Micro Focus Response on “Log4j” Vulnerability

Micro Focus is taking immediate action to analyze and to remediate, where appropriate, Common Vulnerabilities and Exposures (CVE-2021-44228 / Log4j also known as Logshell / Logjam),…

OpenText  profile picture
OpenText

December 13, 20212 minute read

Micro Focus is taking immediate action to analyze and to remediate, where appropriate, Common Vulnerabilities and Exposures (CVE-2021-44228 / Log4j also known as Logshell / Logjam), a reported vulnerability in the Apache Log4j open source-component that allows Remote Code Execution. Using the Remote Code Execution an attacker can potentially run malicious code that can perform unauthorized operations. This is defined by the Common Vulnerability Scoring System (CVSS) as a level 10 exploit. Micro Focus uses Log4j for standard logging functionality across a number of product portfolios. We are actively remediating the vulnerability across those products to protect both SaaS and on-premises customers and issuing security bulletins with instructions on how to remediate for on-premises installations. We will continue to provide details of the Log4j compromise until the risk is completely mitigated. Updates can be found here.

Micro Focus uses a mature formal process to handle vulnerabilities that are identified both internally and externally. We have a robust, dedicated, full-time threat intelligence team with a Micro Focus-wide view, that is constantly reviewing new reports of vulnerabilities, threats and compromises for possible impact to our products and network.

Micro Focus operates a Secure Development Lifecycle that includes among other practices, a Supply Chain Security practice, 3rd Party Component Manifest and a 3rd Party Component Monitoring. Using these formal practices we ensure 3rd party components are sourced from trusted repositories, scanned and tested, free of known CVEs, and signed to ensure authenticity and integrity. New vulnerabilities are scanned and tracked to ensure closure. Unsupported 3rd party components are deprecated.

Micro Focus has a formal practice of secure software coding that is designed to protect against malicious code, backdoors, transitive dependency based vulnerabilities and other threats.

Micro Focus is actively implementing patches and mitigation measures where appropriate for the Log4j vulnerability. Zero-Day and Critical vulnerabilities are fast tracked and delivered outside the product’s major point release cycle. We rank potential patches according to CVSS scoring, and also our own enhanced scoring system that takes additional data points into account. Configuration changes or patch installations require Quality Assurance analysis and testing prior to deployment to production systems to prevent unexpected service interruptions.

After investigation and analysis, we have had no indications of Log4j intrusions as of today, December 13, 2021.

For more information and regular updates please visit our Security updates page.

Share this post

Share this post to x. Share to linkedin. Mail to
OpenText avatar image

OpenText

OpenText, The Information Company, enables organizations to gain insight through market-leading information management solutions, powered by OpenText Cloud Editions.

See all posts

More from the author

All we want for Christmas:  An open letter to Santa from a modern legal team  

All we want for Christmas:  An open letter to Santa from a modern legal team  

As legal professionals embracing digital transformation, our wish list is a bit different this year.

December 11, 2024 4 minute read

Supercharge Your Data Strategy with the Latest Insights on Data and AI

Supercharge Your Data Strategy with the Latest Insights on Data and AI

Introducing the 2024 CXO Insights Guide on Data & AI Guide

October 31, 2024 6 minute read

From breakdown to breakthrough: How predictive and prescriptive maintenance are revolutionizing operations

From breakdown to breakthrough: How predictive and prescriptive maintenance are revolutionizing operations

Cut downtime, save costs, improve safety and stay ahead of failures with advanced analytics and AI-powered maintenance strategies.

October 16, 2024 7 minute read

Stay in the loop!

Get our most popular content delivered monthly to your inbox.