Log4j / CVE-2021-44228 and ActiveNav Products

 

We understand that our customers will be concerned to understand any risk from our products relating to the recently announced Log4j vulnerabilities. As our products are not Java-based we do not and have never used log4j and there are no components within our products with dependencies on it. As a result, you can be confident that you are not exposed to CVE-2021-44228 or related vulnerabilities via ActiveNav software. In addition, we have reviewed all aspects of our build and test pipelines to identify any risk within our Software Supply Chain. All usage of log4j within these environments has been identified and patched. If you have any further questions regarding this vulnerability please submit a support request.