Sophos for Server - Message relay 1.4.0.30 - Affected by Log4j vulnerability?

Hi,

The message relay feature (v.1.1.0.30) in Sophos for servers uses the Apache server v2.4.46. Does anyone knows if this features is affected by the Log4j vulnerability?

According with the article KB-000038269 (support.sophos.com/.../KB-000038269 from Oct 2021 this version was not affected by the vulnerabilites found at that date, but the log4j was discoverd in Dec 2021. Was this article updated?

Thank you for the help.

Rafael

Top Replies

  • in reply to Qoosh +2 verified

    The current disclosure article available here lists "Intercept X for Server" which includes the MR/UC feature. The vulnerability will not affect the Message Relay and Update Cache.

    Sophos Endpoint protection (Windows/Mac/Linux)

    Not vulnerable

    Sophos Endpoint protection (Intercept X Endpoint, Intercept X for Server) does not use Log4j.

    Jump to answer
Parents Reply Children
No Data