• log4j.jar security issue.

    By Eric Tomenga 2 years ago

    Trying to mitigate the security issue with included library log4j.jar in POI 4 Xpages.

    Ref: https://www.cisa.gov/uscert/apache-log4j-vulnerability-guidance

    I'd like to verify the version embedded and have the ability to upgrade it but I don't have to tools to de-compile the JAR. Our group is moving away from Domino Xpages unfortunately so I won't be given much time to try to upgrade the library and may be forced to just remove POI from the application. I know this is an old library but it was well done and very useful so if anyone is still using it we can use this thread for information for anyone that may have found a solution. Thank you to Christian, Lena and Jessie for their hard work in this excellent tool .