<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Latest SSMC update v3.8.2.1 is available for download - log4j vulnerability fixed in HPE 3PAR StoreServ Storage</title>
    <link>https://community.hpe.com/t5/hpe-3par-storeserv-storage/latest-ssmc-update-v3-8-2-1-is-available-for-download-log4j/m-p/7157400#M7322</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.hpe.com/t5/user/viewprofilepage/user-id/1175155"&gt;@Sys Admin at SASREF&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;From v3.3.1 to v3.8.2.1 is not possible. Upto 3.3.x SSMC used to be an application that you install on Windows or Linux OS. v3.4 onwards, it is a 'ready to deploy' appliance that includes OS in the package. So, it needs an individual VM.&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Srinivas Bhat&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;&lt;FONT size="3"&gt;If you feel this was helpful please click the&amp;nbsp;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;KUDOS!&lt;/STRONG&gt;&lt;/FONT&gt;&amp;nbsp;thumb below!&lt;/FONT&gt;&lt;BR /&gt;&lt;U&gt;Note&lt;/U&gt;: All of my comments are my own and are not any official representation of HPE.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 31 Dec 2021 05:03:33 GMT</pubDate>
    <dc:creator>sbhat09</dc:creator>
    <dc:date>2021-12-31T05:03:33Z</dc:date>
    <item>
      <title>Latest SSMC update v3.8.2.1 is available for download - log4j vulnerability fixed</title>
      <link>https://community.hpe.com/t5/hpe-3par-storeserv-storage/latest-ssmc-update-v3-8-2-1-is-available-for-download-log4j/m-p/7156870#M7243</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;The latest SSMC update v3.8.2.1 is now available for download.&lt;/P&gt;&lt;P&gt;This version includes important security fixes&amp;nbsp;and&amp;nbsp;&lt;SPAN&gt;adheres to NIST SP 800-53 guidelines. It addresses the log4j vulnerability (CVE-2021-44228) as well.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://myenterpriselicense.hpe.com/cwp-ui/free-software/SSMC_CONSOLE" target="_blank" rel="noopener"&gt;https://myenterpriselicense.hpe.com/cwp-ui/free-software/SSMC_CONSOLE&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Srinivas Bhat&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;&lt;FONT size="3"&gt;If you feel this was helpful please click the&amp;nbsp;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;KUDOS!&lt;/STRONG&gt;&lt;/FONT&gt;&amp;nbsp;thumb below!&lt;/FONT&gt;&lt;BR /&gt;&lt;U&gt;Note&lt;/U&gt;: All of my comments are my own and are not any official representation of HPE.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Dec 2021 07:55:10 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-3par-storeserv-storage/latest-ssmc-update-v3-8-2-1-is-available-for-download-log4j/m-p/7156870#M7243</guid>
      <dc:creator>sbhat09</dc:creator>
      <dc:date>2021-12-20T07:55:10Z</dc:date>
    </item>
    <item>
      <title>Re: Latest SSMC update v3.8.2.1 is available for download</title>
      <link>https://community.hpe.com/t5/hpe-3par-storeserv-storage/latest-ssmc-update-v3-8-2-1-is-available-for-download-log4j/m-p/7156881#M7244</link>
      <description>&lt;P&gt;Thanks for the quick turnaround. Do you have an ETA for Service Processor 5.x patch?&lt;/P&gt;</description>
      <pubDate>Sat, 18 Dec 2021 16:13:58 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-3par-storeserv-storage/latest-ssmc-update-v3-8-2-1-is-available-for-download-log4j/m-p/7156881#M7244</guid>
      <dc:creator>aireynol</dc:creator>
      <dc:date>2021-12-18T16:13:58Z</dc:date>
    </item>
    <item>
      <title>Re: Latest SSMC update v3.8.2.1 is available for download</title>
