ReportServer and CVE-2021-44228 (Log4j) Information

Hi,

as many of you probably heard, log4j 2 (2.0 until 2.14.1) has this critical security issue: CVE-2021-44228.

ReportServer is not affected by this on its default configuration. Why?

If your Tomcat is configured to use Log4j, you can run the mitigation steps described in the link or, better, upgrade to to log4j >= 2.17.0.


Edit 30.08.2022:

As of ReportServer 4.3.0 we added the log4j-core-2.18.0.jar and log4j-api-2.18.0.jar jars because of a Mondrian dependency.
Details can be found here: https://reportserver.net/releasenotes/RS4.3.0.html

These libraries are not affected, as log4j is only affected until 2.14.1.

Regarding Crystal, you can use the log4j adapter (log4j-1.2-api) as described here: https://reportserver.net/en/guides/admin/chapters/SAP-Crystal-Reports/


Best regards,
Your ReportServer Team