Feedback
Did this article resolve your question/issue?

   

Article

Is Hybrid Data Pipeline vulnerable to the various 2021 Log4J vulnerabilities?

« Go Back

Information

 
TitleIs Hybrid Data Pipeline vulnerable to the various 2021 Log4J vulnerabilities?
URL NameIs-Hybrid-Data-Pipeline-vulnerable-to-the-various-2021-Log4J-vulnerabilities
Article Number000207279
Information
Hybrid Data Pipeline (HDP) does utilize Log4j, so some versions of HDP have been susceptible to the 2021 Log4J vulnerabilities.
While the situation continues to evolve, we recommend customers upgrade to the latest version of HDP (4.6.1.311 or higher).  The 4.6.1.311 version of HDP addresses the currently known log4j vulnerabilities.
For a more in-depth explanation or alternative mitigations, please see the list of KB articles on specific log4j vulnerabilities.

Is Hybrid Data Pipeline vulnerable to CVE-2021-44228 (Log4j)?
Is Hybrid Data Pipeline vulnerable to CVE-2021-45046(Log4j DoS)?
Is Hybrid Data Pipeline vulnerable to CVE-2021-45105 (Log4j 1.x)?

Is Hybrid Data Pipeline vulnerable to CVE-2021-4104(Log4j 1.x)?
Is Hybrid Data Pipeline vulnerable to CVE-2019-17571 (Log4j 1.x)?
Additional Information
EnvironmentHybrid Data Pipeline
Last Modified Date12/21/2021 12:10 AM
Attachment 
Files
Disclaimer The origins of the information on this site may be internal or external to Progress Software Corporation (“Progress”). Progress Software Corporation makes all reasonable efforts to verify this information. However, the information provided is for your information only. Progress Software Corporation makes no explicit or implied claims to the validity of this information.

Any sample code provided on this site is not supported under any Progress support program or service. The sample code is provided on an "AS IS" basis. Progress makes no warranties, express or implied, and disclaims all implied warranties including, without limitation, the implied warranties of merchantability or of fitness for a particular purpose. The entire risk arising out of the use or performance of the sample code is borne by the user. In no event shall Progress, its employees, or anyone else involved in the creation, production, or delivery of the code be liable for any damages whatsoever (including, without limitation, damages for loss of business profits, business interruption, loss of business information, or other pecuniary loss) arising out of the use of or inability to use the sample code, even if Progress has been advised of the possibility of such damages.