<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is OneView vulnerable to the Apache Software Log4j Vulnerability (CVE-2021-44228)? in HPE OneView</title>
    <link>https://community.hpe.com/t5/hpe-oneview/is-oneview-vulnerable-to-the-apache-software-log4j-vulnerability/m-p/7156652#M6741</link>
    <description>&lt;BLOCKQUOTE&gt;&lt;P&gt;&lt;SPAN&gt;Just a quick question, you said iLO doesn't use Log4j, But i was under the impression that HPE are currently making a new iLO version to fix this, am I wrong?&lt;/SPAN&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;I'm not sure where you recieved that information from, but iLO is &lt;STRONG&gt;not&lt;/STRONG&gt; impacted by CVE-2021-44228.&amp;nbsp; We document major vulnerabilities &lt;A href="https://www.hpe.com/us/en/services/security-vulnerability.html" target="_blank" rel="noopener"&gt;here&lt;/A&gt;.&amp;nbsp; The specific details to &lt;A href="https://techhub.hpe.com/eginfolib/securityalerts/Apache%20Software%20Log4j/Apache_Software_Log4j.html" target="_blank" rel="noopener"&gt;CVE-2021-44228 here&lt;/A&gt;.&amp;nbsp; You will see that iLO4 and iLO5 are in the not vulnerable list, &lt;A href="https://support.hpe.com/hpesc/public/docDisplay?docId=emr_na-a00120086en_us" target="_blank" rel="noopener"&gt;here&lt;/A&gt;.&amp;nbsp; We are looking to amend the list to include all versions of iLO.&lt;/P&gt;</description>
    <pubDate>Wed, 15 Dec 2021 16:10:54 GMT</pubDate>
    <dc:creator>ChrisLynch</dc:creator>
    <dc:date>2021-12-15T16:10:54Z</dc:date>
    <item>
      <title>Is OneView vulnerable to the Apache Software Log4j Vulnerability (CVE-2021-44228)?</title>
      <link>https://community.hpe.com/t5/hpe-oneview/is-oneview-vulnerable-to-the-apache-software-log4j-vulnerability/m-p/7156427#M6731</link>
      <description>&lt;P&gt;As title says, I'm looking to determine if the OneView or OneView Global Dashboard appliances (And iLO interfaces for that matter) are vulnerable to the Log4j vulnerability.&lt;/P&gt;&lt;P&gt;I chatted with HPE support, but was not confident in their answer. They directed me to this webpage (&lt;A href="https://www.hpe.com/us/en/services/security-vulnerability.html" target="_blank"&gt;https://www.hpe.com/us/en/services/security-vulnerability.html&lt;/A&gt;) and said OneVeiw is not listed, so that means its not vulnerable. However, no products are listed on that page, so I was looking for a little more positive confirmation that OneVeiw is not vulnerable. Anyone know for certian?&lt;/P&gt;</description>
      <pubDate>Tue, 14 Dec 2021 04:47:14 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-oneview/is-oneview-vulnerable-to-the-apache-software-log4j-vulnerability/m-p/7156427#M6731</guid>
      <dc:creator>daax</dc:creator>
      <dc:date>2021-12-14T04:47:14Z</dc:date>
    </item>
    <item>
      <title>Query: Is OneView vulnerable to the Apache Software Log4j Vulnerability (CVE-2021-44228)?</title>
      <link>https://community.hpe.com/t5/hpe-oneview/is-oneview-vulnerable-to-the-apache-software-log4j-vulnerability/m-p/7156430#M6732</link>
      <description>&lt;P style="margin: 0;"&gt;&lt;STRONG&gt;System recommended content:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="margin: 0;"&gt;1. &lt;A href="https://community.hpe.com/hpeb/plugins/custom/hp/hpebresponsive/article_click_sprinklr_bot?clickData=eyJxdWVyeVBpcGVsaW5lIjoiU3ByaW5rbHItQXV0b21hdGlvbiIsImRvY3VtZW50VXJpSGFzaCI6IkwxdnJZcHh6w7B4dmFNQ0x0Iiwic291cmNlTmFtZSI6ImNkcC1rbS1kb2N1bWVudC1wcm8taDQtdjIiLCJkb2N1bWVudFRpdGxlIjoiTm90aWNlOiBBcGFjaGUgU29mdHdhcmUgTG9nNGogLSBTZWN1cml0eSBWdWxuZXJhYmlsaXR5IENWRS0yMDIxLTQ0MjI4IiwiYXJ0aWNsZUNsaWNrVXJsIjoiaHR0cHM6Ly9zdXBwb3J0LmhwZS5jb20vaHBlc2MvcHVibGljL2RvY0Rpc3BsYXk/ZG9jSWQ9YTAwMTIwMDg2ZW5fdXMiLCJzZWFyY2hRdWVyeVVpZCI6ImNkNGQ2ZDBhLTgwN2ItNGIwOC04ZTdiLWU4OGFmZjE1YTJiMiJ9" target="_blank" rel="noopener"&gt;Notice: Apache Software Log4j - Security Vulnerability CVE-2021-44228&lt;/A&gt;&lt;/P&gt;
&lt;P style="margin: 0;"&gt;2. &lt;A href="https://community.hpe.com/hpeb/plugins/custom/hp/hpebresponsive/article_click_sprinklr_bot?clickData=eyJxdWVyeVBpcGVsaW5lIjoiU3ByaW5rbHItQXV0b21hdGlvbiIsImRvY3VtZW50VXJpSGFzaCI6IlNBcmFHcjRsV3ZoUEF2bGsiLCJzb3VyY2VOYW1lIjoiY2RwLWttLWRvY3VtZW50LXByby1oNC12MiIsImRvY3VtZW50VGl0bGUiOiJJcyBOb25TdG9wIHN5c3RlbSB2dWxuZXJhYmxlIHRvIENWRS0yMDIxLTQ0MjI4PyIsImFydGljbGVDbGlja1VybCI6Imh0dHBzOi8vc3VwcG9ydC5ocGUuY29tL2hwZXNjL3B1YmxpYy9kb2NEaXNwbGF5P2RvY0lkPW5zMjExMjQ1MzUwNDIzZW5fdXMiLCJzZWFyY2hRdWVyeVVpZCI6ImNkNGQ2ZDBhLTgwN2ItNGIwOC04ZTdiLWU4OGFmZjE1YTJiMiJ9" target="_blank" rel="noopener"&gt;Is NonStop system vulnerable to CVE-2021-44228?&lt;/A&gt;&lt;/P&gt;
&lt;P style="margin: 0;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0;"&gt;If the above information is helpful, then please click on "Thumbs Up/Kudo" icon.&lt;/P&gt;
&lt;P style="margin: 0;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0;"&gt;Thank you for being a HPE community member.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 22:45:55 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-oneview/is-oneview-vulnerable-to-the-apache-software-log4j-vulnerability/m-p/7156430#M6732</guid>
      <dc:creator>support_s</dc:creator>
      <dc:date>2021-12-13T22:45:55Z</dc:date>
    </item>
    <item>
      <title>Re: Is OneView vulnerable to the Apache Software Log4j Vulnerability (CVE-2021-44228)?</title>
      <link>https://community.hpe.com/t5/hpe-oneview/is-oneview-vulnerable-to-the-apache-software-log4j-vulnerability/m-p/7156431#M6733</link>
      <description>HPE OneView and OneView Global Dashboard are not vulnerable to the log4j exploit. While both use log4j, it is an older version without the exploit and does not allow an external attacker access to its endpoint (it is restricted to internal authenticated services only).&lt;BR /&gt;&lt;BR /&gt;iLO does not use log4j at all, in any firmware version for any generation of ASIC.</description>
      <pubDate>Mon, 13 Dec 2021 22:55:12 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-oneview/is-oneview-vulnerable-to-the-apache-software-log4j-vulnerability/m-p/7156431#M6733</guid>
      <dc:creator>ChrisLynch</dc:creator>
      <dc:date>2021-12-13T22:55:12Z</dc:date>
    </item>
    <item>
      <title>Re: Is OneView vulnerable to the Apache Software Log4j Vulnerability (CVE-2021-44228)?</title>
      <link>https://community.hpe.com/t5/hpe-oneview/is-oneview-vulnerable-to-the-apache-software-log4j-vulnerability/m-p/7156517#M6734</link>
