<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSMC and log4j vulnerability in HPE 3PAR StoreServ Storage</title>
    <link>https://community.hpe.com/t5/hpe-3par-storeserv-storage/ssmc-and-log4j-vulnerability/m-p/7156909#M7250</link>
    <description>&lt;P&gt;Successfully upgraded to 3.8.2.1.9 (upgraded from 3.8.2.0.39) without issue.&lt;/P&gt;&lt;P&gt;Download .iso, log into SSMC admin and Upgrade with .star file&lt;/P&gt;&lt;P&gt;Is there any confirmation that 3.8.2.1 fixes the log4j vulnerability? I could not find any detailed release notes. Do we need to redo or undo anything if we had applied the workaround?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Sun, 19 Dec 2021 22:24:34 GMT</pubDate>
    <dc:creator>andrewk4</dc:creator>
    <dc:date>2021-12-19T22:24:34Z</dc:date>
    <item>
      <title>SSMC and log4j vulnerability</title>
      <link>https://community.hpe.com/t5/hpe-3par-storeserv-storage/ssmc-and-log4j-vulnerability/m-p/7156368#M7177</link>
      <description>&lt;P&gt;SSMC 3.8.1 is vulnerable to log4j (cve-2021-44228), if you have any public facing instances I would suggest shutting them down while we wait for a bulletin.&lt;/P&gt;&lt;P&gt;Also&amp;nbsp;myenterpriselicense.hpe.com has been down all morning so can't get 3.8.2 to test against that.&lt;/P&gt;&lt;P&gt;Edit: site is back up&lt;/P&gt;&lt;P&gt;Edit1:&amp;nbsp;3.8.2 is still vulnerable in my testing. I have also heard reports Service Processor is vulnerable although I have not been able to confirm with testing.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Dec 2021 13:03:41 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-3par-storeserv-storage/ssmc-and-log4j-vulnerability/m-p/7156368#M7177</guid>
      <dc:creator>aireynol</dc:creator>
      <dc:date>2021-12-14T13:03:41Z</dc:date>
    </item>
    <item>
      <title>Query: SSMC and log4j vulnerability</title>
      <link>https://community.hpe.com/t5/hpe-3par-storeserv-storage/ssmc-and-log4j-vulnerability/m-p/7156392#M7180</link>
      <description>&lt;P style="margin: 0;"&gt;&lt;STRONG&gt;System recommended content:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="margin: 0;"&gt;1. &lt;A href="https://community.hpe.com/hpeb/plugins/custom/hp/hpebresponsive/article_click_sprinklr_bot?clickData=eyJxdWVyeVBpcGVsaW5lIjoiU3ByaW5rbHItQXV0b21hdGlvbiIsImRvY3VtZW50VXJpSGFzaCI6IkwxdnJZcHh6w7B4dmFNQ0x0Iiwic291cmNlTmFtZSI6ImNkcC1rbS1kb2N1bWVudC1wcm8taDQtdjIiLCJkb2N1bWVudFRpdGxlIjoiTm90aWNlOiBBcGFjaGUgU29mdHdhcmUgTG9nNGogLSBTZWN1cml0eSBWdWxuZXJhYmlsaXR5IENWRS0yMDIxLTQ0MjI4IiwiYXJ0aWNsZUNsaWNrVXJsIjoiaHR0cHM6Ly9zdXBwb3J0LmhwZS5jb20vaHBlc2MvcHVibGljL2RvY0Rpc3BsYXk/ZG9jSWQ9YTAwMTIwMDg2ZW5fdXMiLCJzZWFyY2hRdWVyeVVpZCI6ImZjMDY5ZDU2LThlN2UtNDU5Ni04ZWI5LWFiZGNjMmJhOTIwMCJ9" target="_blank" rel="noopener"&gt;Notice: Apache Software Log4j - Security Vulnerability CVE-2021-44228&lt;/A&gt;&lt;/P&gt;
&lt;P style="margin: 0;"&gt;2. &lt;A href="https://community.hpe.com/hpeb/plugins/custom/hp/hpebresponsive/article_click_sprinklr_bot?clickData=eyJxdWVyeVBpcGVsaW5lIjoiU3ByaW5rbHItQXV0b21hdGlvbiIsImRvY3VtZW50VXJpSGFzaCI6IsOxw7BweVd6QXhibTdSeTg1TSIsInNvdXJjZU5hbWUiOiJjZHAta20tZG9jdW1lbnQtcHJvLWg0LXYyIiwiZG9jdW1lbnRUaXRsZSI6IlNlcnZsZXRzOiBsb2c0aiBzeW5jaHJvbml6ZWQgbG9nZ2luZyBpc3N1ZXMgZnJvbSBtdWx0aXBsZSBKVk0gcHJvY2Vzc2VzIiwiYXJ0aWNsZUNsaWNrVXJsIjoiaHR0cHM6Ly9zdXBwb3J0LmhwZS5jb20vaHBlc2MvcHVibGljL2RvY0Rpc3BsYXk/ZG9jSWQ9bnMwMTA4OTQ1ZW5fdXMiLCJzZWFyY2hRdWVyeVVpZCI6ImZjMDY5ZDU2LThlN2UtNDU5Ni04ZWI5LWFiZGNjMmJhOTIwMCJ9" target="_blank" rel="noopener"&gt;Servlets: log4j synchronized logging issues from multiple JVM processes&lt;/A&gt;&lt;/P&gt;
&lt;P style="margin: 0;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0;"&gt;If the above information is helpful, then please click on "Thumbs Up/Kudo" icon.&lt;/P&gt;
