Skip to content
DataMiner DoJo

More results...

Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
Search in posts
Search in pages
Log in
Menu
  • Blog
  • Questions
  • Learning
    • E-learning Courses
    • Empower Replay: Limited Edition
    • Tutorials
    • Open Classroom Training
    • Certification
      • DataMiner Fundamentals
      • DataMiner Configurator
      • DataMiner Automation
      • Scripts & Connectors Developer: HTTP Basics
      • Scripts & Connectors Developer: SNMP Basics
      • Visual Overview – Level 1
      • Verify a certificate
    • Video Library
    • Books We Like
    • >> Go to DataMiner Docs
  • Expert Center
    • Solutions & Use Cases
      • Solutions
      • Use Case Library
    • Markets & Industries
      • Media production
      • Government & defense
      • Content distribution
      • Service providers
      • Partners
      • OSS/BSS
    • DataMiner Insights
      • Security
      • System Architecture
      • DataMiner Releases & Updates
    • Agile
      • Agile Webspace
      • Everything Agile
        • The Agile Manifesto
        • Best Practices
        • Retro Recipes
      • Methodologies
        • The Scrum Framework
        • Kanban
        • Extreme Programming
      • Roles
        • The Product Owner
        • The Agile Coach
        • The Quality & UX Coach (QX)
    • DataMiner DevOps Professional Program
  • Downloads
  • More
    • Feature Suggestions
    • Climb the leaderboard!
    • Swag Shop
    • Contact
      • General Inquiries
      • DataMiner DevOps Support
      • Commercial Requests
    • Global Feedback Survey
  • PARTNERS
    • All Partners
    • Technology Partners
    • Strategic Partner Program
    • Deal Registration
  • >> Go to dataminer.services

Elastic Search CVE-2021-44228 log4j2 RCE Vulnerability

Solved1.88K views13th December 2021
5
Jason Boon [SLC] [DevOps Member]320 12th December 2021 1 Comment

Hi,

May I please confirm that adding the JVM option -Dlog4j2.formatMsgNoLookups=true to Elastic Search installations to address the recently reported log4j vulnerability is an acceptable immediate/short term solution?

Gellynck Jens [SLC] Answered question 13th December 2021
Bing Herng Chong [SLC] [DevOps Advocate] commented 13th December 2021

To add to the context of this question, we are aware that there are multiple users of DataMiner who have raised questions regarding this security vulnerability for both DataMiner 9.6 and 10.1 in their production deployments. More info regarding the vulnerability found here https://nvd.nist.gov/vuln/detail/CVE-2021-44228.

Some guidance of the applicability of this security vulnerability to DataMiner infrastructure (core software and any other third-party software e.g.: databases MSSQL, ES, Cassandra, etc) is requested.

3 Answers

  • Active
  • Voted
  • Newest
  • Oldest
2
Thomas Deweer [SLC]286 Posted 13th December 2021 0 Comments

Hello,

As mentioned on the official Elastic blog website, this indeed is a way to prevent the exploit.

Kind regards,

Jason Boon [SLC] [DevOps Member] Selected answer as best 13th December 2021
9
Gellynck Jens [SLC]2.71K Posted 13th December 2021 2 Comments

An official Skyline blog post has been published: responding to log4shell vulnerability

Gellynck Jens [SLC] Posted new comment 21st December 2021
Jörg Knesebeck [DevOps Enabler] commented 13th December 2021

Thanks!
Best Regards
Jörg

Gellynck Jens [SLC] commented 21st December 2021

Another way to mitigate the vulnerabilities is to update your elasticsearch version, more information can be found here (it’s also linked in the article above): https://community.dataminer.services/documentation/upgrading-elasticsearch-from-one-minor-version-to-another/

1
Jörg Knesebeck [DevOps Enabler]54 Posted 13th December 2021 1 Comment

Dear Skyline teams, I would like to confirm that customers are asking for any sensitivity of DataMiner regarding the log4j vulnerability. Personally I don't think there is any relation because DataMiner is all .NET, however, some statement/guidance is requested by customers. Thanks, Jörg

Bert Vandenberghe [SLC] [DevOps Enabler] Posted new comment 13th December 2021
Bert Vandenberghe [SLC] [DevOps Enabler] commented 13th December 2021

Hi Jörg, DataMiner is indeed not impacted as we don’t use Java. But we have to be careful with Cassandra and Elastic. We’re currently making an assessment and we will publish a blog post today on this topic with our recommendations for Elastic and/or Cassandra.

Please login to be able to comment or post an answer.

My DevOps rank

DevOps Members get more insights on their profile page.

My user earnings

0 Dojo credits

Spend your credits in our swag shop.

0 Reputation points

Boost your reputation, climb the leaderboard.

Promo banner DataMiner DevOps Professiona Program
DataMiner Integration Studio (DIS)
Empower Katas

Recent questions

Invoke HTTP Session from QAction 1 Answer | 1 Vote
Masked alarmes permission management 0 Answers | 0 Votes
Remove all Widgets from Section 2 Answers | 5 Votes

Question Tags

adl2099 (115) alarm (62) Alarm Console (82) alarms (100) alarm template (83) Automation (223) automation scipt (111) Automation script (167) backup (71) Cassandra (180) Connector (109) Correlation (69) Correlation rule (52) Cube (151) Dashboard (194) Dashboards (188) database (83) DataMiner Cube (57) DIS (81) DMS (71) DOM (140) driver (65) DVE (56) Elastic (83) Elasticsearch (115) elements (80) Failover (104) GQI (159) HTTP (76) IDP (74) LCA (152) low code app (166) low code apps (93) lowcodeapps (75) MySQL (53) protocol (203) QAction (83) security (88) SNMP (86) SRM (337) table (54) trending (87) upgrade (62) Visio (539) Visual Overview (345)
Privacy Policy • Terms & Conditions • Contact

© 2025 Skyline Communications. All rights reserved.

DOJO Q&A widget

Can't find what you need?

? Explore the Q&A DataMiner Docs

[ Placeholder content for popup link ] WordPress Download Manager - Best Download Management Plugin