      <link>https://community.hpe.com/t5/hpe-3par-storeserv-storage/latest-ssmc-update-v3-8-2-1-is-available-for-download-log4j/m-p/7156934#M7256</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.hpe.com/t5/user/viewprofilepage/user-id/1996316"&gt;@aireynol&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I don't have any updates yet. Are you finding it vulnerable to log4j in your tests?&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Srinivas Bhat&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;&lt;FONT size="3"&gt;If you feel this was helpful please click the&amp;nbsp;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;KUDOS!&lt;/STRONG&gt;&lt;/FONT&gt;&amp;nbsp;thumb below!&lt;/FONT&gt;&lt;BR /&gt;&lt;U&gt;Note&lt;/U&gt;: All of my comments are my own and are not any official representation of HPE.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Dec 2021 08:54:00 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-3par-storeserv-storage/latest-ssmc-update-v3-8-2-1-is-available-for-download-log4j/m-p/7156934#M7256</guid>
      <dc:creator>sbhat09</dc:creator>
      <dc:date>2021-12-20T08:54:00Z</dc:date>
    </item>
    <item>
      <title>Re: Latest SSMC update v3.8.2.1 is available for download</title>
      <link>https://community.hpe.com/t5/hpe-3par-storeserv-storage/latest-ssmc-update-v3-8-2-1-is-available-for-download-log4j/m-p/7156939#M7258</link>
      <description>&lt;P&gt;I have not been able to independently confirm it is vulnerable however it is listed a vulnerable in the security bulletin so I have shut mine down for now.&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&amp;amp;docId=hpesbgn04215en_us" target="_blank"&gt;https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&amp;amp;docId=hpesbgn04215en_us&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Dec 2021 09:37:44 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-3par-storeserv-storage/latest-ssmc-update-v3-8-2-1-is-available-for-download-log4j/m-p/7156939#M7258</guid>
      <dc:creator>aireynol</dc:creator>
      <dc:date>2021-12-20T09:37:44Z</dc:date>
    </item>
    <item>
      <title>Re: Latest SSMC update v3.8.2.1 is available for download - log4j vulnerability fixed</title>
      <link>https://community.hpe.com/t5/hpe-3par-storeserv-storage/latest-ssmc-update-v3-8-2-1-is-available-for-download-log4j/m-p/7156976#M7261</link>
      <description>&lt;P&gt;Thank you for letting us know!&amp;nbsp;&amp;nbsp; But I don't see any of the .star upgrade packages on that page.&amp;nbsp; Am I just missing them as don't seem to be able to find any .star packages for 3.8 or above, just the ISO files.&amp;nbsp;&amp;nbsp; I am currently on 3.7.2 and it wants the .star upgrade files to do an inplace upgrade.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Dec 2021 13:53:30 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-3par-storeserv-storage/latest-ssmc-update-v3-8-2-1-is-available-for-download-log4j/m-p/7156976#M7261</guid>
      <dc:creator>LewisP</dc:creator>
      <dc:date>2021-12-20T13:53:30Z</dc:date>
    </item>
    <item>
      <title>Re: Latest SSMC update v3.8.2.1 is available for download - log4j vulnerability fixed</title>
      <link>https://community.hpe.com/t5/hpe-3par-storeserv-storage/latest-ssmc-update-v3-8-2-1-is-available-for-download-log4j/m-p/7156977#M7262</link>
      <description>&lt;P&gt;The *.star file is in the iso-file.&lt;/P&gt;&lt;P&gt;If you are on 3.7.x, then you will need to.&lt;/P&gt;&lt;P&gt;0. Create a snapshot on your ESX/vmware/hyperV environment as a backup.&lt;/P&gt;&lt;P&gt;1. download the 3.8.0 iso-file&lt;/P&gt;&lt;P&gt;2. mount the 3.8.0 iso-file on the PC.&lt;/P&gt;&lt;P&gt;3. There you will find the 3.8.0*.star file that you can pick up for the upgrade.&lt;/P&gt;&lt;P&gt;4. download the 3.8.2.1 iso-file&amp;nbsp;&lt;/P&gt;&lt;P&gt;5. mount the 3.8.2.1 iso-file&lt;/P&gt;&lt;P&gt;6. pickup the 3.8.2.1.* star file and do the upgrade.&lt;/P&gt;&lt;P&gt;You may also directly go to 3.8.2.1. But I have not tested this.&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Dec 2021 14:06:12 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-3par-storeserv-storage/latest-ssmc-update-v3-8-2-1-is-available-for-download-log4j/m-p/7156977#M7262</guid>
      <dc:creator>Bertram Stoeckler</dc:creator>
      <dc:date>2021-12-20T14:06:12Z</dc:date>
    </item>
    <item>
      <title>Re: Latest SSMC update v3.8.2.1 is available for download - log4j vulnerability fixed</title>
      <link>https://community.hpe.com/t5/hpe-3par-storeserv-storage/latest-ssmc-update-v3-8-2-1-is-available-for-download-log4j/m-p/7156978#M7263</link>