&lt;P style="margin: 0;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0;"&gt;Thank you for being a HPE community member.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 15:12:55 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-3par-storeserv-storage/ssmc-and-log4j-vulnerability/m-p/7156392#M7180</guid>
      <dc:creator>support_s</dc:creator>
      <dc:date>2021-12-13T15:12:55Z</dc:date>
    </item>
    <item>
      <title>Re: SSMC and log4j vulnerability</title>
      <link>https://community.hpe.com/t5/hpe-3par-storeserv-storage/ssmc-and-log4j-vulnerability/m-p/7156437#M7181</link>
      <description>&lt;P&gt;The Software Depot site seems to have been down for 24 hours - Have tryied multiple times in this time - Getting errors like:&lt;/P&gt;&lt;P&gt;Internal Server Error - Read&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The server encountered an internal error or misconfiguration and was unable to complete your request.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Reference #3.9667cd17.1639443263.1103c702&lt;/P&gt;&lt;P&gt;Can you advise when this site is expected to be back up and running?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Dec 2021 01:35:36 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-3par-storeserv-storage/ssmc-and-log4j-vulnerability/m-p/7156437#M7181</guid>
      <dc:creator>QuintonH</dc:creator>
      <dc:date>2021-12-14T01:35:36Z</dc:date>
    </item>
    <item>
      <title>Re: SSMC and log4j vulnerability</title>
      <link>https://community.hpe.com/t5/hpe-3par-storeserv-storage/ssmc-and-log4j-vulnerability/m-p/7156441#M7182</link>
      <description>&lt;P&gt;The link to download SSMC is still down. I will let you know if I get any updates or the link starts working.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Srinivas Bhat&lt;/P&gt;</description>
      <pubDate>Tue, 14 Dec 2021 03:58:59 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-3par-storeserv-storage/ssmc-and-log4j-vulnerability/m-p/7156441#M7182</guid>
      <dc:creator>sbhat09</dc:creator>
      <dc:date>2021-12-14T03:58:59Z</dc:date>
    </item>
    <item>
      <title>Re: SSMC and log4j vulnerability</title>
      <link>https://community.hpe.com/t5/hpe-3par-storeserv-storage/ssmc-and-log4j-vulnerability/m-p/7156466#M7183</link>
      <description>&lt;P&gt;I can get the HPE website, but i all i seem to find is release notes for 3.8.2 but i can't find the actual download&lt;/P&gt;</description>
      <pubDate>Tue, 14 Dec 2021 09:21:25 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-3par-storeserv-storage/ssmc-and-log4j-vulnerability/m-p/7156466#M7183</guid>
      <dc:creator>cesarpegado</dc:creator>
      <dc:date>2021-12-14T09:21:25Z</dc:date>
    </item>
    <item>
      <title>Re: SSMC and log4j vulnerability</title>
      <link>https://community.hpe.com/t5/hpe-3par-storeserv-storage/ssmc-and-log4j-vulnerability/m-p/7156469#M7184</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Latest release notes are not pdf downloads. Release notes for SSMC v3.8.2 is available only for online reference.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;You can refer this URL for release notes information&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;A title="https://myenterpriselicense.hpe.com/cwp-ui/free-software/ssmc_console" href="https://myenterpriselicense.hpe.com/cwp-ui/free-software/SSMC_CONSOLE" target="_blank" rel="noopener noreferrer"&gt;https://myenterpriselicense.hpe.com/cwp-ui/free-software/SSMC_CONSOLE&lt;/A&gt;&lt;BR /&gt;&lt;SPAN&gt;Hyperlinks are available for additional details as well.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Jyothi (HPE Employee)&lt;/P&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Dec 2021 09:49:01 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-3par-storeserv-storage/ssmc-and-log4j-vulnerability/m-p/7156469#M7184</guid>