      <description>&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Tue, 14 Dec 2021 16:05:55 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-oneview/is-oneview-vulnerable-to-the-apache-software-log4j-vulnerability/m-p/7156517#M6734</guid>
      <dc:creator>daax</dc:creator>
      <dc:date>2021-12-14T16:05:55Z</dc:date>
    </item>
    <item>
      <title>Re: Query: Is OneView vulnerable to the Apache Software Log4j Vulnerability (CVE-2021-4422</title>
      <link>https://community.hpe.com/t5/hpe-oneview/is-oneview-vulnerable-to-the-apache-software-log4j-vulnerability/m-p/7156518#M6735</link>
      <description>&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Tue, 14 Dec 2021 16:06:32 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-oneview/is-oneview-vulnerable-to-the-apache-software-log4j-vulnerability/m-p/7156518#M6735</guid>
      <dc:creator>daax</dc:creator>
      <dc:date>2021-12-14T16:06:32Z</dc:date>
    </item>
    <item>
      <title>Re: Is OneView vulnerable to the Apache Software Log4j Vulnerability (CVE-2021-44228)?</title>
      <link>https://community.hpe.com/t5/hpe-oneview/is-oneview-vulnerable-to-the-apache-software-log4j-vulnerability/m-p/7156596#M6740</link>
      <description>&lt;P&gt;Just a quick question, you said iLO doesn't use Log4j, But i was under the impression that HPE are currently making a new iLO version to fix this, am I wrong?&lt;/P&gt;</description>
      <pubDate>Wed, 15 Dec 2021 09:17:14 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-oneview/is-oneview-vulnerable-to-the-apache-software-log4j-vulnerability/m-p/7156596#M6740</guid>
      <dc:creator>cesarpegado</dc:creator>
      <dc:date>2021-12-15T09:17:14Z</dc:date>
    </item>
    <item>
      <title>Re: Is OneView vulnerable to the Apache Software Log4j Vulnerability (CVE-2021-44228)?</title>
      <link>https://community.hpe.com/t5/hpe-oneview/is-oneview-vulnerable-to-the-apache-software-log4j-vulnerability/m-p/7156652#M6741</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;P&gt;&lt;SPAN&gt;Just a quick question, you said iLO doesn't use Log4j, But i was under the impression that HPE are currently making a new iLO version to fix this, am I wrong?&lt;/SPAN&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;I'm not sure where you recieved that information from, but iLO is &lt;STRONG&gt;not&lt;/STRONG&gt; impacted by CVE-2021-44228.&amp;nbsp; We document major vulnerabilities &lt;A href="https://www.hpe.com/us/en/services/security-vulnerability.html" target="_blank" rel="noopener"&gt;here&lt;/A&gt;.&amp;nbsp; The specific details to &lt;A href="https://techhub.hpe.com/eginfolib/securityalerts/Apache%20Software%20Log4j/Apache_Software_Log4j.html" target="_blank" rel="noopener"&gt;CVE-2021-44228 here&lt;/A&gt;.&amp;nbsp; You will see that iLO4 and iLO5 are in the not vulnerable list, &lt;A href="https://support.hpe.com/hpesc/public/docDisplay?docId=emr_na-a00120086en_us" target="_blank" rel="noopener"&gt;here&lt;/A&gt;.&amp;nbsp; We are looking to amend the list to include all versions of iLO.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Dec 2021 16:10:54 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-oneview/is-oneview-vulnerable-to-the-apache-software-log4j-vulnerability/m-p/7156652#M6741</guid>
      <dc:creator>ChrisLynch</dc:creator>
      <dc:date>2021-12-15T16:10:54Z</dc:date>
    </item>
  </channel>
</rss>