      <description>&lt;P&gt;Thank you Bertram!&amp;nbsp;&amp;nbsp;&amp;nbsp; Definitely too early on a Monday and need more coffee or I might have remembered that.&lt;/P&gt;&lt;P&gt;Will add that to the notes I have for my team because I left that step out.&amp;nbsp; &lt;LI-EMOJI id="lia_disappointed-face" title=":disappointed_face:"&gt;&lt;/LI-EMOJI&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Dec 2021 14:11:51 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-3par-storeserv-storage/latest-ssmc-update-v3-8-2-1-is-available-for-download-log4j/m-p/7156978#M7263</guid>
      <dc:creator>LewisP</dc:creator>
      <dc:date>2021-12-20T14:11:51Z</dc:date>
    </item>
    <item>
      <title>Re: Latest SSMC update v3.8.2.1 is available for download - log4j vulnerability fixed</title>
      <link>https://community.hpe.com/t5/hpe-3par-storeserv-storage/latest-ssmc-update-v3-8-2-1-is-available-for-download-log4j/m-p/7156990#M7266</link>
      <description>&lt;P&gt;&lt;STRONG&gt;A general comment about SSMC upgrade from older versions. Version 3.4.x and 3.5.x (not the windows 3.3.1 version !!)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;First:&amp;nbsp;You can find the version of your SSMC appliance in the right-bottom corner of the SSMC-appliance page.&lt;/P&gt;&lt;P&gt;If your current version is 3.6.x or above, then you can stop reading this post.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If your current version is 3.4.x or 3.5.x then you won´t be able to directly upgrade to version 3.8.2.1.&lt;/P&gt;&lt;P&gt;You either need to first upgrade to version 3.6, or you need to do a new installation of SSMC 3.8.&lt;/P&gt;&lt;P&gt;I would recommend that you do a new installation of SSMC 3.8.0 followed by an upgrade to SSMC 3.8.2.1. A new installation usually does not last more than 30 minutes. Also note that it is possible to run 2 SSMC-instances in parallel, So you can let the old-version running, while the new one is setup. That way you can test the new version. The old instance should then be disconnected as any additional instance adds load the connected arrays.&lt;/P&gt;&lt;P&gt;The upgrade limitation is also documented in the administration guide:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;While upgrading from version 3.4.0.x, SSMC does not display any minimum version error message but generally&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;fails. Hewlett Packard Enterprise recommends you to upgrade to 3.6.0.0 version before upgrading to later&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;versions. To upgrade to HPE SSMC 3.8.0.0, you must have a minimum version of HPE SSMC 3.6.0.0.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;If you have a complex setup (many arrays and many self-created reports) and you prefer to upgrade to SSMC 3.8.2.1 via the interim version of 3.6, then you should open a support case, as the 3.6 version is not available on the HPE-download center.&lt;/P&gt;&lt;P&gt;For those who decide to do this, or who have an 3.6.x version available i also want to emphasize on an important change that came with SSMC 3.6, also mentioned in the administration guide:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Unified Login credentials for Administrative Access from SSMC 3.6 onwards&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;EM&gt;From HPE SSMC 3.6 release onwards, the web administrator account is merged with the appliance administrator&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;account. As a result, there is a single locally defined unified application administrator account for all SSMC.&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;If you are upgrading from a version prior to HPE SSMC 3.6 release, then the web administrator credentials, if&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;defined already, expires and you have to use ssmcadmin (same password that you use for appliance access)&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;to log in to the web GUI as well.