Patch Name:
-----------
Log4jVulnerability


Issue Description:
------------------
1. Patch to fix Apache log4j vulnerability

List of previous patches Included:
----------------------------------
No previous patches


Applicable Version(s):
----------------------
Greater than 10.4


Applicable System(s):
---------------------
All servers (Both Primary and Secondary in case of HA), eStudio

Server Restart Required?
------------------------
Yes


EStudio Restart Required?
------------------------
Yes

Note : EStudio needs to be closed if and only if its running on the same machine on which the patch is being applied.


Can be applied without down time in HA mode***:
----------------------------------------
Yes

***
If "Can be applied without down time in HA mode" is "Yes" for a given patch, it is possible to apply the patch with little or zero downtime (even if "Server Restart Required" is "Yes"), by following the steps below:

o Stop the Passive Server of the HA pair. Apply the patch.
o Once the remote server is in stand alone state, start the Passive server.
o Once the remote server changes to Active state, stop the active server and let the passive server move to stand alone state.
o Apply the patch in the server that is stopped and restart the server.


To install this patch, follow these instructions:
-------------------------------------------------

1. Go to FIORANO_HOME/extlib/log4j and remove the log4j-core-2.7.jar. (Do not rename. If you want to take a backup of this jar then cut and paste it outside FIORANO_HOME)

2. After this, extract the zip file named 'Log4jVulnerability.zip'.

3. Copy the directory: 'Log4jVulnerability' to: '$FIORANO_HOME/patch'.

4. Open console, navigate to the directory'$FIORANO_HOME/patch' and type the following command:
   ant patch

5. When prompted for the patch number, enter the number corresponding to the patch(which is'Log4jVulnerability').
   The patch will be applied and necessary files to uninstall the patch will be created.


To uninstall the patch:
-----------------------
1. Open the console in $FIORANO_HOME/patch directory and type the following command:
   ant unpatch

2. When prompted for the patch number, enter the number corresponding to the patch(which is 'Log4jVulnerability').

The patch will be uninstalled.     


Issued On:
----------
13/12/2021


Depends On:
----------
-NA-


Support Portal Reference :
--------------------------


Customer Reference:
------------------



BugZilla Reference:
-------------------



SVN Details:
------------



===============================================================================
Please email to techsupport@fiorano.com for resolution of common queries.
All rights reserved. © 1999-2021, Fiorano Software Inc.
