-root&amp;gt;\Compose\java\external (Default location: C:\Program Files\Qlik\Compose\java\external)&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;&lt;STRONG&gt;Qlik Compose for Data Lakes:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;Location to replace jar files: &amp;lt;installation-root&amp;gt;\Compose for Data Lakes\java\external (Default location: C:\Program Files\Attunity\Compose for Data Lakes\java\external)&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;&lt;STRONG&gt;Qlik Compose for Data warehouses:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;Location to replace jar files: &amp;lt;installation-root&amp;gt;\Compose for Data warehouses\java\external (Default location: C:\Program Files\Attunity\Compose for Data Warehouses\java\external)&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;H2&gt;Do we need to manually upgrade to 2.17.1 for Compose?&lt;/H2&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;Yes. Customers who require 2.17.1 will need to upgrade log4j manually. You can find instructions here: &lt;A href="https://community.qlik.com/t5/Knowledge/CVE-2021-45105-CVE-2021-44832-Update-to-log4j-2-17-1-for-Qlik/ta-p/1876190" target="_blank" rel="noopener"&gt;https://community.qlik.com/t5/Knowledge/CVE-2021-45105-CVE-2021-44832-Update-to-log4j-2-17-1-for-Qlik/ta-p/1876190&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;&lt;STRONG&gt;Replicate:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;Location to replace jar files: &amp;lt;installation-root&amp;gt;\Replicate\endpoint_srv\externals\ (Default location:C:\Program Files\Attunity\Replicate\endpoint_srv\externals)&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;&lt;STRONG&gt;QEM:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;Location to replace jar files: &amp;lt;installation-root&amp;gt;\Enterprise Manager\java\external (Default location:C:\Program Files\Attunity\Enterprise Manager\java\external)&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;&lt;STRONG&gt;Qlik Compose:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;Location to replace jar files: &amp;lt;installation-root&amp;gt;\Compose\java\external (Default location: C:\Program Files\Qlik\Compose\java\external)&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;&lt;STRONG&gt;Qlik Compose for Data Lakes:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;Location to replace jar files: &amp;lt;installation-root&amp;gt;\Compose for Data Lakes\java\external (Default location: C:\Program Files\Attunity\Compose for Data Lakes\java\external)&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;&lt;STRONG&gt;Qlik Compose for Data warehouses:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;Location to replace jar files: &amp;lt;installation-root&amp;gt;\Compose for Data warehouses\java\external (Default location: C:\Program Files\Attunity\Compose for Data Warehouses\java\external)&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;H2&gt;We followed the mitigation steps from the Qlik file and renamed the file name from "Log4j-core-2.14.1.jar" to "log4j-core-nolookup-2.14.1.jar". When upgrading to the latest build, do we need to rename the mentioned jar file name, or can we perform upgrade installation as-is?&lt;/H2&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;Yes.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;The best approach is renaming the jar files (log4j-core-nolookup-2.14.1.jar) to their original file name (log4j-core-2.14.1.jar) before upgrade or&amp;nbsp;remove the files out of Replicate installation folder.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;This is because Replicate installation program will try to remove the old jar files. If it cannot find it, a warning reported:&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;&lt;STRONG&gt;warning:&lt;/STRONG&gt; file /opt/attunity/replicate/endpoint_srv/externals/log4j-core-2.14.1.jar: remove failed: No such file or directory&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;In this case, the installation program cannot remove the useless jar file, the unnecessary jar file left in the folder, there are 2 versions log4j-core jar files after the upgrade is done. Please remove the "log4j-core-nolookup-2.14.1.jar" manually and restart the services.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;H2&gt;Which GeoAnalytics versions will be upgraded to 2.17?&lt;/H2&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;The November 2021 release can be upgraded using the patch available on the downloads site.&lt;BR /&gt;&lt;BR /&gt;Qlik recommends that customers on previous versions upgrade to the November 2021 release.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;&lt;A href="https://da3hntz84uekx.cloudfront.net/GeoAnalytics/4.32.4/31260/GeoAnalyticsServerReleaseNotes-November2021Patch2.pdf" target="_blank" rel="noopener"&gt;https://da3hntz84uekx.cloudfront.net/GeoAnalytics/4.32.4/31260/GeoAnalyticsServerReleaseNotes-November2021Patch2.pdf&lt;/A&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;H2&gt;What’s the mitigation steps for Visibility?&lt;/H2&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;Qlik is providing these mitigation steps as a temporary measure. Detailed steps see:&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;&lt;A href="https://community.qlik.com/t5/Knowledge/CVE-2021-44832-Handling-the-log4shell-vulnerability-for/ta-p/1877884" target="_blank" rel="noopener"&gt;https://community.qlik.com/t5/Knowledge/CVE-2021-44832-Handling-the-log4shell-vulnerability-for/ta-p/1877884&lt;/A&gt;&lt;/P&gt;
