Skip to main content
Announcements
Live today at 11 AM ET. Get your questions about Qlik Connect answered, or just listen in. SIGN UP NOW

Qlik GeoAnalytics older versions of Log4j found in jetty-0_0_0_0-80-ravegeo_war subfolder

No ratings
cancel
Showing results for 
Search instead for 
Did you mean: 
Sebastian_Linser

Qlik GeoAnalytics older versions of Log4j found in jetty-0_0_0_0-80-ravegeo_war subfolder

Last Update:

Jan 26, 2023 3:25:48 AM

Updated By:

Sonja_Bauernfeind

Created date:

Jan 25, 2023 9:59:39 AM

On a deep scan for log4j files, you might find a hit in a folder called jetty-0_0_0_0-80-ravegeo_war*. Those files are from earlier versions before the fixes had been implemented. E.g. log4j-core-2.13.3.jar.

 

Resolution

  1. Stop the Geoanalytics server and change to the folder you found the files in, the usual ones are listed below

    C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\ or c:\users\USERNAMe\appdata\local\temp\

  2. Delete the jetty-0_0_0_0-80-ravegeo_war* subfolders.

  3. Restart the Qlik Geoanalytics Service again.

Cause 

Older versions of Qlik Geoanalytics extracted log4j jar files into 

C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\jetty-0_0_0_0-80-ravegeo_war-_ravegeo-any-9094929437680040180\webapp\WEB-INF\lib

or 

c:\users\USERNAMe\appdata\local\temp\jetty-0_0_0_0-8080-ravegeo_war-_ravegeo-any-5388159241656068212.dir\webapp\web-inf\lib\

 

Environment

Related Content

CVE_2021_44228 - Handling the log4j lookups critical vulnerability for Qlik GeoAnalytics

 

Labels (1)
Version history
Last update:
‎2023-01-26 03:25 AM
Updated by: