Publication Date: 2021-12-20
Last Update: 2021-12-20
Current Version: V1.0
CVSS v3.1 Base Score: 10.0

Affected Product and Versions Remediation
TraceAlertServerPLUS:
All versions
Currently no remediation is available

Open TraceAlertServerPLUS.exe with Zip tool to remove file JndiLookup.class in directory org/apache/logging/log4j/core/lookup/.

This measure mitigates both CVE-2021-44228 and CVE-2021-45046.
See further recommendations from section Workarounds and Mitigations

CVSS v3.1 Base Score 10.0
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:H/RL:O/RC:C
CWE: CWE-20: Improper Input Validation

CVSS v3.1 Base Score 9.0
CVSS Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE: CWE-20: Improper Input Validation

https://www.siemens.com/cert/advisories