QID 106032
Date Published: 2022-01-12
QID 106032: EOL/Obsolete Software: Apache Log4j 1.X Detected
On August 5, 2015, the Apache Logging Services Project Management Committee (PMC) has announced that the Log4j 1.x logging framework has reached its end of life (EOL) and is no longer officially supported.
QID Detection: (Authenticated) - Linux
This QID uses the OS package manager, locate command and ls proc command to check vulnerable versions of log4j
QID Detection: (Authenticated) - Windows
On Windows system, the QID identifies vulnerable instance of log4j via WMI query to check log4j included in the running processes via command-line.
Apache no longer provides security updates for 1.x versions. Obsolete software is more vulnerable to viruses and other attacks.
Solution
Customers are advised to upgrade to Apache Log4j 2.X, for more information please refer to Apache Blog.
Vendor References
- Apache Log4j Security Advisory -
blogs.apache.org/foundation/entry/apache_logging_services_project_announces
CVEs related to QID 106032
Software Advisories
| Advisory ID | Software | Component | Link |
|---|