&lt;/DIV&gt;</description>
    <pubDate>Tue, 15 Feb 2022 20:30:41 GMT</pubDate>
    <dc:creator>Katie_Davis</dc:creator>
    <dc:date>2022-02-15T20:30:41Z</dc:date>
    <item>
      <title>FAQ for Log4J Vulnerabilities</title>
      <link>https://community.qlik.com/t5/Get-Started/FAQ-for-Log4J-Vulnerabilities/ta-p/1893106</link>
      <description>&lt;P&gt;Please visit our &lt;A href="https://community.qlik.com/t5/Support-Updates-Blog/Vulnerability-Testing-Apache-Log4j-reference-CVE-2021-44228-also/ba-p/1869368" target="_blank" rel="noopener"&gt;Support Updates Blog&lt;/A&gt; detailing Affected Product Chart and Release Solutions.&lt;/P&gt;
&lt;P&gt;&lt;LI-TOC indent="15" liststyle="disc" maxheadinglevel="2"&gt;&lt;/LI-TOC&gt;&lt;/P&gt;
&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;H2&gt;Where can I find more information on the log4j vulnerabilities and what they mean?&lt;/H2&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;A:&amp;nbsp;&lt;A href="https://logging.apache.org/log4j/2.x/security.html" target="_blank" rel="noopener"&gt;https://logging.apache.org/log4j/2.x/security.html&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;During December 2021, the Apache Log4j 2.x vulnerabilities (&lt;A href="https://logging.apache.org/log4j/2.x/security.html" target="_blank" rel="noopener"&gt;https://logging.apache.org/log4j/2.x/security.html&lt;/A&gt;) were found:&lt;BR /&gt;&lt;BR /&gt;(1). CVE-2021-44228 (&lt;A href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2021-44228):" target="_blank" rel="noopener"&gt;https://cve.mitre.org/cgi-bin/cvename.cgi?name=2021-44228):&lt;/A&gt;&amp;nbsp;A remote code execution (RCE) vulnerability in Apache Log4j 2.x referred to as "Log4Shell". Log4j fix: 2.15.0&lt;BR /&gt;&lt;BR /&gt;(2). CVE-2021-45046 (&lt;A href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-45046):" target="_blank" rel="noopener"&gt;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-45046):&lt;/A&gt;&amp;nbsp;Under certain conditions, the library is open to DDoS attacks. Log4j fix: 2.16.0.&lt;BR /&gt;&lt;BR /&gt;(3). CVE-2021-45105 (&lt;A href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-45105):" target="_blank" rel="noopener"&gt;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-45105):&lt;/A&gt;&amp;nbsp;A&lt;BR /&gt;second way that allows the remote connection. Log4j fix: 2.17.0.&lt;BR /&gt;&lt;BR /&gt;(4). CVE-2021-44832 (&lt;A href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44832):" target="_blank" rel="noopener"&gt;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44832):&lt;/A&gt;&amp;nbsp;An Arbitrary Code Execution exploit. It is also an RCE vulnerability. Log4j fix: 2.17.1.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;H2&gt;When will patches be released?&lt;/H2&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;The immediate risks to the current vulnerabilities have been addressed, and further releases will become available with their regular release schedule.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;H2&gt;We are running Qlik Replicate (2021.5.0.1133) and Enterprise Manager (2021.5.0.465). If we upgrade to Qlik Replicate (2021.5.0.1272) and Enterprise Manager (2021.5.0.543) would address log4j vulnerability CVE-2021-44228?&lt;/H2&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;Yes. (00020378) CVE-2021-44228, CVE-2021-45046 - is fixed by 2.16.0&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;The above latest build of Replicate and Enterprise Manager contains log4j 2.16.0.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;If necessary, users may manually upgrade to log4j 2.17.1, the detailed steps are in article:&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;&lt;A href="https://community.qlik.com/t5/Knowledge/CVE-2021-45105-CVE-2021-44832-Update-to-log4j-2-17-1-for-Qlik/ta-p/1876190" target="_blank" rel="noopener"&gt;https://community.qlik.com/t5/Knowledge/CVE-2021-45105-CVE-2021-44832-Update-to-log4j-2-17-1-for-Qlik/ta-p/1876190&lt;/A&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;H2&gt;Are there any patches for Qlik Replicate and Enterprise Manager 2021.11?