Issue
A vulnerability was discovered in Apache Log4j2. Does this vulnerability affect Unified Workspace? If so, how do we go about mitigation of the vulnerability?
Solution
Unified Workspace does use Log4J 1.2.16.
We have confirmed that Log4J 1.x does NOT offer a JNDI lookup mechanism at the message level, and therefore is NOT susceptible to this vulnerability.
Our developers, however, are currently working on upgrading Log4J to the most current release, in the next release of Unified Workspace.