&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;The single local account ( ssmcadmin ) remains as the only emergency account for all SSMC&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Why this is important:&lt;/P&gt;&lt;P&gt;We had a couple of customers who could not remember the ssmcadmin password. They never, or only once have logged in to the SSMC-TUI and then forgot the password, as with SSMC 3.4.x and SSMc 3.5.x the Web-based-administrator login, the one you use when adding an array, or when upgrading SSMC is a different user, and the TUI access once the SSMC is completly setup, is never used.&amp;nbsp;&lt;/P&gt;&lt;P&gt;So what happened was this:&lt;/P&gt;&lt;P&gt;1. customer logged in via the GUI-admin user and started the upgrade to SSMC 3.6&lt;/P&gt;&lt;P&gt;2. SSMC 3.6 during the upgrade removes the GUI-admin account and merges it with the TUI-ssmcadmin acount.&lt;/P&gt;&lt;P&gt;3. Since the customer forgot about the TUI-ssmcadmin password, they were not able to upgrade further or to add any array.&amp;nbsp;Resetting the password at that point is NOT possible as you need the TUI-ssmcadmin credentials to do this.&lt;/P&gt;&lt;P&gt;HPE-support is also not able to reset the password because there is no root-access on the appliance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To prevent this from happening you&amp;nbsp; should do this:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Prior to the upgrade from version 3.4.x or 3.5.x to the interim version 3.6.x: Check if you can ssh-login as the "ssmcadmin" user to the TUI . Keep the password in mind as you will need it to do the further updates via the ssmcadmin user.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;(One addtional note: Starting with SSMC 3.6, the appliance allows the configuration of a password-recovery via email)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope that this was not too confusing.&lt;/P&gt;&lt;P&gt;As i wrote, instead of an upgrade from 3.4.x or 3.5.x, you can do a new installation of 3.8.0 plus an upgrade to 3.8.2.1.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Dec 2021 16:26:20 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-3par-storeserv-storage/latest-ssmc-update-v3-8-2-1-is-available-for-download-log4j/m-p/7156990#M7266</guid>
      <dc:creator>Bertram Stoeckler</dc:creator>
      <dc:date>2021-12-20T16:26:20Z</dc:date>
    </item>
    <item>
      <title>Re: Latest SSMC update v3.8.2.1 is available for download</title>
      <link>https://community.hpe.com/t5/hpe-3par-storeserv-storage/latest-ssmc-update-v3-8-2-1-is-available-for-download-log4j/m-p/7156995#M7269</link>
      <description>&lt;P&gt;Looks like SP&amp;nbsp;5.0.9.2 will fix it&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" data-unlink="true"&gt;&lt;STRIKE&gt;https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&amp;amp;docId=a00002915en_us&amp;nbsp;&amp;nbsp;&lt;/STRIKE&gt;&lt;STRONG&gt;Moderator&amp;nbsp;&lt;/STRONG&gt;[above link is no longer valid, please visit&amp;nbsp;&lt;SPAN&gt;&lt;A href="https://support.hpe.com/hpesc/public/home?jumpid&amp;amp;#61;em_0pvxxmoei_aid-520066529" target="_blank"&gt;https://support.hpe.com/connect/s/&lt;/A&gt;&lt;/SPAN&gt;&amp;nbsp; to find the latest info ]&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Fixes&lt;/P&gt;
&lt;P&gt;The following issue is addressed in 5.0.9.2 release:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Issue ID: &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;350855&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Issue summary: &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;CVE-2021-44228 and CVE-2021-45046 - Log4j and Log4Shell Security Vulnerabilities.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Affected platforms: &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Only SP.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Affected software versions: &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;All versions from 5.0 onwards.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Issue description:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Security fixes for CVE-2021-44228 (Log4Shell) and CVE-2021-45046 are available in this patch release. Hewlett Packard Enterprise strongly recommends you to upgrade HPE Service Processor to 5.0.9.2 patch release as early as possible.