Bentley Communities
Bentley Communities
  • Site
  • User
  • Site
  • Search
  • User
ProjectWise
  • Product Communities
ProjectWise
ProjectWise Design Integration Forum Zero-Day Vulnerability Discovered in Java Spring Framework aka Spring4Shell (similar to Log4Shell?) Does this affect Projectwise in any capacity?
    • Sign In

    • State Verified Answer
    • +1 person also asked this people also asked this
    • Replies 8 replies
    • Answers 1 answer
    • Subscribers 62 subscribers
    • Views 918 views
    • Users 0 members are here
    • Java
    • ProjectWise
    • spring4shell
    • integration
    • java spring framework
    • ProjectWise Integration Server

    Zero-Day Vulnerability Discovered in Java Spring Framework aka Spring4Shell (similar to Log4Shell?) Does this affect Projectwise in any capacity?

    Devang Singh
    Offline Devang Singh over 1 year ago

    If yes then is there any counter measures we need to be aware of?

    • Sign in to reply
    • Cancel

    Top Replies

    • Sangameshwar Pendalwar
      Offline Sangameshwar Pendalwar Fri, Apr 8 2022 10:03 AM in reply to Devang Singh +1 verified
      At this time we are not aware of any issues with Bentley software or services involving the “ Zero-Day Vulnerability Discovered in Java Spring Framework aka Spring4Shell ” Should the Bentley security…
    Parents
    • Kevin van Haaren
      0 Offline Kevin van Haaren Mon, Apr 4 2022 9:00 AM

      ProjectWise Design Integration doesn't use Java. It does use a logging system based on Log4J that was part of the Log4Shell vulnerability but the 2 systems* they use were never vulnerable to Log4Shell.

      Spring4Shell is unrelated to Log4Shell and is in a 100% Java framework.

      https://arstechnica.com/information-technology/2022/04/explaining-spring4shell-the-internet-security-disaster-that-wasnt/

      I have no idea if Bentley uses that Spring framework internally or in their Cloud services, but there isn't anything we can do about that, they'll have to address that.

      * as far as I can tell Projectwise uses Log4cxx and Log4Net, I don't think Bentley has officially indicated that's what they use.

      https://logging.apache.org

       

      • Cancel
      • Vote Up 0 Vote Down
      • Sign in to reply
      • Verify Answer
      • Cancel
    Reply
    • Kevin van Haaren
      0 Offline Kevin van Haaren Mon, Apr 4 2022 9:00 AM

      ProjectWise Design Integration doesn't use Java. It does use a logging system based on Log4J that was part of the Log4Shell vulnerability but the 2 systems* they use were never vulnerable to Log4Shell.

      Spring4Shell is unrelated to Log4Shell and is in a 100% Java framework.

      https://arstechnica.com/information-technology/2022/04/explaining-spring4shell-the-internet-security-disaster-that-wasnt/

      I have no idea if Bentley uses that Spring framework internally or in their Cloud services, but there isn't anything we can do about that, they'll have to address that.

      * as far as I can tell Projectwise uses Log4cxx and Log4Net, I don't think Bentley has officially indicated that's what they use.

      https://logging.apache.org

       

      • Cancel
      • Vote Up 0 Vote Down
      • Sign in to reply
      • Verify Answer
      • Cancel
    Children
    • Devang Singh
      0 Offline Devang Singh Mon, Apr 4 2022 10:09 AM in reply to Kevin van Haaren

      I have raised a request with the Bentley team as well. they are looking into it if there is any connection. Thanks for the reply though.

      • Cancel
      • Vote Up 0 Vote Down
      • Sign in to reply
      • Verify Answer
      • Cancel
    • paul hoffmann
      0 Offline paul hoffmann Wed, Apr 6 2022 8:15 AM in reply to Kevin van Haaren

      I also raised a Service Request at Bentley!!

      • Cancel
      • Vote Up 0 Vote Down
      • Sign in to reply
      • Verify Answer
      • Cancel
    • Devang Singh
      0 Offline Devang Singh Wed, Apr 6 2022 9:32 AM in reply to paul hoffmann

      let me know if you get anything

      • Cancel
      • Vote Up 0 Vote Down
      • Sign in to reply
      • Verify Answer
      • Cancel

    Communities
    • Home
    • Getting Started
    • Community Central
    • Products
    • Support
    • Secure File Upload
    • Feedback
    Support and Services
    • Home
    • Product Support
    • Downloads
    • Subscription Services Portal
    Training and Learning
    • Home
    • About Bentley Institute
    • My Learning History
    • Reference Books
    Social Media
    •    LinkedIn
    •    Facebook
    •    Twitter
    •    YouTube
    •    RSS Feed
    •    Email

    © 2023 Bentley Systems, Incorporated  |  Contact Us  |  Privacy |  Terms of Use  |  Cookies