CMS-XML SBM: SECURITY BULLETIN - CVE-2021-44228 and CVE-2021-45046 - RCE 0-day exploit found in Log4J
that following versions of SBM (11.4.2 and 12.0) can be manually updated to log4j 2.17 using the following steps. Versions likely can be updated with some customer reports of success on 11.8 and 11.7.1, but have not been officially tested yet. If you find this does not work for your system, then return the original JAR files to their location and back out the changes.
CMS-XML SBM - RCE 0-day exploit found in log4j - Security issue CVE 2021-44228
CVE 2021-44228: A serious security issue affecting SBM, RCE 0-day exploit, has been found for log4j 2.0 – 2.14.1. For further information on the vulnerability, you can follow the Apache Log 4 j site .
CMS-XML Problems with SSO Log File Growth After Upgrade to SBM 11.1
To work around this problem, edit the following 2 files: On the Application Engine server, edit [INSTALLDIR]\Application Engine\alfssojavabridge\alfssogatekeeper\conf\ log 4 j .properties On the SSO server, edit [INSTALLDIR]\\Common\Tomcat 7.0\server\default\webapps\idp\WEB-INF\conf\
CMS-XML How to set the notification log (ns.log) file size and number of archived files in SBM 10.1 and newer
By default when the ns.log file reaches the size of 5024KB, a new one will be created and the current one is saved as ns.log.1. The settings for this can be found in the log 4 j configuration file: JBoss:
CMS-XML How to turn on additional JBoss logging in server.log (SBM 10.1.4,, 10.1.5,
Locate the following folder in the SBM install: C:\Program Files\Serena\SBM\Common\jboss405\lib Rename the file log 4 j -1.2.16.jar to be log4j-boot.jar
CMS-XML Increase logging for Serena SBM Single Sign-On
### Higgins/Serena SSO ### -------------------------------------------------------------------- log 4 j
CMS-XML How to change JBoss server.log maximum log size and rotation
The JBoss server.log size and rotation can be customised in the file <JBoss_HOME>\server\default\conf\jboss- log 4 j .xml (e.g. for a default SBM install it would be C:\Program Files\Serena\ SBM \Common\jboss405\server\default\conf\jboss- log 4 j .xml)
CMS-XML Limit size of sla.log and archive last few logs
2. Edit this file: Program Files\Serena\ SBM \Common\jboss405\server\default\deploy\sla.war\WEB-INF\classes\ log 4 j .xml 3. Change this section:
CMS-XML Rest Grid Widget - get more logging from the SBMProxy
Go to C:\Program Files\Serena\ SBM \Common\Tomcat 7.0\server\default\conf\ log 4 j .xml and search for sbmproxy.
CMS-XML How to change location, size or number of iterations of log files for Tomcat
(2) In addition a number of the tomcat logs are configured here "..\ SBM \Common\Tomcat 7.0\server\default\conf\ log 4 j .xml" e.g. server.log, commonSbmApi.log