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Conditions of occurrence: &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;N/A&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Impact: &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;High&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Customer circumvention: &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Upgrade to patch 5.0.9.2Customer recovery step: N/A&lt;/P&gt;</description>
      <pubDate>Wed, 23 Apr 2025 11:21:55 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-3par-storeserv-storage/latest-ssmc-update-v3-8-2-1-is-available-for-download-log4j/m-p/7156995#M7269</guid>
      <dc:creator>Superscouser</dc:creator>
      <dc:date>2025-04-23T11:21:55Z</dc:date>
    </item>
    <item>
      <title>Re: Latest SSMC update v3.8.2.1 is available for download - log4j vulnerability fixed</title>
      <link>https://community.hpe.com/t5/hpe-3par-storeserv-storage/latest-ssmc-update-v3-8-2-1-is-available-for-download-log4j/m-p/7157006#M7274</link>
      <description>&lt;P&gt;Here's SSMC v3.6: &lt;A href="https://myenterpriselicense.hpe.com/cwp-ui/software-update-details?productNumber=HPE_STORAGE_SSMC&amp;amp;version=3.6&amp;amp;impersonationFlow=searchProductByFamilyFlow" target="_blank"&gt;https://myenterpriselicense.hpe.com/cwp-ui/software-update-details?productNumber=HPE_STORAGE_SSMC&amp;amp;version=3.6&amp;amp;impersonationFlow=searchProductByFamilyFlow&lt;/A&gt;&lt;BR /&gt;ISO: HPE_SSMC_3.6_SW_QR482-11420.iso&lt;/P&gt;&lt;P&gt;You'll need to have contract access to it.&lt;/P&gt;&lt;P&gt;However, I think starting fresh on SSMC 3.8 will be fine.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Dec 2021 22:14:57 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-3par-storeserv-storage/latest-ssmc-update-v3-8-2-1-is-available-for-download-log4j/m-p/7157006#M7274</guid>
      <dc:creator>goslackware</dc:creator>
      <dc:date>2021-12-20T22:14:57Z</dc:date>
    </item>
    <item>
      <title>Re: Latest SSMC update v3.8.2.1 is available for download</title>
      <link>https://community.hpe.com/t5/hpe-3par-storeserv-storage/latest-ssmc-update-v3-8-2-1-is-available-for-download-log4j/m-p/7157044#M7277</link>
      <description>&lt;P&gt;Please check again the document you referred to, as it got updated, yesterday.&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&amp;amp;docId=hpesbgn04215en_us" target="_blank" rel="nofollow noopener noreferrer"&gt;https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&amp;amp;docId=hpesbgn04215en_us&lt;/A&gt;&lt;/P&gt;&lt;P&gt;In that document search for "SSMC" and follow the SSMC security bulletin.&lt;/P&gt;&lt;P&gt;You will find this:&lt;/P&gt;&lt;P&gt;===&lt;/P&gt;&lt;P&gt;SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed.&lt;/P&gt;&lt;P&gt;HPE StoreServ Management Console (SSMC) -Prior to v3.8.2.1&lt;/P&gt;&lt;P&gt;===&lt;/P&gt;&lt;P&gt;This is the official statement that all SSMC versions prior to version 3.8.2.1 are impacted.&lt;/P&gt;&lt;P&gt;Version 3.8.2.1 is therefor the fix.&lt;/P&gt;&lt;P&gt;Please let me know if you have any further questions.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Dec 2021 12:44:51 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-3par-storeserv-storage/latest-ssmc-update-v3-8-2-1-is-available-for-download-log4j/m-p/7157044#M7277</guid>
      <dc:creator>Bertram Stoeckler</dc:creator>
      <dc:date>2021-12-21T12:44:51Z</dc:date>
    </item>
    <item>
      <title>Re: Latest SSMC update v3.8.2.1 is available for download</title>
      <link>https://community.hpe.com/t5/hpe-3par-storeserv-storage/latest-ssmc-update-v3-8-2-1-is-available-for-download-log4j/m-p/7157321#M7311</link>
      <description>&lt;P&gt;Which specific version of log4j is included in the package 8.2.3.1? The linked security bulletin just mentions version 2.16.0, but the generel recommandation is to update to at least 2.17.0&lt;/P&gt;&lt;P&gt;Best regards Sebastian&lt;/P&gt;</description>
