The GoldSim product itself is not vulnerable to log4j as this module is not shipped or used by GoldSim software. The license server used to serve GoldSim Network licenses "FlexNet Publisher License Server" (FNPLS) is also not vulnerable to the log4j vulnerability because FNP does not use any JNDI data source. We have heard some reports from license server administrators that a possible vulnerability was flagged by their server scanners. The affected files triggering this warning are only used as examples that ship with the lmadmin installer but are not actually used.
If you are hosting a GoldSim Network license using Flexera's FlexNet Publisher (FNP) License Server and want to avoid seeing possible security warnings related to the log4j example files installed with lmadmin, follow the steps described below. FNP License Server (v126.96.36.199 or older), a third-party product required only when hosting GoldSim Network licenses, includes components affected by the vulnerability.
- If you haven't done so already, download the latest version of the FlexNet Publisher License Server (lmadmin 188.8.131.52).
- If you already have the latest version installed, skip to step 5.
- Uninstall the Network License Server.
- Install and Configure a Network License.
- Delete the following 3 files from this location: C:\Program Files (x86)\FlexNet Publisher License Server Manager\examples\alerter\lib
- Download the apache-log4j-2.18.0 zip file from Apache Downloads
- Unzip and move the following files to the same folder specified in step 4:
Because the files shown above are only used as examples, these steps will not affect any operations of the License Server used to serve GoldSim licenses. If you experience any issues or have further questions about the steps above, please let us know by commenting below this article.