Do we have impact of "CVE-2021-44228 — Apache Log4j Vulnerability" on Microsoft SQL Server Express 2019?

P, Manjunatha 1 Reputation point
2021-12-14T14:35:49.49+00:00

Hi All,

I am using Microsoft Sql Server 2019 express edition which has a reference to log4j-1.2.17.jar in my .Net web app.

will this be having any impact? Does Microsoft release any security patch updates or sql server updates to mitigate this vulnerability ?

157399-image.png

Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,732 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Leon Laude 85,666 Reputation points
    2021-12-14T14:44:30.447+00:00

    Hi @P, Manjunatha ,

    The versions affected are from 2.0-beta9 to 2.14.1, lower versions such as the one you've posted in the screenshot are not vulnerable to the Log4J "Log4Shell" Zero-Day Vulnerability but is still recommended to be updated to the latest version.

    SQL Server in itself is not vulnerable, unless you have extensions that make use of the Log4j.

    For more information see:

    ----------

    If the reply was helpful please don't forget to upvote and/or accept as answer, thank you!

    Best regards,
    Leon