Investigation of Log4j Vulnerability status for Illumina off-instrument software products

02/03/2022


On December 10, 2021, Illumina was made aware of a vulnerability in the Apache Log4j software suite (CVE-2021-44228, CVE-2021-45046, and CVE-2021-44832). This software component is a Java-based logging utility and part of the Apache Logging Services Foundation products.

After Illumina became aware of the issue, we launched an investigation to identify potentially affected products and assess risk. The status for off-instrument software products is updated in the table below.

For more detailed updates on specific Illumina software products, Illumina recommends that our customers monitor the Technical Bulletins page. Illumina will continue to provide updates as necessary based on our investigation.

Illumina takes data privacy and security issues very seriously, and we hope this information helps alleviate any concerns about this vulnerability. If you have any questions, email Illumina Technical Support.


Terms:

  • Impacted: The product contains one or more identified affected components.
  • Not impacted: The product does not contain identified affected components.
  • Patched: For Illumina-hosted solutions, updates have been applied to all in-scope instances.
  • In progress: The product evaluation is underway.
PRODUCT IMPACT Mitigation Status Technical Bulletin
Illumina Connected Analytics SaaS (ICA) Impacted Patched https://support.illumina.com/bulletins/2021/121/investigation-of-log4j-vulnerability-with-illumina-connected-ana.html
TruSight Suite SaaS Not impacted Patched https://support.illumina.com/bulletins/2021/121/investigation-of-log4j-vulnerability-with-trusight-software-suit.html
BaseSpace Suite Impacted Patched https://support.illumina.com/bulletins/2021/121/investigation-of-log4jvulnerability-with-basespace-sequence-hub-.html
DRAGEN Suite Not impacted Not impacted https://support.illumina.com/bulletins/2021/121/investigation-of-log4j-vulnerability-with-the-illumina-dragen-bi.html
Emedgene Not impacted Not impacted   https://support.illumina.com/bulletins/2021/121/investigation-of-log4j-vulnerability-with-emedgene-.html
Clarity LIMS v.4.x, 5.0, 5.1 Not impacted Not impacted https://support.illumina.com/bulletins/2021/121/investigation-of-log4j-vulnerability-with-clarity-lims.html
Clarity LIMS Cloud v5.2, 5.3, 5.4 Impacted Patched   https://support.illumina.com/bulletins/2021/121/investigation-of-log4j-vulnerability-with-clarity-lims.html
Clarity NextSeq 1K2K v2.1.0 Impacted Patched https://support.illumina.com/bulletins/2021/121/investigation-of-log4j-vulnerability-with-clarity-lims.html
GenomeStudio In progress -  
BlueFuse Multi In progress -  
Proactive Portal Not impacted Not impacted https://support.illumina.com/bulletins/2021/121/investigation-of-log4j-vulnerability-with-illumina-proactive-por.html
VeriSeq NIPT V2 In progress -  
TruSight Cystic Fibrosis In progress -  
Illumina Experiment Manager (IEM) Not impacted Not impacted  
Sequence Analysis Viewer (SAV) Not impacted Not impacted