One component in the Weaver stack was determined to be vulnerable to this attack vector. 

A mitigation was released on December 10th, which was rolled out to cloud and on-premise installations maintained by Weaver immediately. 

In order to verify this has been patched on a specific environment, please check that the Reaver (weaver-database-) version is at least 5.5.1, and the Changelog contains the line "Fix log4j vulnerability (CVE-2021-44228)".


To check the version of Reaver, press the release notes located at the top of the taskbar:



Navigate to the Reaver tab: