问题描述
Does the COMSOL software contain the Apache Log4j 2.x library and, if so, is it affected by security vulnerabilities found in it?
解决方法
Summary
The following COMSOL software uses the Apache Log4j 2.x library:
- COMSOL Multiphysics
- COMSOL Server
- COMSOL Model Manager Server (with managed search index servers)
COMSOL strives to keep third-party software up-to-date in update releases. It is not possible to update the Apache Log4j 2.x software manually. See below for more information about Apache Log4j 2.x security vulnerabilities.
Security vulnerabilities
The Apache Logging Services security team lists known vulnerabilities on the Apache Logging Services Security page.
Not all security vulnerabilities of the Apache Log4j 2.x library apply to the COMSOL software, since the COMSOL software does not expose all the Apache Log4j 2.x functionality. In fact, COMSOL software typically only uses a relatively limited subset of the the Apache Log4j 2.x functionality.
- CVE-2025-68161
Assessment: Not vulnerable
The COMSOL software does not enable the Socket Appender so the lack of TLS hostname verification in Apache Log4j 2.25.2 and below is not relevant.
Apache Log4j 2.x version
The following versions of the Apache Log4j 2.x library are included with the currently supported versions of COMSOL:
- COMSOL 6.4 update 1:
Apache Log4j 2.24.3 and 2.17.2 - COMSOL 6.3 update 2:
Apache Log4j 2.17.2
In general, the version of the Apache Log4j software included with a particular COMSOL software installation can be determined by inspecting the filenames of all .jar found by searching for log4j in the COMSOL installation directory. The following are the default installation directories:
- On Windows systems:
C:\Program Files\COMSOL\COMSOL64\[Product]\ - On macOS systems:
/Applications/COMSOL64/[Product]/t - On Linux systems:
/usr/local/comsol64/[product]/ - The
[Product]path segment isMultiphysicsfor COMSOL Multiphysics,Serverfor COMSOL Server, andModelManagerServerfor COMSOL Model Manager Server.
COMSOL 尽一切合理的努力验证您在此页面上查看的信息。本页面提供的资源和文档仅供参考,COMSOL 对其有效性不作任何明示或暗示的声明。COMSOL 对所披露数据的准确性不承担任何法律责任。本文档中引用的任何商标均为其各自所有者的财产。有关完整的商标详细信息,请参阅产品手册。
