- Community Home
- >
- Storage
- >
- Midrange and Enterprise Storage
- >
- HPE 3PAR StoreServ Storage
- >
- SSMC and log4j vulnerability
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-13-2021 06:12 AM - edited 12-14-2021 05:03 AM
12-13-2021 06:12 AM - edited 12-14-2021 05:03 AM
SSMC 3.8.1 is vulnerable to log4j (cve-2021-44228), if you have any public facing instances I would suggest shutting them down while we wait for a bulletin.
Also myenterpriselicense.hpe.com has been down all morning so can't get 3.8.2 to test against that.
Edit: site is back up
Edit1: 3.8.2 is still vulnerable in my testing. I have also heard reports Service Processor is vulnerable although I have not been able to confirm with testing.
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-13-2021 07:12 AM
12-13-2021 07:12 AM
Query: SSMC and log4j vulnerability
System recommended content:
1. Notice: Apache Software Log4j - Security Vulnerability CVE-2021-44228
2. Servlets: log4j synchronized logging issues from multiple JVM processes
If the above information is helpful, then please click on "Thumbs Up/Kudo" icon.
Thank you for being a HPE community member.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-13-2021 05:35 PM
12-13-2021 05:35 PM
Re: SSMC and log4j vulnerability
The Software Depot site seems to have been down for 24 hours - Have tryied multiple times in this time - Getting errors like:
Internal Server Error - Read
The server encountered an internal error or misconfiguration and was unable to complete your request.
Reference #3.9667cd17.1639443263.1103c702
Can you advise when this site is expected to be back up and running?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-13-2021 07:58 PM
12-13-2021 07:58 PM
Re: SSMC and log4j vulnerability
The link to download SSMC is still down. I will let you know if I get any updates or the link starts working.
Regards,
Srinivas Bhat
I work at HPE
HPE Support Center offers support for your HPE services and products when and how you need it. Get started with HPE Support Center today.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-14-2021 01:21 AM
12-14-2021 01:21 AM
Re: SSMC and log4j vulnerability
I can get the HPE website, but i all i seem to find is release notes for 3.8.2 but i can't find the actual download
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-14-2021 01:49 AM
12-14-2021 01:49 AM
Re: SSMC and log4j vulnerability
Latest release notes are not pdf downloads. Release notes for SSMC v3.8.2 is available only for online reference.
You can refer this URL for release notes information https://myenterpriselicense.hpe.com/cwp-ui/free-software/SSMC_CONSOLE
Hyperlinks are available for additional details as well.
Regards
Jyothi (HPE Employee)
I work at HPE
HPE Support Center offers support for your HPE services and products when and how you need it. Get started with HPE Support Center today.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-14-2021 02:01 AM
12-14-2021 02:01 AM
Re: SSMC and log4j vulnerability
Thank you, i can download it from your link
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-14-2021 02:09 AM
12-14-2021 02:09 AM
Re: SSMC and log4j vulnerability
So I was able to download 3.8.2. But I cannot find anything if the log4j exploit is fixed or not. Anyone with more information care to chip in?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-14-2021 02:22 AM - edited 12-14-2021 05:07 AM
12-14-2021 02:22 AM - edited 12-14-2021 05:07 AM
Re: SSMC and log4j vulnerability
Hello @ArjanSchepers,
The release notes (as on 9th Dec 2021) say SSMC v3.8.2 includes "important security fixes that strengthen the security posture of SSMC appliance. HPE strongly recommends that you upgrade your SSMC appliance to this version."
Later (As on 13th Dec 2021) the below document confirms that HPE 3PAR is not affected by 'Log4j' vulnarability.
https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=a00120086en_us
There is no official confirmation about whether the vulnerability is fixed in the SSMC v3.8.2.
I will keep you posted if I can get more details.
Regards,
Srinivas Bhat
If you feel this was helpful please click the KUDOS! thumb below!
Note: All of my comments are my own and are not any official representation of HPE.
I work at HPE
HPE Support Center offers support for your HPE services and products when and how you need it. Get started with HPE Support Center today.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-14-2021 03:02 AM
12-14-2021 03:02 AM
Re: SSMC and log4j vulnerability
Hi WE have some old G6 blades and chassis We wanted to check if these are affected ?
Thanks
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-14-2021 03:13 AM
12-14-2021 03:13 AM
Re: SSMC and log4j vulnerability
Hello @Raz2,
Here is the list of HPE Products that are NOT affected by the vulnerability (after recommended upgrade). HPE is working on to safeguard rest of the actively supported products. Please refer the list below:
https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=a00120086en_us
Regards,
Srinivas Bhat
If you feel this was helpful please click the KUDOS! thumb below!
Note: All of my comments are my own and are not any official representation of HPE.
I work at HPE
HPE Support Center offers support for your HPE services and products when and how you need it. Get started with HPE Support Center today.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-14-2021 03:32 AM
12-14-2021 03:32 AM
Re: Query: SSMC and log4j vulnerability
Dear HPE, so the SSMC version 3.7.2 can be vulnerable ?
thanks a lot
Monardo
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-14-2021 04:18 AM - edited 12-14-2021 04:44 AM
12-14-2021 04:18 AM - edited 12-14-2021 04:44 AM
Re: Query: SSMC and log4j vulnerability
Hello @monardo,
This vulnerability was just found last week (9th December 2021 I think). SSMC 3.7.2 is the older release.
