> Source: [sk176865](https://support.checkpoint.com/results/sk/sk176865)

# sk176865 - Check Point Response to Apache Log4j Remote Code Execution

| Property | Value |
|----------|-------|
| Solution ID | sk176865 |
| Date Created | 2021-12-10 |
| Last Modified | 2025-02-09 |
| Technical Level | General |
| Products | Security Gateway, Security Management Server, Cloud Firewall, Mobile Security, Check Point Portal |
| Versions | R82.10, R82, R81.20, R81.10 (EOS), R82.10, R82, R81.20, R82.10, Cloud, Cloud, R81 (EOS), R81.10 (EOS), R81 (EOS), R81 (EOS), R81.10 (EOS), R81.20, R82 |

## Solution

On December 10, 2021, a proof of concept of a vulnerability in the Apache Log4j Java library [CVE-2021-44228](https://www.cve.org/CVERecord?id=CVE-2021-44228) was published.  
The vulnerability may allow unauthenticated threat actors to obtain remote code execution. The severity of the vulnerability was deemed critical.

<br />

The Check Point Infinity architecture is protected against this threat. We verified that this vulnerability does not affect our Infinity portfolio (including Quantum Gateways, SMART Management, Harmony Endpoint, Harmony Mobile, SMB, ThreatCloud and CloudGuard). We will continue to update you on any new development of this significant security event.

In addition - all of Check Point's products are covered against these vulnerabilities:

|-------------------------------------------------------------------|---------------------------------------------------------------------------------------|
| CVE                                                               | Explanation                                                                           |
| [CVE-2021-44228](https://www.cve.org/CVERecord?id=CVE-2021-44228) | Remote code execution is not possible due to Check Point's hardened Java environment. |
| [CVE-2021-45046](https://www.cve.org/CVERecord?id=CVE-2021-45046) | The vulnerable patterns are not used by Check Point.                                  |
| [CVE-2021-4104](https://www.cve.org/CVERecord?id=CVE-2021-4104)   | JSMAppender is not used by Check Point.                                               |
| [CVE-2021-45105](https://www.cve.org/CVERecord?id=CVE-2021-45105) | The vulnerable patterns are not used by Check Point.                                  |
| [CVE-2021-44832](https://www.cve.org/CVERecord?id=CVE-2021-44832) | The logging configuration file is accessible only to the authenticated Expert user.   |

### Check Point Products Status

|-----------------------------|--------------------|
| Product                     | Status             |
| Quantum Security Gateway    | **Not vulnerable** |
| Quantum Security Management | **Not vulnerable** |
| CloudGuard                  | **Not vulnerable** |
| Infinity Portal             | **Not vulnerable** |
| Harmony Endpoint            | **Not vulnerable** |
| Harmony Mobile              | **Not vulnerable** |
| Harmony Connect             | **Not vulnerable** |
| SMB                         | **Not vulnerable** |
| ThreatCloud                 | **Not vulnerable** |

**Notes:**

* All Check Point's software versions including out of support versions are not vulnerable.
* All Check Point appliances are not vulnerable.

Visit the Check Point blog for additional information: [Protecting against CVE-2021-44228 (Apache Log4j2 versions 2.14.1)](https://blog.checkpoint.com/2021/12/11/protecting-against-cve-2021-44228228-apache-log4j2-versions-2-14-1/)

### IPS Protection

Check Point released an **Apache Log4j Remote Code Execution ([CVE-2021-44228](https://www.cve.org/CVERecord?id=CVE-2021-44228))** IPS protection with this Threat Prevention coverage against the Apache Log4j vulnerability.  
For more information on how to verify if your setup already contains the fix and to update the IPS profile with the latest protection, see [sk176884.](https://support.checkpoint.com/results/sk/sk176884)  

**Check Point recommends activating HTTPS Inspection (in the Security Gateway properties -\> HTTPS Inspection view), as the attack payload may appear in encrypted or decrypted traffic.**

Additionally, Apache provides a Log4j patch to mitigate this vulnerability. Users may update their version accordingly. For Apache's remediation options, visit [CVE-2021-44228](https://www.cve.org/CVERecord?id=CVE-2021-44228).

<br />

**Related solutions**:

* [sk176951 - Detecting Log4j Vulnerability on Endpoint environment](https://support.checkpoint.com/results/sk/sk176951)
* [sk176983 - Endpoint protection and detection of the Log4j vulnerability](https://support.checkpoint.com/results/sk/sk176983)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