&lt;/H2&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;Yes. Please download Replicate 2021.11 SR1 (2021.11.0.165), QEM 2021.11 SP02 (2021.11.0.198)&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;- or -&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;&lt;A href="https://files.qlik.com/url/qr2021110165sp02" target="_blank" rel="noopener"&gt;https://files.qlik.com/url/qr2021110165sp02&lt;/A&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;(expires 3/31/2022)&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;&lt;A href="https://files.qlik.com/url/qem2021110198sp02" target="_blank" rel="noopener"&gt;https://files.qlik.com/url/qem2021110198sp02&lt;/A&gt; (expires 3/31/2022)&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;H2&gt;Are there any patches for Qlik Replicate and Enterprise Manager 2021.5?&lt;/H2&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;Yes. Please download Replicate 2021.5 SR5 (2021.5.0.1272), QEM 2021.5 SP09 (2021.5.0.543)&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;- or -&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;&lt;A href="https://files.qlik.com/url/qr2021501272sp09" target="_blank" rel="noopener"&gt;https://files.qlik.com/url/qr2021501272sp09&lt;/A&gt; &amp;nbsp;&amp;nbsp;(expires 3/31/2022)&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;&lt;A href="https://files.qlik.com/url/qem202150543sp09" target="_blank" rel="noopener"&gt;https://files.qlik.com/url/qem202150543sp09&lt;/A&gt; (expires 3/31/2022)&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;H2&gt;Are there any patches for Qlik Replicate and Enterprise Manager 7.0 (Nov 2020)?&lt;/H2&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;Yes. Please download Replicate 7.0 SR5 (7.0.0.1221) and QEM SR5 (7.0.0.1607)&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;- Or -&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;&lt;A href="https://files.qlik.com/url/qr700967sp10" target="_blank" rel="noopener"&gt;https://files.qlik.com/url/qr700967sp10&lt;/A&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (expires 04/30/2022)&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;&lt;A href="https://files.qlik.com/url/qem7001602sp10" target="_blank" rel="noopener"&gt;https://files.qlik.com/url/qem7001602sp10&lt;/A&gt; (expires 04/30/2022)&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;H2&gt;Are there any patches for Qlik Replicate and Enterprise Manager 6.6 (Apr 2020)?&lt;/H2&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;Yes. Please download Replicate 6.6 SR6 (6.6.0.904) and QEM SR3 (6.6.0.790)&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;- Or -&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;&lt;A href="https://files.qlik.com/url/qr660904sp14" target="_blank" rel="noopener"&gt;https://files.qlik.com/url/qr660904sp14&lt;/A&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (expires 4/30/2022)&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;&lt;A href="https://files.qlik.com/url/qem660790sp12" target="_blank" rel="noopener"&gt;https://files.qlik.com/url/qem660790sp12&lt;/A&gt; (expires 4/30/2022)&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;H2&gt;Are there any patches for Qlik Replicate and Enterprise Manger 5.5/6.2/6.3/6.4/6.5?&lt;/H2&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;No. These versions are no longer being supported so it will not be patched for the log4j vulnerability. Please consider upgrading to supported versions.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;Take note the upgrade should be 2 steps: 6.x&amp;nbsp; &lt;STRONG&gt;&amp;gt;&amp;nbsp;&lt;/STRONG&gt; 6.6 &lt;STRONG&gt;&amp;gt;&lt;/STRONG&gt; 2021.5 or 2021.11&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;Replicate 6.2 does not have this folder because it does not support endpoint server yet.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;If you are upgrading from Replicate 5.5, please contact Qlik Support.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;For more information, see the product lifecycle:&amp;nbsp;&lt;A href="https://community.qlik.com/t5/Product-Support-Lifecycle/Qlik-Replicate-Product-Lifecycle/ta-p/1837201" target="_blank" rel="noopener"&gt;https://community.qlik.com/t5/Product-Support-Lifecycle/Qlik-Replicate-Product-Lifecycle/ta-p/1837201&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;For mitigation steps, please see:&amp;nbsp;&lt;A href="https://community.qlik.com/t5/Knowledge/CVE-2021-44228-Handling-the-log4j-lookups-critical-vulnerability/ta-p/1869996" target="_blank" rel="noopener"&gt;https://community.qlik.com/t5/Knowledge/CVE-2021-44228-Handling-the-log4j-lookups-critical-vulnerability/ta-p/1869996&lt;/A&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;H2&gt;We are running Replicate 6.3/6.4. Does Log4j vulnerabilities impact the installation?&lt;/H2&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;Replicate v6.3/6.4 does not include Endpoint Server and it is no longer supported. Please consider upgrading to supported versions.