<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article CVE_2021_44228 - Handling the LOG4J Lookups Critical Vulnerability for Qlik Catalog in Official Support Articles</title>
    <link>https://community.qlik.com/t5/Official-Support-Articles/CVE-2021-44228-Handling-the-LOG4J-Lookups-Critical-Vulnerability/ta-p/1871126</link>
    <description>&lt;P&gt;The following two configuration changes may be used to disable the expression evaluation feature of log4j2, and can immediately be applied to &lt;STRONG&gt;single-node Catalog May 2021 through Nov 2021, &lt;FONT color="#008000"&gt;or any version of multi-node Catalog&lt;/FONT&gt;&lt;/STRONG&gt;&lt;FONT color="#008000"&gt; where log4j2 is on the cluster vendor's Hadoop classpath:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="mc-variable CommonComponents.GeoAnalyticsConnector variable"&gt;Patches are available. See&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://community.qlik.com/t5/Support-Updates-Blog/Vulnerability-Testing-Apache-Log4j-reference-CVE-2021-44228-also/ba-p/1869368" target="_self"&gt;Vulnerability Testing - Apache Log4j, reference CVE-2021-44228 (also referred to as Log4Shell)&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;for your release and the relevant patch.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;&lt;SPAN class="mc-variable CommonComponents.GeoAnalyticsConnector variable"&gt;Upgrade at the earliest.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;Environment&lt;/H4&gt;
&lt;UL&gt;
&lt;LI&gt;#QlikCatalog&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;Resolution for Qlik Catalog (May 2021-Nov. 2021)&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Before proceeding, check the first page of&amp;nbsp;&lt;A title="Catalog 4.x fix" href="https://community.qlik.com/t5/Support-Updates-Blog/Vulnerability-Testing-Apache-Log4j-reference-CVE-2021-44228-also/ba-p/1869368#comments" target="_blank" rel="noopener"&gt;Catalog 4.x fix&lt;/A&gt;&amp;nbsp;with Log4j 2.17.0. It's highly recommended to apply the fix. However, if you're not ready for the upgrade and you wish to mitigate the&amp;nbsp;vulnerabilities manually, then proceed with the steps below.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;(1) add line to end of bin/setenv.sh:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;export JAVA_OPTS="$JAVA_OPTS -Dlog4j2.formatMsgNoLookups=true"&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Can't find the file?&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;The sample location of the file "setenv.sh":&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Sonja_Bauernfeind_0-1640774568138.png" style="width: 400px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/69338i6C560A1CCC19F10D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Sonja_Bauernfeind_0-1640774568138.png" alt="Sonja_Bauernfeind_0-1640774568138.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;(2) find and edit property in core_env.properties:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;# Pipe (|) delimited list of additional arguments to be passed to the Java runtime. Default: none&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;external.job.runner.extra.java.arguments=-Dlog4j2.formatMsgNoLookups=true&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Can't find the file? &lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;The sample location of the file "core_env.properites":&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Sonja_Bauernfeind_1-1640774568287.png" style="width: 400px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/69339iCF6BE9B30CBD767A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Sonja_Bauernfeind_1-1640774568287.png" alt="Sonja_Bauernfeind_1-1640774568287.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;(3) Restart Tomcat.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.lunasec.io/docs/blog/log4j-zero-day-mitigation-guide/" target="_blank" rel="noopener"&gt;https://www.lunasec.io/docs/blog/log4j-zero-day-mitigation-guide/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;For more information on the Log4j vulnerability, please visit the&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://community.qlik.com/t5/Support-Updates-Blog/Vulnerability-Testing-Apache-Log4j-reference-CVE-2021-44228-also/ba-p/1869368" target="_blank" rel="noopener"&gt;Support Updates Blog&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;post.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 25 Jan 2022 12:49:05 GMT</pubDate>
    <dc:creator>Katie_Davis</dc:creator>
    <dc:date>2022-01-25T12:49:05Z</dc:date>
    <item>
      <title>CVE_2021_44228 - Handling the LOG4J Lookups Critical Vulnerability for Qlik Catalog</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/CVE-2021-44228-Handling-the-LOG4J-Lookups-Critical-Vulnerability/ta-p/1871126</link>
      <description>&lt;P&gt;The following two configuration changes may be used to disable the expression evaluation feature of log4j2, and can immediately be applied to &lt;STRONG&gt;single-node Catalog May 2021 through Nov 2021, &lt;FONT color="#008000"&gt;or any version of multi-node Catalog&lt;/FONT&gt;&lt;/STRONG&gt;&lt;FONT color="#008000"&gt; where log4j2 is on the cluster vendor's Hadoop classpath:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="mc-variable CommonComponents.GeoAnalyticsConnector variable"&gt;Patches are available. See&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://community.qlik.com/t5/Support-Updates-Blog/Vulnerability-Testing-Apache-Log4j-reference-CVE-2021-44228-also/ba-p/1869368" target="_self"&gt;Vulnerability Testing - Apache Log4j, reference CVE-2021-44228 (also referred to as Log4Shell)&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;for your release and the relevant patch.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;&lt;SPAN class="mc-variable CommonComponents.GeoAnalyticsConnector variable"&gt;Upgrade at the earliest.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;Environment&lt;/H4&gt;
