DaVinci Developer Adaptive
Important Security Information

log4j Security Vulnerablities

The Apache Log4j Library contain a set of security vulnerabilityies

CVE-2021-45105, CVE-2021-45046, CVE-2021-44228.

Applicability to DaVinci Developer Adaptive

Vector Embedded Products

Vector embedded software products for ECUs (e.g., MICROSAR) do not employ the Apache Log4j Library. Concerning the security of the embedded software, any exploit of this vulnerability is therefore equivalent to any other vulnerability at infrastructure level.

Vector Embedded Products related Tool Products & Tools

Vector provides Java-based development tools and helper tools used for the configuration/analysis of the embedded software. DaVinci Developer Adaptive uses Apache Log4j. Affected Product Versions are shown below. All newer Product Versions (as the latest stated Product Version) will not contain any version of Log4j mentioned above.

Please check the Apache Website for the latest information on workarounds and/or mitigations:

https://logging.apache.org/log4j/2.x/security.html.

Risk analysis

We assume that there is no significant increase of risk resulting from the usage of this tool since no external interface is provided by the tool.

Recommended Actions

Only the DaVinci Developer Adaptive Versions below are affected by this vulnerability. This issue will be fixed in future Service Packs, Updates or is already fixed via hotfix (Fix Version). Please update to one of the Fix Versions mentioned in the description below when its available. You can download the Fix Version in our Vector Portal, as mentioned in our delivery document.

Please also replace all copies and installations of the affected Version on your side.

Please check this page or Vector Portal for updates on availability for a Fix Version.

Product Version Specific Information

Release roadmap for the mentioned Versions can be found here:

https://portal.vector.com/de/web/davinci/release-roadmap/davinci-developer-adaptive.



v2.6 and Service Packs as mentioned here (affected)

for CVE-2021-45046 and CVE-2021-44228

  • v2.6 & Service Pack SP1: Hotfix v2.6 SP1 HF1 fixes the security vulnerability
  • We recommend updating to v2.6 HF2 or later Service Packs, as this also fixes the following CVE

for CVE-2021-45105

  • v2.6 & Service Pack SP1 & SP1 HF1: Hotfix v2.6 SP1 HF2 fixes the security vulnerability
  • We recommend updating to this or later Service Packs


v2.5 and Service Packs as mentioned here (affected)

for CVE-2021-45105, CVE-2021-45046, CVE-2021-44228

  • v2.5 & Service Pack SP1: Version v2.6 SP1 HF2 is compatible in regard of the AUTOSAR Schema and fixes the security vulnerability
  • We recommend updating to this or later Service Packs


v2.4 and Service Packs as mentioned here (affected)

for CVE-2021-45046 and CVE-2021-44228

  • v2.4 & Service Pack SP1 - SP3: Version v2.4 SP3 HF1 fixes the security vulnerability
  • We recommend updating to v2.4 SP4 or later Service Packs, as this also fixes the following CVE

for CVE-2021-45105

  • v2.4 & Service Pack SP1 - SP3 HF1: Version v2.4 SP4 fixes the security vulnerability
  • We recommend updating to this or later Service Packs


v2.3 – v1.2 and their Service Packs (affected)

for CVE-2021-45105, CVE-2021-45046, CVE-2021-44228

  • We recommend updating to one of the mentioned Fix Versions above
  • In case you essentially need one of these versions please contact our Support (support@vector.com) with your CBD number and required Version


v1.1 (affected)

for CVE-2021-45105, CVE-2021-45046, CVE-2021-44228

  • v1.1 & Service Pack SP1 - SP3 HF3: Version v1.1 SP3 HF2 fixes the security vulnerability
  • We recommend updating to this or later Service Packs


All Versions < v1.1 and their Service Packs (affected)

for CVE-2021-45105, CVE-2021-45046, CVE-2021-44228

  • We recommend updating to one of the mentioned Fix Versions above
  • In case you essentially need one of these versions please contact our Support (support@vector.com) with your CBD number and required Version