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;The product lifecycle:&amp;nbsp;&lt;A href="https://community.qlik.com/t5/Product-Support-Lifecycle/Qlik-Replicate-Product-Lifecycle/ta-p/1837201" target="_blank" rel="noopener"&gt;https://community.qlik.com/t5/Product-Support-Lifecycle/Qlik-Replicate-Product-Lifecycle/ta-p/1837201&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;or mitigation steps:&amp;nbsp;&lt;A href="https://community.qlik.com/t5/Knowledge/CVE-2021-44228-Handling-the-log4j-lookups-critical-vulnerability/ta-p/1869996" target="_blank" rel="noopener"&gt;https://community.qlik.com/t5/Knowledge/CVE-2021-44228-Handling-the-log4j-lookups-critical-vulnerability/ta-p/1869996&lt;/A&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;H2&gt;Why do customers need to manually upgrade to 2.17.1?&lt;/H2&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;We have reviewed a third Log4j vulnerability, CVE-2021-45105, and determined the relevant products (Replicate, Compose, QEM and GeoAnalytics) do not use the logging feature and context string defined in the CVE. Qlik considers the risks of Denial-Of-Service to be low and will address this in future regularly scheduled patch releases.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;For Catalog, Qlik has published service releases for May, August, and November 2021 versions with upgraded Log4j 2.17.0 to the downloads page.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;H2&gt;Do we need to manually upgrade to 2.17.1 for Replicate/Enterprise Manager?&lt;/H2&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;Yes. Customers who require 2.17.1 will need to upgrade log4j manually. You can find instructions here: &lt;A href="https://community.qlik.com/t5/Knowledge/CVE-2021-45105-CVE-2021-44832-Update-to-log4j-2-17-1-for-Qlik/ta-p/1876190" target="_blank" rel="noopener"&gt;https://community.qlik.com/t5/Knowledge/CVE-2021-45105-CVE-2021-44832-Update-to-log4j-2-17-1-for-Qlik/ta-p/1876190&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;&lt;STRONG&gt;Replicate:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;Location to replace jar files: &amp;lt;installation-root&amp;gt;\Replicate\endpoint_srv\externals\ (Default location:C:\Program Files\Attunity\Replicate\endpoint_srv\externals)&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;&lt;STRONG&gt;QEM:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;Location to replace jar files: &amp;lt;installation-root&amp;gt;\Enterprise Manager\java\external (Default location:C:\Program Files\Attunity\Enterprise Manager\java\external)&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;&lt;STRONG&gt;Qlik Compose:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;Location to replace jar files: &amp;lt;installation-root&amp;gt;\Compose\java\external (Default location: C:\Program Files\Qlik\Compose\java\external)&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;&lt;STRONG&gt;Qlik Compose for Data Lakes:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;Location to replace jar files: &amp;lt;installation-root&amp;gt;\Compose for Data Lakes\java\external (Default location: C:\Program Files\Attunity\Compose for Data Lakes\java\external)&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;&lt;STRONG&gt;Qlik Compose for Data warehouses:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;Location to replace jar files: &amp;lt;installation-root&amp;gt;\Compose for Data warehouses\java\external (Default location: C:\Program Files\Attunity\Compose for Data Warehouses\java\external)&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;H2&gt;Do we need to manually upgrade to 2.17.1 for Compose?&lt;/H2&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;Yes. Customers who require 2.17.1 will need to upgrade log4j manually. You can find instructions here: &lt;A href="https://community.qlik.com/t5/Knowledge/CVE-2021-45105-CVE-2021-44832-Update-to-log4j-2-17-1-for-Qlik/ta-p/1876190" target="_blank" rel="noopener"&gt;https://community.qlik.com/t5/Knowledge/CVE-2021-45105-CVE-2021-44832-Update-to-log4j-2-17-1-for-Qlik/ta-p/1876190&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;&lt;STRONG&gt;Replicate:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;Location to replace jar files: &amp;lt;installation-root&amp;gt;\Replicate\endpoint_srv\externals\ (Default location:C:\Program Files\Attunity\Replicate\endpoint_srv\externals)&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;&lt;STRONG&gt;QEM:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;Location to replace jar files: &amp;lt;installation-root&amp;gt;\Enterprise Manager\java\external (Default location:C:\Program Files\Attunity\Enterprise Manager\java\external)&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;&lt;STRONG&gt;Qlik Compose:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;Location to replace jar files: &amp;lt;installation-root&amp;gt;\Compose\java\external (Default location: C:\Program Files\Qlik\Compose\java\external)&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;&lt;STRONG&gt;Qlik