LOG4J security issue for ATS like service
Hello
We received the attached notice from Refinitiv : Log4j Vulnerability Update as of 15_30 GMT on 30th December 2021.pdf , and we would like to get some lights about the point related to Refinitiv Real-Time Advanced Transformation Server (ATS).
Basically, we had installed an ATS like service on our TREP infra (Real-Time Distribution System) and, from what I understood when we configured it with one of your collegue, it is not a real Advanced Transformation Server.
So my question is : is our current config impacted by the Log4j vulnerability ? If yes : how to fix it ?
Thanks,
Henri
Best Answer
-
The PUB service doesn't have the Vendor element entry so it is possible that it is not a service from ATS.
However, to confirm it, you need to contact your market data team to verify the source of this service.
0
Answers
-
Hi @Henri.GARDON,
Can you please elaborate what you mean by "ATS like service". Log4J is a product specifically used in the ATS. If your RTDS service was configured using ADS etc, and not ATS specifically, then your infrastructure is not impacted by this vulnerability.
0 -
Basically, when we connect to our TREP infra, we have two services (via adhmon/adsmon):
IDN_RDF to retrieve real market data.
PUB : ATS like service where we can publish our our data in some way with a command line like : ./rmdstestclient -S PUB -f post.txt -ir 1 -I 1 with post.txt containing RICs.
I guess that we are not impacted, right ?0 -
There can be a number of ways in which a publishing service can be setup in infrastructure. To be completely sure, please talk to your market data administrator and verify that you don't have ATS setup - to be sure.
0 -
Hello @Henri.GARDON
According to the given PDF document, the product is the Refinitiv Real-Time Advanced Transformation Server (ATS), but your product in the capture screen is the Refinitiv Real-Time Advanced Distribution Hub (ADH) which is a totally different product.
I highly recommend you contact the ADH support team directly to verify if it is impacted by the Log4j vulnerabilities. You can contact the team via https://my.refinitiv.com/content/mytr/en/productsupport.html website.
Update:
If the PUB server is ATS, you can contact the ATS support team to verify if it is impacted by the Log4j vulnerabilities.
0 -
You may run rmdstestclient to check the source directory message of the PUB service.
The command looks like this:
rmdsTestClient.exe -h <hostname> -p 14002 -S PUB -ct rssl -f rics.txt -X -d 3 -l stdout
If the Vendor element entry of the PUB service is DTS or ATS, the source of the PUB service could be an ATS server.
1 -
Hi, thank you a lot for the info !
@Jirapongse with the command that you provide I have the answer attached rmdstestclient.txt and the following keywords :<refreshMsg domainType="RSSL_DMT_SOURCE" streamId="2" containerType="RSSL_DT_MAP" flags="0x168 (RSSL_RFMF_HAS_MSG_KE Y|RSSL_RFMF_SOLICITED|RSSL_RFMF_REFRESH_COMPLETE|RSSL_RFMF_CLEAR_CACHE)" groupId="0" dataState="RSSL_DATA_OK" stream State="RSSL_STREAM_OPEN" code="RSSL_SC_NONE" text="" dataSize="539">
Then :
<elementEntry name="Name" dataType="RSSL_DT_ASCII_STRING" data="PUB"/>
And finally :
<elementEntry name="Vendor" dataType="RSSL_DT_ASCII_STRING" data="Thomson Reuters"/>
So I guess this is not a real ATS ? Do you confirm ?
Thanks,
0 -
Confirmed with our Refinitiv contact that we are not impacted,
Thank you for the help !
0
Categories
- All Categories
- 6 AHS
- 37 Alpha
- 161 App Studio
- 4 Block Chain
- 4 Bot Platform
- 16 Connected Risk APIs
- 47 Data Fusion
- 30 Data Model Discovery
- 608 Datastream
- 1.3K DSS
- 577 Eikon COM
- 4.9K Eikon Data APIs
- 7 Electronic Trading
- Generic FIX
- 7 Local Bank Node API
- Trading API
- 2.7K Elektron
- 1.3K EMA
- 236 ETA
- 519 WebSocket API
- 33 FX Venues
- 10 FX Market Data
- 1 FX Post Trade
- 1 FX Trading - Matching
- 12 FX Trading – RFQ Maker
- 5 Intelligent Tagging
- 2 Legal One
- 20 Messenger Bot
- 2 Messenger Side by Side
- 9 ONESOURCE
- 7 Indirect Tax
- 59 Open Calais
- 264 Open PermID
- 39 Entity Search
- 2 Org ID
- PAM
- PAM - Logging
- 8.4K Private Comments
- 6 Product Insight
- Project Tracking
- ProView
- ProView Internal
- 20 RDMS
- 1.4K Refinitiv Data Platform
- 367 Refinitiv Data Platform Libraries
- 3 Refinitiv Due Diligence
- LSEG Due Diligence Portal API
- 3 Refinitiv Due Dilligence Centre
- Rose's Space
- 1.1K Screening
- 18 Qual-ID API
- 13 Screening Deployed
- 23 Screening Online
- 10 World-Check Customer Risk Screener
- 990 World-Check One
- 44 World-Check One Zero Footprint
- 45 Side by Side Integration API
- Test Space
- 3 Thomson One Smart
- 1.2K TR Internal
- Global Hackathon 2015
- 2 Specialists Who Code
- 10 TR Knowledge Graph
- 150 Transactions
- 142 REDI API
- 1.7K TREP APIs
- 4 CAT
- 21 DACS Station
- 117 Open DACS
- 1.1K RFA
- 103 UPA
- 172 TREP Infrastructure
- 224 TRKD
- 886 TRTH
- 5 Velocity Analytics
- 5 Wealth Management Web Services
- 59 Workspace SDK
- 9 Element Framework
- 5 Grid
- 13 World-Check Data File
- Yield Book Analytics
- 46 中文论坛