Fixes are available
APAR status
Closed as program error.
Error description
Allow application class loaders to block class loads of classes with security vulnerabilities
Local fix
Problem summary
**************************************************************** * USERS AFFECTED: All users of WebSphere Liberty * **************************************************************** * PROBLEM DESCRIPTION: Security-compromised classes can be * * loaded by the Liberty application and * * library class loaders. * **************************************************************** * RECOMMENDATION: * **************************************************************** Applications deployed to Liberty servers may include versions of Log4j2 that are affected by the Log4Shell (CVE-2021-44228) vulnerability. This APAR updates the Liberty application and shared library class loaders to block the loading of the org.apache.logging.log4j.core.lookup.JndiLookup class, which is the cause of the vulnerability. IBM recommends customers analyze their applications for use of Log4j2 with urgency; in the meantime this fix may help mitigate Log4Shell and other vulnerabilities related to that class. This APAR will not protect in cases where the Log4j2 classes have been renamed (a process known as "shading") or if Log4j2 is loaded from non- Liberty class loaders (e.g. Java system class loaders or user- created class loaders). This fix is provided for customers to assist in creating a holistic deep defense against Log4Shell.
Problem conclusion
Blocking of class loads for org.apache.logging.log4j.core.lookup.JndiLookup was added to the Liberty application and shared library class loaders. NOTE: For applications utilizing the Log4j 2.0 Beta 9 release, preventing the load of this class will cause an uncaught NoClassDefFoundError. Users whose applications include this library are advised to update their Log4j immediately and avoid applying this APAR until after that update is applied. The fix for this APAR is targeted for inclusion in Liberty 22.0.0.1. For more information, see 'Recommended Updates for WebSphere Application Server': https://www.ibm.com/support/pages/node/715553
Temporary fix
Comments
APAR Information
APAR number
PH42759
Reported component name
WEBSPHERE APP S
Reported component ID
5724J0800
Reported release
900
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt / Xsystem
Submitted date
2021-12-13
Closed date
2021-12-15
Last modified date
2022-01-18
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
WEBSPHERE APP S
Fixed component ID
5724J0800
Applicable component levels
[{"Line of Business":{"code":"LOB45","label":"Automation"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSEQTP","label":"WebSphere Application Server"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"9.0"}]
Document Information
Modified date:
19 January 2022