Skip to main content

Zero-Day Exploit in log4j | log4shell

Comments

11 comments

  • Zendesk API User
    Author: choff - 12/14/2021 7:40

    In what context is the script meant to be run? I tried to run it as a beanshell script inside the SiteArchitect. This lead to an error because connection is unknown. What kind of connection is connection meant to be and where can I get if from?

    Thanks in advance for your support.

    0
  • Zendesk API User
    Author: brandelc - 12/14/2021 8:06

    For me it worked adding it as a schedule entry with a script action in the Server Properties and running it from the ServerManager.

    You need to make sure that your server has the appropriate logging level set (INFO or DEBUG), or you won't see any output from the script in the logs.

    0
  • Zendesk API User
    Author: dleinich - 12/14/2021 8:38

    Yes, it's meant to be run as a schedule entry. Thanks for pointing that out. Will clarify that soon.

    0
  • Zendesk API User
    Author: bianca_batsch - 12/14/2021 8:46

    Hello Christian,

    that was helpful :smileygrin: - how / where do I check​ / edit the log-level of the server?

    Best regards

    Bianca

    0
  • Zendesk API User
    Author: brandelc - 12/14/2021 8:50

    See here: Documentation for Administrators - Logging

    0
  • Zendesk API User
    Author: rodrigo_lopes - 12/14/2021 9:56

    Hello,

    I am using version 2010-01. Does this article also cover that version?

    Cheers

    0
  • Zendesk API User
    Author: bianca_batsch - 12/14/2021 10:11

    I would bet, that Version 2010-01 is covered by nothing.... :smileysad:

    0
  • Zendesk API User
    Author: gockel - 12/15/2021 6:50

    Hi Rodrigo,

    not sure which version you meant here.

    We started the release name version scheme in 2018. Therefore, as far as I know, back in year 2010 there was never a version 2010-01.

    Which version exactly do you mean?
    Please provide more specific version information collected from the about page of your server. (http://<YOUR-SERVER>/about.jsp)

    0
  • Zendesk API User
    Author: linde - 12/15/2021 11:21

    Some customer ask for the vulnerability of the SiteArchitect. Are the statements for FirstSpirit also valid for the SiteArchitect?

    0
  • Zendesk API User
    Author: dleinich - 12/15/2021 11:50

    Yes, for both SiteArchitect and ServerManager.

    0
  • Zendesk API User
    Author: RZoller - 12/15/2021 18:57

    Hallo zusammen,

    Monday Webform wurde gerade aktualisiert und kann verwendet werden. Die Aktualisierung umfasst das Update der log4j-Version auf log4j v2.16.0. Die Webforms-Versionen sind im Einzelnen:

    • Webforms 6.3.6.FS5
    • Webforms 6.2.10.FS5
    • Webforms 6.1.9.FS5
    • Webforms 6.0.3.FS5

    René

    0

Please sign in to leave a comment.