BizTalk 2016 : log4J vulnerability

Sunil Ahire 21 Reputation points
2021-12-22T03:42:56.36+00:00

Hi,
This is about apache log4j vulnerability. Is BizTalk 2016 platform impacted because of this?
I dont think so but need a confirmation

Regards,
Sunil.

Microsoft BizTalk Server
Microsoft BizTalk Server
A family of Microsoft server products that support large-scale implementation management of enterprise application integration processes.
365 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Colin Dijkgraaf 1,361 Reputation points
    2021-12-22T19:31:05.147+00:00

    Only if BizTalk uses an Adapter that is Java based, or call out to Java, of which there are a few around.

    I found the log4j library in the Oracle Client, however that looks to be a version 1.0, so not vulnerable to the log4Shell vulnerabilities, but it might have other vulnerabilities.

    I also checked out a third party adapter used to connect to AMQ, but couldn't find it referenced there, but I might take another look.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.