      <dc:creator>Jyothiyash</dc:creator>
      <dc:date>2021-12-14T09:49:01Z</dc:date>
    </item>
    <item>
      <title>Re: SSMC and log4j vulnerability</title>
      <link>https://community.hpe.com/t5/hpe-3par-storeserv-storage/ssmc-and-log4j-vulnerability/m-p/7156477#M7186</link>
      <description>&lt;P&gt;Thank you, i can download it from your link&lt;/P&gt;</description>
      <pubDate>Tue, 14 Dec 2021 10:01:01 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-3par-storeserv-storage/ssmc-and-log4j-vulnerability/m-p/7156477#M7186</guid>
      <dc:creator>cesarpegado</dc:creator>
      <dc:date>2021-12-14T10:01:01Z</dc:date>
    </item>
    <item>
      <title>Re: SSMC and log4j vulnerability</title>
      <link>https://community.hpe.com/t5/hpe-3par-storeserv-storage/ssmc-and-log4j-vulnerability/m-p/7156478#M7187</link>
      <description>&lt;P&gt;So I was able to download 3.8.2. But I cannot find anything if the log4j exploit is fixed or not. Anyone with more information care to chip in?&lt;/P&gt;</description>
      <pubDate>Tue, 14 Dec 2021 10:09:05 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-3par-storeserv-storage/ssmc-and-log4j-vulnerability/m-p/7156478#M7187</guid>
      <dc:creator>ArjanSchepers</dc:creator>
      <dc:date>2021-12-14T10:09:05Z</dc:date>
    </item>
    <item>
      <title>Re: SSMC and log4j vulnerability</title>
      <link>https://community.hpe.com/t5/hpe-3par-storeserv-storage/ssmc-and-log4j-vulnerability/m-p/7156480#M7188</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.hpe.com/t5/user/viewprofilepage/user-id/2053591"&gt;@ArjanSchepers&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;The release notes (as on 9th Dec 2021) say SSMC v3.8.2 &lt;SPAN&gt;includes "important security fixes that strengthen the security posture of SSMC appliance. HPE strongly recommends that you upgrade your SSMC appliance to this version."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Later (As on 13th Dec 2021) the below document confirms that HPE 3PAR is not affected by 'Log4j' vulnarability.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&amp;amp;docId=a00120086en_us" target="_blank" rel="noopener"&gt;https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&amp;amp;docId=a00120086en_us&lt;/A&gt;&lt;/P&gt;&lt;P&gt;There is no official confirmation about whether&amp;nbsp;the vulnerability is fixed in the SSMC v3.8.2.&lt;/P&gt;&lt;P&gt;I will keep you posted if I can get more details.&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Srinivas Bhat&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;&lt;FONT size="3"&gt;If you feel this was helpful please click the&amp;nbsp;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;KUDOS!&lt;/STRONG&gt;&lt;/FONT&gt;&amp;nbsp;thumb below!&lt;/FONT&gt;&lt;BR /&gt;&lt;U&gt;Note&lt;/U&gt;: All of my comments are my own and are not any official representation of HPE.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Dec 2021 13:07:22 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-3par-storeserv-storage/ssmc-and-log4j-vulnerability/m-p/7156480#M7188</guid>
      <dc:creator>sbhat09</dc:creator>
      <dc:date>2021-12-14T13:07:22Z</dc:date>
    </item>
    <item>
      <title>Re: SSMC and log4j vulnerability</title>
      <link>https://community.hpe.com/t5/hpe-3par-storeserv-storage/ssmc-and-log4j-vulnerability/m-p/7156482#M7189</link>