      <pubDate>Tue, 28 Dec 2021 09:52:05 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-3par-storeserv-storage/latest-ssmc-update-v3-8-2-1-is-available-for-download-log4j/m-p/7157321#M7311</guid>
      <dc:creator>SebSei</dc:creator>
      <dc:date>2021-12-28T09:52:05Z</dc:date>
    </item>
    <item>
      <title>Re: Latest SSMC update v3.8.2.1 is available for download</title>
      <link>https://community.hpe.com/t5/hpe-3par-storeserv-storage/latest-ssmc-update-v3-8-2-1-is-available-for-download-log4j/m-p/7157322#M7312</link>
      <description>&lt;P&gt;*package 3.8.2.1&lt;/P&gt;</description>
      <pubDate>Tue, 28 Dec 2021 09:52:38 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-3par-storeserv-storage/latest-ssmc-update-v3-8-2-1-is-available-for-download-log4j/m-p/7157322#M7312</guid>
      <dc:creator>SebSei</dc:creator>
      <dc:date>2021-12-28T09:52:38Z</dc:date>
    </item>
    <item>
      <title>Re: Latest SSMC update v3.8.2.1 is available for download</title>
      <link>https://community.hpe.com/t5/hpe-3par-storeserv-storage/latest-ssmc-update-v3-8-2-1-is-available-for-download-log4j/m-p/7157325#M7313</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.hpe.com/t5/user/viewprofilepage/user-id/2054114"&gt;@SebSei&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;There is no update yet about 2.17.0. The document will be revised when there is an update. I request&amp;nbsp;&lt;a href="https://community.hpe.com/t5/user/viewprofilepage/user-id/777826"&gt;@Bertram Stoeckler&lt;/a&gt; to add if you have any comments on this.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Srinivas Bhat&lt;/P&gt;</description>
      <pubDate>Tue, 28 Dec 2021 11:01:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-3par-storeserv-storage/latest-ssmc-update-v3-8-2-1-is-available-for-download-log4j/m-p/7157325#M7313</guid>
      <dc:creator>sbhat09</dc:creator>
      <dc:date>2021-12-28T11:01:21Z</dc:date>
    </item>
    <item>
      <title>Re: Latest SSMC update v3.8.2.1 is available for download - log4j vulnerability fixed</title>
      <link>https://community.hpe.com/t5/hpe-3par-storeserv-storage/latest-ssmc-update-v3-8-2-1-is-available-for-download-log4j/m-p/7157339#M7319</link>
      <description>&lt;P&gt;is there a version of the windows software the HPE 3PAR Stor Serv management COnsole. This software seems to come up as having&amp;nbsp; this vulnerability as well. Where does one get the update for this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Dec 2021 23:49:02 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-3par-storeserv-storage/latest-ssmc-update-v3-8-2-1-is-available-for-download-log4j/m-p/7157339#M7319</guid>
      <dc:creator>syntaxmax</dc:creator>
      <dc:date>2021-12-28T23:49:02Z</dc:date>
    </item>
    <item>
      <title>Re: Latest SSMC update v3.8.2.1 is available for download - log4j vulnerability fixed</title>
      <link>https://community.hpe.com/t5/hpe-3par-storeserv-storage/latest-ssmc-update-v3-8-2-1-is-available-for-download-log4j/m-p/7157352#M7320</link>
      <description>You can use the update option via GUI. Its the same package you can find in the .ISO.&lt;BR /&gt;&lt;BR /&gt;Best regards Sebastian</description>
      <pubDate>Wed, 29 Dec 2021 09:20:14 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-3par-storeserv-storage/latest-ssmc-update-v3-8-2-1-is-available-for-download-log4j/m-p/7157352#M7320</guid>
      <dc:creator>SebSei</dc:creator>
      <dc:date>2021-12-29T09:20:14Z</dc:date>
    </item>
    <item>
      <title>Re: Latest SSMC update v3.8.2.1 is available for download - log4j vulnerability fixed</title>
      <link>https://community.hpe.com/t5/hpe-3par-storeserv-storage/latest-ssmc-update-v3-8-2-1-is-available-for-download-log4j/m-p/7157369#M7321</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thank you for notifying, KUDOS!&amp;nbsp;&lt;/P&gt;&lt;P&gt;I just wanna know that, I am using 3.3.1 ssmc software, can I upgrade it to v3.8.2.1 or does it needs an individual VM.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Dec 2021 06:04:01 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-3par-storeserv-storage/latest-ssmc-update-v3-8-2-1-is-available-for-download-log4j/m-p/7157369#M7321</guid>
