{"id":3411,"date":"2021-12-14T10:22:29","date_gmt":"2021-12-14T09:22:29","guid":{"rendered":"https:\/\/fiskaltrust.eu\/news\/sicherheitsproblem-mit-log4j-bei-cloud-tse\/"},"modified":"2025-05-05T00:47:13","modified_gmt":"2025-05-04T23:47:13","slug":"sicherheitsproblem-mit-log4j-bei-cloud-tse","status":"publish","type":"news","link":"https:\/\/fiskaltrust.eu\/news\/sicherheitsproblem-mit-log4j-bei-cloud-tse\/","title":{"rendered":"Sicherheitsproblem mit log4j bei Cloud-TSE"},"content":{"rendered":"\n<p>Wahrscheinlich haben Sie von den anhaltenden Sicherheitsproblemen mit log4j, dem Java-Logging-Framework, geh\u00f6rt.&nbsp;<\/p>\n\n\n\n<p>fiskaltrust&nbsp;verwendet&nbsp;diese Bibliothek in&nbsp;keinem ihrer eigenen&nbsp;Produkte&nbsp;und&nbsp;somit&nbsp;sind&nbsp;nach unserem&nbsp;derzeitigen&nbsp;Kenntnisstand&nbsp;keine&nbsp;angebotenen Dienste der&nbsp;fiskaltrust betroffen.&nbsp;&nbsp;<\/p>\n\n\n\n<p>fiskaltrust&nbsp;liegen&nbsp;bereits&nbsp;Informationen&nbsp;diverser Anbieter vor, die&nbsp;von&nbsp;dieser&nbsp;Sicherheitsl\u00fccke betroffen&nbsp;sind.&nbsp;Alle Anbieter arbeiten mit&nbsp;Hochdruck an&nbsp;einer L\u00f6sung.&nbsp;&nbsp;<\/p>\n\n\n\n<!--more-->\n\n\n\n<p>SwissbitCloud&nbsp;und&nbsp;&nbsp;DeutscheFiskal&nbsp;Benutzer&nbsp;mit&nbsp;entsprechenden&nbsp;SCUs haben,&nbsp;wie von DF\/SB&nbsp;vorgeschlagen,&nbsp;zwei M\u00f6glichkeiten,&nbsp;die&nbsp;Sicherheitsl\u00fccke zu&nbsp;schlie\u00dfen.&nbsp;<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>Manuelles Setzen der Umgebungsvariablen&nbsp;auf dem Client, der die FCC ausf\u00fchrt, wie folgt:&nbsp;<kbd>LOG4J_FORMAT_MSG_NO_LOOKUPS=true<\/kbd><\/li><li>Sollte dies&nbsp;nicht m\u00f6glich&nbsp;sein,&nbsp;wird&nbsp;Benutzern empfohlen zu&nbsp;warten, bis die neue FCC-Version freigegeben wird. Sobald dies geschieht,&nbsp;wird eine neue SCU-Version ver\u00f6ffentlicht&nbsp;und&nbsp;die FCC automatisch aktualisiert.&nbsp;Benutzer k\u00f6nnen die&nbsp;Sicherheitsl\u00fccke&nbsp;beheben, indem&nbsp;sie die SCU&nbsp;ohne&nbsp;zus\u00e4tzlich notwendige&nbsp;Schritte aktualisieren.&nbsp;<\/li><\/ol>\n\n\n\n<p>Wir stehen im st\u00e4ndigen Austausch mit den Anbietern und&nbsp;informieren sie&nbsp;bez\u00fcglich&nbsp;zu den weiteren&nbsp;Entwicklungen&nbsp;auf unserem Blog.&nbsp;<\/p>\n\n\n\n<p>Bei weiteren Fragen wenden Sie sich bitte an&nbsp;<a href=\"mailto:sales@fiskaltrust.de\">sales@fiskaltrust.de<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">English version below:<\/h2>\n\n\n\n<p>Probably&nbsp;you&nbsp;have&nbsp;heard of the\u202fongoing security&nbsp;gap&nbsp;with log4j, the java logging framework.&nbsp;&nbsp;<\/p>\n\n\n\n<p>fiskaltrust&nbsp;does not use this library in any of its own products and therefore currently no services offered by&nbsp;fiskaltrust&nbsp;are affected.&nbsp;<\/p>\n\n\n\n<p>Furthermore&nbsp;fiskaltrust&nbsp;already has&nbsp;been&nbsp;informed&nbsp;and is actively requesting information&nbsp;from various providers who&nbsp;might be&nbsp;affected by this security gap. All providers are working out on a&nbsp;permanent fix.