&lt;UL&gt;
&lt;LI&gt;#QlikCatalog&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;Resolution for Qlik Catalog (May 2021-Nov. 2021)&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Before proceeding, check the first page of&amp;nbsp;&lt;A title="Catalog 4.x fix" href="https://community.qlik.com/t5/Support-Updates-Blog/Vulnerability-Testing-Apache-Log4j-reference-CVE-2021-44228-also/ba-p/1869368#comments" target="_blank" rel="noopener"&gt;Catalog 4.x fix&lt;/A&gt;&amp;nbsp;with Log4j 2.17.0. It's highly recommended to apply the fix. However, if you're not ready for the upgrade and you wish to mitigate the&amp;nbsp;vulnerabilities manually, then proceed with the steps below.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;(1) add line to end of bin/setenv.sh:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;export JAVA_OPTS="$JAVA_OPTS -Dlog4j2.formatMsgNoLookups=true"&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Can't find the file?&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;The sample location of the file "setenv.sh":&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Sonja_Bauernfeind_0-1640774568138.png" style="width: 400px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/69338i6C560A1CCC19F10D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Sonja_Bauernfeind_0-1640774568138.png" alt="Sonja_Bauernfeind_0-1640774568138.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;(2) find and edit property in core_env.properties:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;# Pipe (|) delimited list of additional arguments to be passed to the Java runtime. Default: none&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;external.job.runner.extra.java.arguments=-Dlog4j2.formatMsgNoLookups=true&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Can't find the file? &lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;The sample location of the file "core_env.properites":&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Sonja_Bauernfeind_1-1640774568287.png" style="width: 400px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/69339iCF6BE9B30CBD767A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Sonja_Bauernfeind_1-1640774568287.png" alt="Sonja_Bauernfeind_1-1640774568287.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;(3) Restart Tomcat.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.lunasec.io/docs/blog/log4j-zero-day-mitigation-guide/" target="_blank" rel="noopener"&gt;https://www.lunasec.io/docs/blog/log4j-zero-day-mitigation-guide/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;For more information on the Log4j vulnerability, please visit the&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://community.qlik.com/t5/Support-Updates-Blog/Vulnerability-Testing-Apache-Log4j-reference-CVE-2021-44228-also/ba-p/1869368" target="_blank" rel="noopener"&gt;Support Updates Blog&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;post.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jan 2022 12:49:05 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/CVE-2021-44228-Handling-the-LOG4J-Lookups-Critical-Vulnerability/ta-p/1871126</guid>
      <dc:creator>Katie_Davis</dc:creator>
      <dc:date>2022-01-25T12:49:05Z</dc:date>
    </item>
    <item>
      <title>Re: CVE_2021_44228 - Handling the LOG4J Lookups Critical Vulnerability for Qlik Catalog</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/CVE-2021-44228-Handling-the-LOG4J-Lookups-Critical-Vulnerability/tac-p/1875411#M5170</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/147077"&gt;@Katie_Davis&lt;/a&gt;&amp;nbsp;, &lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/28597"&gt;@Sonja_Bauernfeind&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;I'd like to add some extra information.&lt;/P&gt;
&lt;P&gt;First of all, please check the first page of&amp;nbsp;&lt;A title="Catalog 4.x fix" href="https://community.qlik.com/t5/Support-Updates-Blog/Vulnerability-Testing-Apache-Log4j-reference-CVE-2021-44228-also/ba-p/1869368#comments" target="_blank" rel="noopener"&gt;Catalog 4.x fix&lt;/A&gt;&amp;nbsp;with Log4j 2.17.0. It's highly recommended to apply the fix. However if you're not ready for the upgrade and you wish to mitigate the&amp;nbsp;vulnerabilities manually , then the location of the files are (depends on the tomcat version number):&lt;/P&gt;
&lt;P&gt;1. the sample location of the file "setenv.sh" :&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="john_wang_0-1640665452068.png" style="width: 400px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/69264i76A7899EC2AA3BE0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="john_wang_0-1640665452068.png" alt="john_wang_0-1640665452068.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. the sample location of the file "core_env.properites":&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="john_wang_1-1640665509930.png" style="width: 400px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/69265i3555B2C3574EA770/image-size/medium?v=v2&amp;amp;px=400" role="button" title="john_wang_1-1640665509930.png" alt="john_wang_1-1640665509930.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;John.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Dec 2021 04:31:34 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/CVE-2021-44228-Handling-the-LOG4J-Lookups-Critical-Vulnerability/tac-p/1875411#M5170</guid>
      <dc:creator>john_wang</dc:creator>
      <dc:date>2021-12-28T04:31:34Z</dc:date>
    </item>
  </channel>
</rss>