      <description>&lt;P&gt;Hi WE have some old G6 blades and chassis&amp;nbsp; We wanted to check if these are affected ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 14 Dec 2021 11:02:11 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-3par-storeserv-storage/ssmc-and-log4j-vulnerability/m-p/7156482#M7189</guid>
      <dc:creator>Raz2</dc:creator>
      <dc:date>2021-12-14T11:02:11Z</dc:date>
    </item>
    <item>
      <title>Re: SSMC and log4j vulnerability</title>
      <link>https://community.hpe.com/t5/hpe-3par-storeserv-storage/ssmc-and-log4j-vulnerability/m-p/7156486#M7190</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.hpe.com/t5/user/viewprofilepage/user-id/2053593"&gt;@Raz2&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Here is the list of HPE Products that are NOT affected by the vulnerability (after recommended upgrade). HPE is working on to safeguard rest of the actively supported products. Please refer the list below:&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&amp;amp;docId=a00120086en_us" target="_blank" rel="nofollow noopener noreferrer"&gt;https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&amp;amp;docId=a00120086en_us&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Srinivas Bhat&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;&lt;FONT size="3"&gt;If you feel this was helpful please click the&amp;nbsp;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;KUDOS!&lt;/STRONG&gt;&lt;/FONT&gt;&amp;nbsp;thumb below!&lt;/FONT&gt;&lt;BR /&gt;&lt;U&gt;Note&lt;/U&gt;: All of my comments are my own and are not any official representation of HPE.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Dec 2021 11:13:10 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-3par-storeserv-storage/ssmc-and-log4j-vulnerability/m-p/7156486#M7190</guid>
      <dc:creator>sbhat09</dc:creator>
      <dc:date>2021-12-14T11:13:10Z</dc:date>
    </item>
    <item>
      <title>Re: Query: SSMC and log4j vulnerability</title>
      <link>https://community.hpe.com/t5/hpe-3par-storeserv-storage/ssmc-and-log4j-vulnerability/m-p/7156492#M7194</link>
      <description>&lt;P&gt;Dear HPE, so the SSMC version 3.7.2 can be vulnerable ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks a lot&lt;/P&gt;&lt;P&gt;Monardo&lt;/P&gt;</description>
      <pubDate>Tue, 14 Dec 2021 11:32:37 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-3par-storeserv-storage/ssmc-and-log4j-vulnerability/m-p/7156492#M7194</guid>
      <dc:creator>monardo</dc:creator>
      <dc:date>2021-12-14T11:32:37Z</dc:date>
    </item>
    <item>
      <title>Re: Query: SSMC and log4j vulnerability</title>
      <link>https://community.hpe.com/t5/hpe-3par-storeserv-storage/ssmc-and-log4j-vulnerability/m-p/7156497#M7195</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.hpe.com/t5/user/viewprofilepage/user-id/1651002"&gt;@monardo&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;This vulnerability was just found last week (9th December 2021 I think). SSMC 3.7.2 is the older release.&lt;/P&gt;&lt;P&gt;As per my news sources, in it's standard form, I don't think SSMC v3.7.2 is vulnerable in a secured network. However, HPE has not confirmed that v3.7.2 is safeguarded from the vulnerability as well. Vulnerability also depends on your network security, other cloud and web application, APIs and other plugins.&lt;/P&gt;&lt;P&gt;I recommend you to get that confirmed by your IT security team.&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Srinivas Bhat&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;&lt;FONT size="3"&gt;If you feel this was helpful please click the&amp;nbsp;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;KUDOS!&lt;/STRONG&gt;&lt;/FONT&gt;&amp;nbsp;thumb below!&lt;/FONT&gt;&lt;BR /&gt;&lt;U&gt;Note&lt;/U&gt;: All of my comments are my own and are not any official representation of HPE.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Dec 2021 12:44:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-3par-storeserv-storage/ssmc-and-log4j-vulnerability/m-p/7156497#M7195</guid>