&nbsp;<\/p>\n\n\n\n<p>SwissbitCloud&nbsp;and&nbsp;DeutscheFiskal&nbsp;users with appropriate SCUs have two options for closing the security gap, as suggested by DF \/ SB:&nbsp;<\/p>\n\n\n\n<p>Users of the affected SCUs have two options, as suggested by DF\/SB:&nbsp;<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>Set&nbsp;the environment variable\u202f<kbd>LOG4J_FORMAT_MSG_NO_LOOKUPS=true<\/kbd>\u202fmanually&nbsp;on the PC&nbsp;on which&nbsp;the FCC is running&nbsp;<\/li><\/ol>\n\n\n\n<ol class=\"wp-block-list\" start=\"2\"><li>In case&nbsp;this is not possible, users should wait until the new FCC version is released. As soon as this happens&nbsp;a new SCU version that automatically updates the FCC&nbsp;will be released. After that users can&nbsp;fix the security issue by updating their SCU without any further steps.&nbsp;<\/li><\/ol>\n\n\n\n<p>In case of any additional questions please reach out to&nbsp;<a href=\"mailto:sales@fiskaltrust.de\" target=\"_blank\" rel=\"noreferrer noopener\">sales@fiskaltrust.de<\/a>.\u202f&nbsp;<\/p>\n","protected":false},"author":1,"featured_media":3412,"parent":0,"menu_order":0,"template":"","meta":{"_acf_changed":false,"_seopress_robots_primary_cat":"","_seopress_titles_title":"Sicherheitsproblem log4j bei Cloud-TSE - fiskaltrust","_seopress_titles_desc":"Sicherheitsproblem mit log4j bei Cloud-TSE: fiskaltrust informiert H\u00e4ndler und Entwickler. Aktuelle Sicherheitsupdates f\u00fcr Kassensysteme.","_seopress_robots_index":"","footnotes":""},"news-market":[82],"news-targetgroup":[],"news-topic":[],"class_list":["post-3411","news","type-news","status-publish","has-post-thumbnail","hentry","news-market-de"],"acf":[],"wpml_current_locale":null,"wpml_translations":[],"wpml_trid":null,"_links":{"self":[{"href":"https:\/\/fiskaltrust.eu\/en-eu\/wp-json\/wp\/v2\/news\/3411","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fiskaltrust.eu\/en-eu\/wp-json\/wp\/v2\/news"}],"about":[{"href":"https:\/\/fiskaltrust.eu\/en-eu\/wp-json\/wp\/v2\/types\/news"}],"author":[{"embeddable":true,"href":"https:\/\/fiskaltrust.eu\/en-eu\/wp-json\/wp\/v2\/users\/1"}],"version-history":[{"count":0,"href":"https:\/\/fiskaltrust.eu\/en-eu\/wp-json\/wp\/v2\/news\/3411\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/fiskaltrust.eu\/en-eu\/wp-json\/wp\/v2\/media\/3412"}],"wp:attachment":[{"href":"https:\/\/fiskaltrust.eu\/en-eu\/wp-json\/wp\/v2\/media?parent=3411"}],"wp:term":[{"taxonomy":"news-market","embeddable":true,"href":"https:\/\/fiskaltrust.eu\/en-eu\/wp-json\/wp\/v2\/news-market?post=3411"},{"taxonomy":"news-targetgroup","embeddable":true,"href":"https:\/\/fiskaltrust.eu\/en-eu\/wp-json\/wp\/v2\/news-targetgroup?post=3411"},{"taxonomy":"news-topic","embeddable":true,"href":"https:\/\/fiskaltrust.eu\/en-eu\/wp-json\/wp\/v2\/news-topic?post=3411"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}