Tech Info 196: Java log4j vulnerability – HELIOS is not affected

HELIOS Tech Info #196

Mon, 13 Dec 2021

Java log4j vulnerability – HELIOS is not affected


HELIOS server services (HELIOS G8 as well as the previous version HELIOS UB64) do not use any log4j and are therefore not affected by the log4j 2.x vulnerability.

Most HELIOS server services are written in the C programming language and are therefore not affected by Java library or runtime security problems.

Although WebShare Web Server is written in Java, log4j is not used by WebShare. With HELIOS G8 an external Java installation is not needed, so there is no risk of external Java installations introducing any security conflicts.

HELIOS recommends all customer to deploy the current HELIOS G8 release because previous versions are not supported anymore. In case of future emergency updates, these updates will only be delivered for HELIOS G8.