Splunk enterprise Logback 1.2.3 CVE-2021-42550


In Splunk enterprise when running the following log4j scanner it is picking up that the following files

as vulnerable. Can somebody please provide steps on how I can remediate this? Is it a case of upgrading

all splunk servers with the latest version from If not please advise steps and will it require me to reboot all related splunk servers please?


log4j/logback scanner


Files found as being vulnerable

C:\Program Files\Splunk\etc\apps\splunk_app_db_connect\jars\command.jar

Logback 1.2.3 CVE-2021-42550
C:\Program Files\Splunk\etc\apps\splunk_app_db_connect\jars\dbxquery.jar Logback 1.2.3 CVE-2021-42550
C:\Program Files\Splunk\etc\apps\splunk_app_db_connect\jars\server.jar Logback 1.2.3 CVE-2021-42550


many thanks

Labels (1)
0 Karma


Have you seen ?

If this reply helps you, an upvote would be appreciated.
0 Karma


thanks for your reply.

Unfortunately that does not cover logback CVE-2021-42550.


Logback is a fork of logj4 - whilst everybody is concentrating on log4j they are missing or simply ignoring logback. 


I just need to know the remediation steps, patched to upgrade logback 1.2.3 which is being used by Splunk Enterprise thank you

Tags (1)
0 Karma