(ID1518) Flash: Information related to Log4Shell security vulnerability


Product lines

  • BMC AMI Data for Db2 products
  • BMC AMI Data for IMS products
  • BMC AMI Ops products
  • BMC AMI Security products
  • BMC Compuware products

Versions

All supported versions

Date

2021/12/15 00:00

A serious problem in the products and components listed in the Issue section requires immediate attention. 

Issue

We have found an exposure to Log4Shell vulnerability in the following products and components:

  • BMC AMI Ops Infrastructure, version 7.0.00
  • BMC AMI Ops Insight, versions 1.0.00 and 1.2.00

    Warning

    Important

    If you are using version 1.0.00 of BMC AMI Ops Insight, you must upgrade to version 1.2.00 before applying the PTFs.

  • BMC Common REST API (CRA), version 2.0.00 

    Warning

    Important

    If you are using version 1.0.00 of CRA, you must upgrade to version 2.0 before applying the PTFs.

  • BMC AMI Ops UI, version 1.1.00—a web-based user interface component of the BMC AMI Ops Infrastructure product
  • MainView Middleware Monitor, version 9.1.00

Resolution

For more information about the issue, complete list of affected and unaffected products, and the list of correcting PTFs, seeBMC Security Advisory for CVE-2021-44228 Log4Shell Vulnerability .

Error
Important

If additional information becomes available, we will update this notice only in the documentation portal. To receive an email alert whenever the notice changes, set a watch on the notice's page:

  1. In the upper right toolbar, click Watch:
    watch.png
  2. Click Watch this Page.
  3. Email alerts are sent from docs-noreply@bmc.com, so make sure that @bmc.com is in your mail system's safe list to prevent email alerts being lost in your spam folder.

If you have questions, callBMC Support. If outside the United States, use the Select Another Country drop-down list to search for local phone numbers.

 

Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*

BMC Compuware common notices