      <dc:creator>Sys Admin at SASREF</dc:creator>
      <dc:date>2021-12-30T06:04:01Z</dc:date>
    </item>
    <item>
      <title>Re: Latest SSMC update v3.8.2.1 is available for download - log4j vulnerability fixed</title>
      <link>https://community.hpe.com/t5/hpe-3par-storeserv-storage/latest-ssmc-update-v3-8-2-1-is-available-for-download-log4j/m-p/7157400#M7322</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.hpe.com/t5/user/viewprofilepage/user-id/1175155"&gt;@Sys Admin at SASREF&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;From v3.3.1 to v3.8.2.1 is not possible. Upto 3.3.x SSMC used to be an application that you install on Windows or Linux OS. v3.4 onwards, it is a 'ready to deploy' appliance that includes OS in the package. So, it needs an individual VM.&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Srinivas Bhat&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;&lt;FONT size="3"&gt;If you feel this was helpful please click the&amp;nbsp;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;KUDOS!&lt;/STRONG&gt;&lt;/FONT&gt;&amp;nbsp;thumb below!&lt;/FONT&gt;&lt;BR /&gt;&lt;U&gt;Note&lt;/U&gt;: All of my comments are my own and are not any official representation of HPE.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 31 Dec 2021 05:03:33 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-3par-storeserv-storage/latest-ssmc-update-v3-8-2-1-is-available-for-download-log4j/m-p/7157400#M7322</guid>
      <dc:creator>sbhat09</dc:creator>
      <dc:date>2021-12-31T05:03:33Z</dc:date>
    </item>
    <item>
      <title>Re: Latest SSMC update v3.8.2.1 is available for download</title>
      <link>https://community.hpe.com/t5/hpe-3par-storeserv-storage/latest-ssmc-update-v3-8-2-1-is-available-for-download-log4j/m-p/7157495#M7328</link>
      <description>&lt;P&gt;log4j 2.17.0 (Java &lt;LI-EMOJI id="lia_smiling-face-with-sunglasses" title=":smiling_face_with_sunglasses:"&gt;&lt;/LI-EMOJI&gt; fixes CVE-2021-45105&lt;/P&gt;&lt;P&gt;SSMC 3.8.2.1 has log4j version "2.16", but is NOT vulnerable to the issues reported in CVE-2021-45105.&lt;/P&gt;&lt;P&gt;SSMC does NOT use the feature of a "non-default Pattern Layout with a Context Lookup".&lt;/P&gt;&lt;P&gt;SSMC 3.8.2.1 therefore fixes all currently reported/known log4j vulnerabilities.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jan 2022 14:30:16 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-3par-storeserv-storage/latest-ssmc-update-v3-8-2-1-is-available-for-download-log4j/m-p/7157495#M7328</guid>
      <dc:creator>Bertram Stoeckler</dc:creator>
      <dc:date>2022-01-03T14:30:16Z</dc:date>
    </item>
    <item>
      <title>Re: Latest SSMC update v3.8.2.1 is available for download - log4j vulnerability fixed</title>
      <link>https://community.hpe.com/t5/hpe-3par-storeserv-storage/latest-ssmc-update-v3-8-2-1-is-available-for-download-log4j/m-p/7157966#M7367</link>
      <description>&lt;P&gt;Good evening,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For customers still running on SSMC&amp;nbsp;v3.3.1.25068, would you also advise doing a new installation to 3.8 , followed by upgrade to SSMC 3.8.2.1. so that we can run tests with the 2 SSMC instances in parallel ? Also with regards to the&amp;nbsp;ssmcadmin user . Is this an account associated with 3.4.x or higher as not familiar with that. We have a 3paradm user (which has full admin rights, and which i use for presenting storage etc) and also have a 3paradm1 account for logging on as Administrator console. Also am I right in thinking that v3.8 and above can only be installed on a VM ? (our current 3.3.1 SSMC&amp;nbsp; runs under Windows Server 2016.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jan 2022 17:09:10 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-3par-storeserv-storage/latest-ssmc-update-v3-8-2-1-is-available-for-download-log4j/m-p/7157966#M7367</guid>
      <dc:creator>Paolo_c</dc:creator>
      <dc:date>2022-01-10T17:09:10Z</dc:date>
    </item>
  </channel>
</rss>