      <dc:creator>sbhat09</dc:creator>
      <dc:date>2021-12-14T12:44:21Z</dc:date>
    </item>
    <item>
      <title>Re: SSMC and log4j vulnerability</title>
      <link>https://community.hpe.com/t5/hpe-3par-storeserv-storage/ssmc-and-log4j-vulnerability/m-p/7156499#M7196</link>
      <description>&lt;P&gt;Yes, please keep us posted. "Looks like the vulnerability is fixed" is not good enough for us, we need to be sure. In the meantime, we shut down the SSMC appliance.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Dec 2021 12:19:36 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-3par-storeserv-storage/ssmc-and-log4j-vulnerability/m-p/7156499#M7196</guid>
      <dc:creator>ArjanSchepers</dc:creator>
      <dc:date>2021-12-14T12:19:36Z</dc:date>
    </item>
    <item>
      <title>Re: SSMC and log4j vulnerability</title>
      <link>https://community.hpe.com/t5/hpe-3par-storeserv-storage/ssmc-and-log4j-vulnerability/m-p/7156500#M7197</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.hpe.com/t5/user/viewprofilepage/user-id/2053591"&gt;@ArjanSchepers&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;This notice (URL below) states that 3PAR, Primera, alletra and several other HPE systems are safe from the vulnerability. But doesn't explicitly confirms about the SSMC. I will post it here when I can get that confirmation.&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&amp;amp;docId=a00120086en_us" target="_blank"&gt;https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&amp;amp;docId=a00120086en_us&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Srinivas Bhat&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;&lt;FONT size="3"&gt;If you feel this was helpful please click the&amp;nbsp;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;KUDOS!&lt;/STRONG&gt;&lt;/FONT&gt;&amp;nbsp;thumb below!&lt;/FONT&gt;&lt;BR /&gt;&lt;U&gt;Note&lt;/U&gt;: All of my comments are my own and are not any official representation of HPE.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Dec 2021 12:54:42 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-3par-storeserv-storage/ssmc-and-log4j-vulnerability/m-p/7156500#M7197</guid>
      <dc:creator>sbhat09</dc:creator>
      <dc:date>2021-12-14T12:54:42Z</dc:date>
    </item>
    <item>
      <title>Re: SSMC and log4j vulnerability</title>
      <link>https://community.hpe.com/t5/hpe-3par-storeserv-storage/ssmc-and-log4j-vulnerability/m-p/7156501#M7198</link>
      <description>&lt;P&gt;3.8.2 is still vulnerable in my testing. I have also heard reports Service Processor is vulnerable although I have not been able to confirm with testing.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Dec 2021 13:03:03 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-3par-storeserv-storage/ssmc-and-log4j-vulnerability/m-p/7156501#M7198</guid>
      <dc:creator>aireynol</dc:creator>
      <dc:date>2021-12-14T13:03:03Z</dc:date>
    </item>
    <item>
      <title>Re: SSMC and log4j vulnerability</title>
      <link>https://community.hpe.com/t5/hpe-3par-storeserv-storage/ssmc-and-log4j-vulnerability/m-p/7156506#M7199</link>
      <description>&lt;P&gt;Yes, I saw this document and it is not totally complete...&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Dec 2021 13:50:13 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-3par-storeserv-storage/ssmc-and-log4j-vulnerability/m-p/7156506#M7199</guid>
