IBM Support

PH42759: Block class loads for vulnerable classes

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • Allow application class loaders to block class loads of
    classes with security vulnerabilities
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED:  All users of WebSphere Liberty              *
    ****************************************************************
    * PROBLEM DESCRIPTION: Security-compromised classes can be     *
    *                      loaded by the Liberty application and   *
    *                      library class loaders.                  *
    ****************************************************************
    * RECOMMENDATION:                                              *
    ****************************************************************
    Applications deployed to Liberty servers may include versions of
    Log4j2 that are affected by the Log4Shell (CVE-2021-44228)
    vulnerability. This APAR updates the Liberty application and
    shared library class loaders to block the loading of the
    org.apache.logging.log4j.core.lookup.JndiLookup class, which is
    the cause of the vulnerability. IBM recommends customers
    analyze their applications for use of Log4j2 with urgency; in
    the meantime this fix may help mitigate Log4Shell and other
    vulnerabilities related to that class. This APAR will not
    protect in cases where the Log4j2 classes have been renamed (a
    process known as "shading") or if Log4j2 is loaded from non-
    Liberty class loaders (e.g. Java system class loaders or user-
    created class loaders). This fix is provided for customers to
    assist in creating a holistic deep defense against Log4Shell.
    

Problem conclusion

  • Blocking of class loads for
    org.apache.logging.log4j.core.lookup.JndiLookup was added to the
    Liberty application and shared library class loaders.
    
    NOTE: For applications utilizing the Log4j 2.0 Beta 9 release,
    preventing the load of this class will cause an uncaught
    NoClassDefFoundError. Users whose applications include this
    library are advised to update their Log4j immediately and avoid
    applying this APAR until after that update is applied.
    
    The fix for this APAR is targeted for inclusion in Liberty
    22.0.0.1. For more information, see 'Recommended
    Updates for WebSphere Application Server':
    https://www.ibm.com/support/pages/node/715553
    

Temporary fix

Comments

APAR Information

  • APAR number

    PH42759

  • Reported component name

    WEBSPHERE APP S

  • Reported component ID

    5724J0800

  • Reported release

    900

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2021-12-13

  • Closed date

    2021-12-15

  • Last modified date

    2022-01-18

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    WEBSPHERE APP S

  • Fixed component ID

    5724J0800

Applicable component levels

[{"Line of Business":{"code":"LOB45","label":"Automation"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSEQTP","label":"WebSphere Application Server"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"9.0"}]

Document Information

Modified date:
19 January 2022