About the log4net vulnerability (CVE-2018-1285)
Article # 3042636 - Page views: 130
Issue
About the log4net vulnerability (CVE-2018-1285).
Cause
This is a know vulnerability fixed in log4net v2.0.10. Kofax RPA uses 2.0.9.0 in 11.1 and 11.2, and previous log4net versions in older RPA ones.
Solution
The upcoming version of RPA, 11.3, has updated log4net from 2.0.9.0 to 2.0.14, so it is no longer under this vulnerability.
Level of Complexity
Easy
Applies to
Product | Version | Build | Environment | Hardware |
---|---|---|---|---|
RPA | 11.2 and previous |
References
Add any references to other internal or external articles
Article # 3042636