      <dc:creator>monardo</dc:creator>
      <dc:date>2021-12-14T13:50:13Z</dc:date>
    </item>
    <item>
      <title>Re: SSMC and log4j vulnerability</title>
      <link>https://community.hpe.com/t5/hpe-3par-storeserv-storage/ssmc-and-log4j-vulnerability/m-p/7156507#M7200</link>
      <description>&lt;P&gt;Got an update that SSMC v3.8.2 is not confirmed as safe against the 'log4j' vulnerability.&lt;/P&gt;&lt;P&gt;The fix for the vulnerability is in progress. But there s a workaround available as well. Please contact HPE support if waiting for the fix is not an option for you.&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Srinivas Bhat&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;&lt;FONT size="3"&gt;If you feel this was helpful please click the&amp;nbsp;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;KUDOS!&lt;/STRONG&gt;&lt;/FONT&gt;&amp;nbsp;thumb below!&lt;/FONT&gt;&lt;BR /&gt;&lt;U&gt;Note&lt;/U&gt;: All of my comments are my own and are not any official representation of HPE.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Dec 2021 14:06:58 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-3par-storeserv-storage/ssmc-and-log4j-vulnerability/m-p/7156507#M7200</guid>
      <dc:creator>sbhat09</dc:creator>
      <dc:date>2021-12-14T14:06:58Z</dc:date>
    </item>
    <item>
      <title>Re: SSMC and log4j vulnerability</title>
      <link>https://community.hpe.com/t5/hpe-3par-storeserv-storage/ssmc-and-log4j-vulnerability/m-p/7156536#M7201</link>
      <description>&lt;P&gt;From what I can tell, SSMC 3.8.2 is patching a completely &lt;EM&gt;different&lt;/EM&gt; CVE (CVE-2021-29214)...I think its release timing of December 9th is what's confusing. I would imagine that 3.8.2 is stil vulnerable to CVE-2021-44228.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;A href="https://support.hpe.com/hpesc/public/docDisplay?nlaid=HPGL_ALERTS_3009714&amp;amp;docId=emr_na-hpesbst04207en_us&amp;amp;hprpt_id=HPGL_ALERTS_3009714&amp;amp;jumpid=em_alerts_us-us_Dec21_xbu_all_all&amp;amp;DIMID=EMID_1b68e56b8128e2b9cc0cfdcd2e937de64f4651b3047495cdb9e2265c5b200fa11b68e56b8128e2b9cc0cfdcd2e937de64f4651b3047495cdb9e2265c5b200fa1/&amp;amp;elq_mid=17733&amp;amp;elq_cid=48560422" target="_blank" rel="noopener"&gt;CVE-2021-29214&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;vs&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&amp;amp;docId=hpesbgn04215en_us" target="_blank" rel="noopener"&gt;CVE-2021-44228&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Dec 2021 18:11:35 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-3par-storeserv-storage/ssmc-and-log4j-vulnerability/m-p/7156536#M7201</guid>
      <dc:creator>fnbit</dc:creator>
      <dc:date>2021-12-14T18:11:35Z</dc:date>
    </item>
    <item>
      <title>Re: SSMC and log4j vulnerability</title>
      <link>https://community.hpe.com/t5/hpe-3par-storeserv-storage/ssmc-and-log4j-vulnerability/m-p/7156616#M7209</link>
      <description>&lt;P&gt;Can you please post the workaround? I'm currently juggling around with at least 5 affected products in my organization, I do not have time to contact each supplier individually. We need a public facing website with workarounds, patches or other means of mitigation. Thank you&amp;nbsp;&lt;a href="https://community.hpe.com/t5/user/viewprofilepage/user-id/2011514"&gt;@sbhat09&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Dec 2021 11:47:22 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-3par-storeserv-storage/ssmc-and-log4j-vulnerability/m-p/7156616#M7209</guid>
      <dc:creator>ArjanSchepers</dc:creator>
      <dc:date>2021-12-15T11:47:22Z</dc:date>
    </item>
  </channel>
</rss>

