# Log4j

**URL:** <https://the.fmsoup.org/t/log4j/2643>\
**Category:** Questions\
**Tags:** security\
**Created:** [December 13, 2021, 10:19pm UTC](https://the.fmsoup.org/t/log4j/2643 "2021-12-13T22:19:33Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![bdbd](https://yyz2.discourse-cdn.com/flex030/user_avatar/the.fmsoup.org/bdbd/32/620_2.png) [@bdbd](https://the.fmsoup.org/u/bdbd)\
**Post date:** [December 13, 2021, 10:19pm UTC](https://the.fmsoup.org/t/log4j/2643/1 "2021-12-13T22:19:33Z")

</div>

Anyone know if Log4j is used by FileMaker in any capacity, whether in Pro, Go, Server or Cloud?

---

<div class="post-metadata">

**Author:** ![Malcolm](https://yyz2.discourse-cdn.com/flex030/user_avatar/the.fmsoup.org/malcolm/32/196_2.png) [@Malcolm](https://the.fmsoup.org/u/Malcolm)\
**Post date:** [December 13, 2021, 10:34pm UTC](https://the.fmsoup.org/t/log4j/2643/2 "2021-12-13T22:34:41Z")

</div>

Over at Reddit, people are saying that Claris has claimed there are no vulnerabilities.

360-works has chimed in to say that none of their code uses Log4j.

It seems as though the 360-works product called Plastic is affected and that updates are available.

> **[r/filemaker - Log4j and Filemaker Server](https://www.reddit.com/r/filemaker/comments/rfl3cr/log4j_and_filemaker_server/)**
>
> 7 votes and 3 comments so far on Reddit

MonkeyBread has a statement here: [MBS Blog - log4j](https://www.mbs-plugins.com/archive/2021-12-13/log4j/monkeybreadsoftware_blog_filemaker)

---

<div class="post-metadata">

**Author:** ![MonkeybreadSoftware](https://yyz2.discourse-cdn.com/flex030/user_avatar/the.fmsoup.org/monkeybreadsoftware/32/361_2.png) [@MonkeybreadSoftware](https://the.fmsoup.org/u/MonkeybreadSoftware)\
**Post date:** [December 14, 2021, 6:51am UTC](https://the.fmsoup.org/t/log4j/2643/3 "2021-12-14T06:51:40Z")

</div>

Claris posted an answer:  
[https://support.claris.com/s/answerview?language=en\_US&anum=000035819](https://support.claris.com/s/answerview?language=en_US&anum=000035819)

---

<div class="post-metadata">

**Author:** ![OliverBarrett](https://avatars.discourse-cdn.com/v4/letter/o/f19dbf/32.png) [@OliverBarrett](https://the.fmsoup.org/u/OliverBarrett)\
**Post date:** [December 14, 2021, 11:44am UTC](https://the.fmsoup.org/t/log4j/2643/4 "2021-12-14T11:44:53Z")

</div>

If you have any code written that uses log4j, Apache has already posted updated libraries (with corresponding new maven dependencies --\> log4j-2.15.0) that fix this problem. If you have the 1.x version of log4j, you're OK for _this_ current vulnerability, but that version has other problems.

Also, updating from 1.x -\> 2.x requires a **small code change** in how you instantiate the LOGGER.

**Log4j Version 1:**  
private static final Logger logger =  
Logger.getLogger(\<class\_name\>.class);

**log4j Version 2:**  
private static final Logger logger = LogManager.getLogger(\<class\_name\>.class.getName());

 ![image](https://canada1.discourse-cdn.com/flex030/uploads/fmsoup/original/2X/0/00ce87a5c90741993a07cbe55f0a15646bd33cd5.png)

---

<div class="post-metadata">

**Author:** ![Bobino](https://yyz2.discourse-cdn.com/flex030/user_avatar/the.fmsoup.org/bobino/32/194_2.png) [@Bobino](https://the.fmsoup.org/u/Bobino)\
**Post date:** [December 14, 2021, 2:34pm UTC](https://the.fmsoup.org/t/log4j/2643/5 "2021-12-14T14:34:10Z")

</div>

This blog post offers a good recap: [Fixing the Log4Shell (Log4j) exploit for FileMaker Server | by Anchor-Buoy Software | Dec, 2021 | Medium](https://medium.com/@anchorbuoy_sftw/log4shell-log4j-zero-day-exploit-and-filemaker-server-e20ebe806e8a)

---

<div class="post-metadata">

**Author:** ![Bobino](https://yyz2.discourse-cdn.com/flex030/user_avatar/the.fmsoup.org/bobino/32/194_2.png) [@Bobino](https://the.fmsoup.org/u/Bobino)\
**Post date:** [December 15, 2021, 1:32am UTC](https://the.fmsoup.org/t/log4j/2643/6 "2021-12-15T01:32:11Z")

</div>

New update from Claris over here: [ClarisPKB](https://support.claris.com/s/article/CVE-2021-44228-Apache-Log4j-Vulnerability-and-Claris-products?language=en_US)

---

<div class="post-metadata">

**Author:** ![Markus](https://avatars.discourse-cdn.com/v4/letter/m/b782af/32.png) [@Markus](https://the.fmsoup.org/u/Markus)\
**Post date:** [December 15, 2021, 4:55pm UTC](https://the.fmsoup.org/t/log4j/2643/7 "2021-12-15T16:55:13Z")

</div>

the statement by Claris could be a bit more clear

- in aspect to log4j, FMS 18 is not affected, so for that reason no update to a 'current' version is needed (although, running a current version is always the preferred way)
- running an older version as 18 (imho 16, 17) does not have the affected version of log4j, but that is no guarantee that it would be safe
- there might be add-ons that installed log4j, so for example pdfBox for ubuntu seems to have that

---

<div class="post-metadata">

**Author:** ![OliverBarrett](https://avatars.discourse-cdn.com/v4/letter/o/f19dbf/32.png) [@OliverBarrett](https://the.fmsoup.org/u/OliverBarrett)\
**Post date:** [December 15, 2021, 6:12pm UTC](https://the.fmsoup.org/t/log4j/2643/8 "2021-12-15T18:12:11Z")

</div>

Make sure it's log4j **2** as log4j version 1 is not affected by this particular problem.

---

<div class="post-metadata">

**Author:** ![Markus](https://avatars.discourse-cdn.com/v4/letter/m/b782af/32.png) [@Markus](https://the.fmsoup.org/u/Markus)\
**Post date:** [December 16, 2021, 8:54am UTC](https://the.fmsoup.org/t/log4j/2643/9 "2021-12-16T08:54:53Z")

</div>

Claris posted a new, detailled documentation

[https://support.claris.com/s/answerview?language=en\_US&anum=000035819](https://support.claris.com/s/answerview?language=en_US&anum=000035819)

Thank You so much, Claris!

---

<div class="post-metadata">

**Author:** ![Bobino](https://yyz2.discourse-cdn.com/flex030/user_avatar/the.fmsoup.org/bobino/32/194_2.png) [@Bobino](https://the.fmsoup.org/u/Bobino)\
**Post date:** [December 16, 2021, 3:08pm UTC](https://the.fmsoup.org/t/log4j/2643/10 "2021-12-16T15:08:51Z")

</div>

Just for Clarification, they updated their original post. I'm glad they did so, otherwise people need a bunch of different links to get the full picture. They centralized everything in that one post, and it is a good thing.
