Portfolio, Log4j, Apache vulnerabilities

Portfolio, Log4j, Apache vulnerabilities

Who does this affect?

This article applies to users running Portfolio 3.x and 4.x.

Issue

On December 10, 2021 researchers reported CVE-2021-44228, detailing an exploit in the Log4j library that allowed a malicious user to run code on an affected system. Portfolio uses an affected version of Log4j.

On March 10th, 2023 an issue with Log4j 1.x was denoted on systems running JRE earlier than ver. 1.7 in CVE-2023-26464

Is there a solution?

VulnerabilityCommentsRemediation
CVE-2021-44228

Affects Portfolio version 4.0 and earlier

Update to Portfolio 4.0.1. Installer can be found here:

https://www.extensis.com/support/portfolio-4/ 

CVE-2023-26464Portfolio 3.6.3 and 4.x do not use a JRE lower than 1.7 
CVE-2018-19409Only effects Linux servers (not support by Portfolio) 
CVE-2018-16509Requires local access to the system to be exploited. A secure network should mitigate this issue 
CVE-2016-7979 & CVE-2019-14813Requires local access to the system to be exploited. A secure network should mitigate this issue 
CVE-2022-23302Requires local access to the system to be exploited. A secure network should mitigate this issue 
CVE-2018-18284Only effects Linux servers (not support by Portfolio) 
CVE-2019-7321Portfolio does not use an affected version of MuPDF 
CVE-2018-1335Portfolio does not use tika-server 
CVE-2016-6809Portfolio does not support MATLAB files 
CVE-2022-42252Only applicable if Portfolio is behind a reverse proxy that also fails to reject the request with the invalid header. Reverse proxies are not part of our standard configuration when developing Portfolio 
CVE-2022-45143Portfolio does not use this feature of Tomcat 
CVE-2022-29885Portfolio does not use any of the clustering features outlined in the vulnerability. A secure network should further mitigate this issue 
CVE-2021-4104We do not use JMSAppender in any of our products 
CVE-2019-17571We do not use the Log4j network logging features and are not affected 
CVE-2020-9488We do not use the Log4j SMTPAppender and are not affected 
CVE-2022-23305We do not use the Log4j JDBCAppender and are not affected 
CVE-2022-23307 & CVE-2020-9493This is related to Apache Chainsaw, a gui log reader that an be included with log4j. We do not include this with our distribution and are not affected 
CVE-2022-23305We do not use the JDBCAppender 
CVE-2020-9488We do not use the SMTPAppender 
CVE-2023-44487Portfolio doesn't support HTTP/2 and is unaffected 
CVE-2024-23672
Portfolio doesn't use WebSocket connections and is unaffected 
CVE-2024-24549Portfolio doesn't support HTTP/2 and is unaffected 
CVE-2023-28708This vulnerability affects servers deployed behind a reverse proxy. This is an uncommon and unsupported configuration for Portfolio 
CVE-2023-45648This vulnerability affects servers deployed behind a reverse proxy. This is an uncommon and unsupported configuration for Portfolio 
CVE-2023-41080This vulnerability affects an authentication feature of Apache that we do not use in Portfolio. 
CVE-2022-34305This vulnerability affects an authentication feature of Apache that we do not use in Portfolio 
CVE-2023-46589This vulnerability affects servers deployed behind a reverse proxy. This is an uncommon and unsupported configuration for Portfolio 

 


    • Related Articles

    • Log Into the Portfolio Client

      Objective: Log in to the Portfolio Web Client 1: In the address bar of your browser, enter: http://yourportfolioserver:8090 or https://yourportfolioserver:9443 “yourportfolioserver” is the hostname or IP address matching your Portfolio instance ...
    • Portfolio and Spring4Shell Vulnerabilities

      On March 29th, 2022, CVE-2022-22963 and CVE-2022-22965 were reported detailing an exploit in the Spring Cloud, Spring MVC and Spring Webflux framework. Solution Portfolio does not utilize any of these frameworks and is not affected by these issues.
    • Portfolio Glossary

      Following are some terms used throughout Portfolio and its documentation. Some are technical (“computer”) terms that relate to Portfolio features and services, some are fundamental concepts within Portfolio, and some are terms that relate to Digital ...
    • Portfolio logs

      Portfolio logs its performance and error information to assist in support and troubleshooting. Some log files can grow very large, so you may wish to move them from their default location. To change where log files are saved, see Logs folder. ...
    • Activating Portfolio

      Affected Versions This article applies to Portfolio 3.6.0 and later versions. Solution Activating Portfolio with your Extensis account NOTE: Portfolio must connect to cwsg.extensis.com on port 443 to activate; for more information, go to Extensis ...