Compose for Data Lakes:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;Location to replace jar files: &amp;lt;installation-root&amp;gt;\Compose for Data Lakes\java\external (Default location: C:\Program Files\Attunity\Compose for Data Lakes\java\external)&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;&lt;STRONG&gt;Qlik Compose for Data warehouses:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;Location to replace jar files: &amp;lt;installation-root&amp;gt;\Compose for Data warehouses\java\external (Default location: C:\Program Files\Attunity\Compose for Data Warehouses\java\external)&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;H2&gt;We followed the mitigation steps from the Qlik file and renamed the file name from "Log4j-core-2.14.1.jar" to "log4j-core-nolookup-2.14.1.jar". When upgrading to the latest build, do we need to rename the mentioned jar file name, or can we perform upgrade installation as-is?&lt;/H2&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;Yes.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;The best approach is renaming the jar files (log4j-core-nolookup-2.14.1.jar) to their original file name (log4j-core-2.14.1.jar) before upgrade or&amp;nbsp;remove the files out of Replicate installation folder.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;This is because Replicate installation program will try to remove the old jar files. If it cannot find it, a warning reported:&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;&lt;STRONG&gt;warning:&lt;/STRONG&gt; file /opt/attunity/replicate/endpoint_srv/externals/log4j-core-2.14.1.jar: remove failed: No such file or directory&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;In this case, the installation program cannot remove the useless jar file, the unnecessary jar file left in the folder, there are 2 versions log4j-core jar files after the upgrade is done. Please remove the "log4j-core-nolookup-2.14.1.jar" manually and restart the services.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;H2&gt;Which GeoAnalytics versions will be upgraded to 2.17?&lt;/H2&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;The November 2021 release can be upgraded using the patch available on the downloads site.&lt;BR /&gt;&lt;BR /&gt;Qlik recommends that customers on previous versions upgrade to the November 2021 release.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;&lt;A href="https://da3hntz84uekx.cloudfront.net/GeoAnalytics/4.32.4/31260/GeoAnalyticsServerReleaseNotes-November2021Patch2.pdf" target="_blank" rel="noopener"&gt;https://da3hntz84uekx.cloudfront.net/GeoAnalytics/4.32.4/31260/GeoAnalyticsServerReleaseNotes-November2021Patch2.pdf&lt;/A&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;H2&gt;What’s the mitigation steps for Visibility?&lt;/H2&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;Qlik is providing these mitigation steps as a temporary measure. Detailed steps see:&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;&lt;A href="https://community.qlik.com/t5/Knowledge/CVE-2021-44832-Handling-the-log4shell-vulnerability-for/ta-p/1877884" target="_blank" rel="noopener"&gt;https://community.qlik.com/t5/Knowledge/CVE-2021-44832-Handling-the-log4shell-vulnerability-for/ta-p/1877884&lt;/A&gt;&lt;/P&gt;
&lt;/DIV&gt;</description>
      <pubDate>Tue, 15 Feb 2022 20:30:41 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Get-Started/FAQ-for-Log4J-Vulnerabilities/ta-p/1893106</guid>
      <dc:creator>Katie_Davis</dc:creator>
      <dc:date>2022-02-15T20:30:41Z</dc:date>
    </item>
    <item>
      <title>Re: FAQ for Log4J Vulnerabilities</title>
      <link>https://community.qlik.com/t5/Get-Started/FAQ-for-Log4J-Vulnerabilities/tac-p/1930035#M482</link>
      <description>&lt;P&gt;Is Log4j v2.3.2 the only version compatible with Visibility for this vulnerability. Under the general section on info about CVE02021-4428 noted below, it recommends at least v2.15.0. Is there a 2.15.0 version that can be downloaded and tested for Visibility?&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;(1). CVE-2021-44228 (&lt;/SPAN&gt;&lt;A href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2021-44228):" target="_blank" rel="noopener nofollow noreferrer"&gt;https://cve.mitre.org/cgi-bin/cvename.cgi?name=2021-44228):&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;A remote code execution (RCE) vulnerability in Apache Log4j 2.x referred to as "Log4Shell". Log4j fix: 2.15.0&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Please advise.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Vikki turner&lt;/P&gt;
&lt;P&gt;vikki.turner@pnc.com&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2022 19:47:43 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Get-Started/FAQ-for-Log4J-Vulnerabilities/tac-p/1930035#M482</guid>
      <dc:creator>Vikki</dc:creator>
      <dc:date>2022-05-12T19:47:43Z</dc:date>
    </item>
  </channel>
</rss>

