Jim,

I wouldn't have believed it unless I experienced it myself.

If that's the case then why not answer me by saying "We don't know for sure, but we're looking into it as quickly as possible".

It's the way they are answering me (or not) that is making me furious... reminds me of a White House press conference.

-----Original Message-----
From: MIDRANGE-L <midrange-l-bounces@xxxxxxxxxxxxxxxxxx> On Behalf Of Jim Oberholtzer
Sent: Monday, December 13, 2021 3:02 PM
To: Midrange Systems Technical Discussion <midrange-l@xxxxxxxxxxxxxxxxxx>
Subject: Re: Remote code execution exploit found in Log4j - CVE-2021-44228

I don't know if IBM is evasive, or if they don't really know
definitively yet, I'm going with the latter at this point. Also IBM tends
to release the PTFs when they announce the vulnerability as well, so I'll
bet there are developers working to identify and correct anything they need
to.

That logging is usually called out as a java class, ie:

package org.apache.logging; import org.apache.logging.log4j.LogManager;
import org.apache.logging.log4j.Logger;
import org.apache.logging.log4j.Marker;

It could be used in 1000s of places, or none. We have to wait for more
information.

--
Jim Oberholtzer
Chief Technical Architect
Agile Technology Architects


On Mon, Dec 13, 2021 at 9:41 AM Greg Wilburn <
gwilburn@xxxxxxxxxxxxxxxxxxxxxxx> wrote:

IBM Support's response is to push you to the blog
https://www.ibm.com/blogs/psirt/

Which then references the link below. Nothing in the link below tells me
anything about the IBM i specifically. I added the environment variable
and restarted DB2 Web Query. But beyond that, the steps are Greek to me.

The only application we have externally facing is DB2 Web Query. I asked
if it was affected... support just keeps reiterating "our only
communication is via the blog"

I have never seen IBM support so "evasive" about an issue.



As an Amazon Associate we earn from qualifying purchases.

This thread ...

Follow-Ups:
Replies:

Follow On AppleNews
Return to Archive home page | Return to MIDRANGE.COM home page

This mailing list archive is Copyright 1997-2022 by midrange.com and David Gibbs as a compilation work. Use of the archive is restricted to research of a business or technical nature. Any other uses are prohibited. Full details are available on our policy page. If you have questions about this, please contact [javascript protected email address].

Operating expenses for this site are earned using the Amazon Associate program and Google Adsense.