Announcement

Collapse
No announcement yet.

Partner 728x90

Collapse

Interactive Brokers Log4j security risk

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    Interactive Brokers Log4j security risk

    There is much talk today about a very serious security risk with Apache Log4j.

    From ZDNet:

    "Basically any device that's exposed to the internet is at risk if it's running Apache Log4J, versions 2.0 to 2.14.1"


    The following file is part of the Interactive Brokers TWS/IB Gateway software that is recommended for use with NT8:

    log4j-api-2.12.0.jar


    1) Can anyone on the forum provide a practical/unofficial assessment of the current security risk involved in running TWS/IB Gateway software with NT8?

    2) Should we expect NinjaTrader to test/recommend a new version of IB's TWS/IB Gateway software in the very near future?

    Thanks

    #2
    Hello Zigfried,

    Thanks for your post.

    With some quick research I see that there is an update to log4j, version 2.15.0 that may patch the recently discovered vulnerability.

    If you are using TWS/IB Gateway, this would be relevant for you, and at this time, we suggest corresponding with Interactive Brokers for their own word on security recommendations. (TWS 985.1g and IB Gateway 981.3c are the versions we currently recommend if they mention those versions are vulnerable.)

    An update for Java may be all that is necessary, but Interactive Brokers would know more as it involves their apps. If there is anything for us to share, I will be updating this post or replying again to this thread.
    JimNinjaTrader Customer Service

    Comment


      #3
      Jim

      IB has updated their TWS and IB Gateway software

      I have installed the new IB software versions and have confirmed that they now include log4j version 2.15.0

      The previous versions that were recommended by NinjaTrader used log4j version 2.12.0 (a vulnerable version of log4j)

      The latest IB software versions that I downloaded today are:

      TWS - version 10.12.2a
      IB Gateway - version 981.3f

      Are these new IB software versions compatible with NT8?

      Thanks

      Comment


        #4
        Hello Zigfried,

        The versions of TWS and IB Gateway we provide in our Connection Guide are the versions that are thoroughly tested and supported by us. Sometimes we see unexpected behavior with various versions of TWS and IB Gateway, but that is not to say other version than what we recommend will exhibit issues.

        You are welcome to try newer versions, but if an issue is seen, we would suggest confirming if the issue is seen with the versions of TWS/IB Gateway we give in our Connection Guide.

        We understand that there was another vulnerability for log4j 2.15.0 discovered as well. We are monitoring the situation closely and are considering the need to support newer versions of TWS and IB Gateway.

        Please refer to information provided by Interactive Brokers regarding security implications with their applications as they would be best able to answer.
        JimNinjaTrader Customer Service

        Comment

        Latest Posts

        Collapse

        Topics Statistics Last Post
        Started by zstheorist, Today, 07:52 PM
        0 responses
        3 views
        0 likes
        Last Post zstheorist  
        Started by pmachiraju, 11-01-2023, 04:46 AM
        8 responses
        149 views
        0 likes
        Last Post rehmans
        by rehmans
         
        Started by mattbsea, Today, 05:44 PM
        0 responses
        5 views
        0 likes
        Last Post mattbsea  
        Started by RideMe, 04-07-2024, 04:54 PM
        6 responses
        33 views
        0 likes
        Last Post RideMe
        by RideMe
         
        Started by tkaboris, Today, 05:13 PM
        0 responses
        5 views
        0 likes
        Last Post tkaboris  
        Working...
        X