As per my news sources, in it's standard form, I don't think SSMC v3.7.2 is vulnerable in a secured network. However, HPE has not confirmed that v3.7.2 is safeguarded from the vulnerability as well. Vulnerability also depends on your network security, other cloud and web application, APIs and other plugins.
I recommend you to get that confirmed by your IT security team.
Regards,
Srinivas Bhat
If you feel this was helpful please click the KUDOS! thumb below!
Note: All of my comments are my own and are not any official representation of HPE.
I work at HPE
HPE Support Center offers support for your HPE services and products when and how you need it. Get started with HPE Support Center today.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-14-2021 04:19 AM
12-14-2021 04:19 AM
Re: SSMC and log4j vulnerability
Yes, please keep us posted. "Looks like the vulnerability is fixed" is not good enough for us, we need to be sure. In the meantime, we shut down the SSMC appliance.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-14-2021 04:54 AM
12-14-2021 04:54 AM
Re: SSMC and log4j vulnerability
Hello @ArjanSchepers,
This notice (URL below) states that 3PAR, Primera, alletra and several other HPE systems are safe from the vulnerability. But doesn't explicitly confirms about the SSMC. I will post it here when I can get that confirmation.
https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=a00120086en_us
Regards,
Srinivas Bhat
If you feel this was helpful please click the KUDOS! thumb below!
Note: All of my comments are my own and are not any official representation of HPE.
I work at HPE
HPE Support Center offers support for your HPE services and products when and how you need it. Get started with HPE Support Center today.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-14-2021 05:03 AM
12-14-2021 05:03 AM
Re: SSMC and log4j vulnerability
3.8.2 is still vulnerable in my testing. I have also heard reports Service Processor is vulnerable although I have not been able to confirm with testing.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-14-2021 05:50 AM
12-14-2021 05:50 AM
Re: SSMC and log4j vulnerability
Yes, I saw this document and it is not totally complete...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-14-2021 06:06 AM
12-14-2021 06:06 AM
Re: SSMC and log4j vulnerability
Got an update that SSMC v3.8.2 is not confirmed as safe against the 'log4j' vulnerability.
The fix for the vulnerability is in progress. But there s a workaround available as well. Please contact HPE support if waiting for the fix is not an option for you.
Regards,
Srinivas Bhat
If you feel this was helpful please click the KUDOS! thumb below!
Note: All of my comments are my own and are not any official representation of HPE.
I work at HPE
HPE Support Center offers support for your HPE services and products when and how you need it. Get started with HPE Support Center today.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-14-2021 10:11 AM
12-14-2021 10:11 AM
Re: SSMC and log4j vulnerability
From what I can tell, SSMC 3.8.2 is patching a completely different CVE (CVE-2021-29214)...I think its release timing of December 9th is what's confusing. I would imagine that 3.8.2 is stil vulnerable to CVE-2021-44228.
vs
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-15-2021 03:47 AM
12-15-2021 03:47 AM
Re: SSMC and log4j vulnerability
Can you please post the workaround? I'm currently juggling around with at least 5 affected products in my organization, I do not have time to contact each supplier individually. We need a public facing website with workarounds, patches or other means of mitigation. Thank you @sbhat09
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-15-2021 04:25 AM
12-15-2021 04:25 AM
Re: SSMC and log4j vulnerability
Hello @ArjanSchepers,
I am not allowed to share the workaround publicly. But the security update patch to address 'log4j' vulnerability is in progress and will be released soon.
Till then you can shut-down the SSMC. Use CLI for important administration tasks.
If that is not an option for you, I can personal message you the steps of temporary workaround.
How do you like to go about this?
Regards,
Srinivas Bhat
If you feel this was helpful please click the KUDOS! thumb below!
Note: All of my comments are my own and are not any official representation of HPE.
I work at HPE
HPE Support Center offers support for your HPE services and products when and how you need it. Get started with HPE Support Center today.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-15-2021 06:15 AM
12-15-2021 06:15 AM
Re: SSMC and log4j vulnerability
Hello @sbhat09 , if you could PM me the workaround instructions, that would be great. Thank you in advance!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-16-2021 06:31 AM
12-16-2021 06:31 AM
Re: SSMC and log4j vulnerability
Hello, would you be able to send me the workaround instructions as well per DM? We shut our SSMCs down, and really need them up.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-16-2021 06:36 AM
12-16-2021 06:36 AM
Re: SSMC and log4j vulnerability
Hello @jvbakel,
Sent it.
Regards,
Srinivas Bhat
If you feel this was helpful please click the KUDOS! thumb below!
Note: All of my comments are my own and are not any official representation of HPE.
I work at HPE
HPE Support Center offers support for your HPE services and products when and how you need it. Get started with HPE Support Center today.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-16-2021 06:37 AM
12-16-2021 06:37 AM
Re: SSMC and log4j vulnerability
Hello @ArjanSchepers ,
Sent it.
Regards,
Srinivas Bhat
If you feel this was helpful please click the KUDOS! thumb below!
Note: All of my comments are my own and are not any official representation of HPE.
I work at HPE
HPE Support Center offers support for your HPE services and products when and how you need it. Get started with HPE Support Center today.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]
