HPE 3PAR StoreServ Storage
1833776 Members
2062 Online
110063 Solutions
New Discussion

SSMC and log4j vulnerability

 
SOLVED
Go to solution
aireynol
Valued Contributor

Re: SSMC and log4j vulnerability

Please PM it to me also.

Alex781
Occasional Visitor

Re: SSMC and log4j vulnerability

Hi,
we still use the old windows software based SSMC 3.3.1 which seems also to be affected by log4j issue.
Is there any chance that HPE will provide an update or at least a workaround for this old version, or do we need to migrate to the SSMC VM appliance?
Thx & regards
Alex

karla87
Occasional Visitor

Re: SSMC and log4j vulnerability

Hello @sbhat09

Could you please PM me the workaround as well. 

Thanks for your help!

sbhat09
HPE Pro

Re: SSMC and log4j vulnerability

Hello @aireynol @karla87 

Sent it.

Regards,
Srinivas Bhat

If you feel this was helpful please click the KUDOS! thumb below!
Note: All of my comments are my own and are not any official representation of HPE.



I work at HPE
HPE Support Center offers support for your HPE services and products when and how you need it. Get started with HPE Support Center today.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]
Accept or Kudo
jeff07
Occasional Visitor

Re: SSMC and log4j vulnerability

Hi Srinivas, can you please share the workaround via PM?  Thanks!

todayishere
New Member

Re: SSMC and log4j vulnerability

Hello @sbhat09 

Could you please PM me the workaround as well. 

Thanks for your help!

RobertoStagno
Occasional Visitor

Re: SSMC and log4j vulnerability

Hi Srinivas @sbhat09 ,

would you be so kind as to pm me the workaround please ?

 

Thank you very much.

thedudeperson
Visitor

Re: SSMC and log4j vulnerability

@sbhat09 ,

Could you pm me the workaround as well?  Thanks.

Cpartipilo
Regular Visitor

Re: SSMC and log4j vulnerability

@sbhat09  please share the workaround via PM to keep handy in case the permanent fix takes longer than planned.  I have powered off my SSMC as precaution for now..

sbhat09
HPE Pro

Re: SSMC and log4j vulnerability

Hello @jeff07 @todayishere @RobertoStagno @thedudeperson @Cpartipilo @andrewk4 @Rob785 

I sent it.

Regards,
Srinivas Bhat

If you feel this was helpful please click the KUDOS! thumb below!
Note: All of my comments are my own and are not any official representation of HPE.



I work at HPE
HPE Support Center offers support for your HPE services and products when and how you need it. Get started with HPE Support Center today.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]
Accept or Kudo
ptheile
HPE Pro

Re: SSMC and log4j vulnerability

I would like to have the workaround as well, please PM.

Peter

 

GeirTK
Member

Re: SSMC and log4j vulnerability

@sbhat09 ,

Please PM me the workaround. Thank you.

sbhat09
HPE Pro

Re: SSMC and log4j vulnerability

@GeirTK @ptheile 

I sent it.

Regards,
Srinivas Bhat

If you feel this was helpful please click the KUDOS! thumb below!
Note: All of my comments are my own and are not any official representation of HPE.



I work at HPE
HPE Support Center offers support for your HPE services and products when and how you need it. Get started with HPE Support Center today.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]
Accept or Kudo
badmuds
New Member

Re: SSMC and log4j vulnerability

Hi Srinivas,

can you please send me the workaround
Thans in advance,

Twan

sbhat09
HPE Pro

Re: SSMC and log4j vulnerability

As per the latest update, the workaround is not completely sufficient. Now the Early Access (EA) to SSMC update version 3.8.2.1 is available on request.
It is not available yet for download. If it is very urgent, you can contact HPE support with a support case. For that HPE support contract is a must.
General Availability (GA) of the SSMC update (the version name may change) is expected soon.

Regards,
Srinivas Bhat

If you feel this was helpful please click the KUDOS! thumb below!
Note: All of my comments are my own and are not any official representation of HPE.



I work at HPE
HPE Support Center offers support for your HPE services and products when and how you need it. Get started with HPE Support Center today.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]
Accept or Kudo
AerCapTeam
New Member

Re: SSMC and log4j vulnerability

Hi @sbhat09 ,

Can we get PM with solution, please.

Regards,

Alan

sbhat09
HPE Pro
Solution

Re: SSMC and log4j vulnerability

GREAT NEWS!

The latest SSMC update version 3.8.2.1 is available for download - https://myenterpriselicense.hpe.com/cwp-ui/free-software/SSMC_CONSOLE

Regards,
Srinivas Bhat

If you feel this was helpful please click the KUDOS! thumb below!
Note: All of my comments are my own and are not any official representation of HPE.



I work at HPE
HPE Support Center offers support for your HPE services and products when and how you need it. Get started with HPE Support Center today.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]
Accept or Kudo
BBARBAROS
Advisor

Re: SSMC and log4j vulnerability

Do you know any upgrade issues/ problems about 3.82 or 3.8.2.1 ?

I`ve got 3.8.1 but no matter what I tried I cannot upgrade to 3.8.2.1...Package uploads, I start the upgrade but ssmc never reboots, it stays at 3.8.1  

sbhat09
HPE Pro

Re: SSMC and log4j vulnerability

Hello @BBARBAROS,

That is strange though. Please ensure your system meets all the resource/networking/port/firewall requirements to install SSMC v3.8.2.1.

Is there any error you noticed after installing v3.8.2.1? What are the OS versions of the SSMC connected 3PAR systems? Can you please try to create a new VM and freshly instal the v3.8.21?

Regards,
Srinivas Bhat

If you feel this was helpful please click the KUDOS! thumb below!
Note: All of my comments are my own and are not any official representation of HPE.



I work at HPE
HPE Support Center offers support for your HPE services and products when and how you need it. Get started with HPE Support Center today.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]
Accept or Kudo
BBARBAROS
Advisor

Re: SSMC and log4j vulnerability

3.8.2 and 3.8.2.1 are security updates installed on 3.8.0, not fresh installations.

I upgarded to 3.8.1 with no problem.

I don`t get any errors for 3.8.2/3.8.2.1. The upgrade process runs but nothing happens.

andrewk4
Frequent Visitor

Re: SSMC and log4j vulnerability

Successfully upgraded to 3.8.2.1.9 (upgraded from 3.8.2.0.39) without issue.

Download .iso, log into SSMC admin and Upgrade with .star file

Is there any confirmation that 3.8.2.1 fixes the log4j vulnerability? I could not find any detailed release notes. Do we need to redo or undo anything if we had applied the workaround?

Thanks

Re: SSMC and log4j vulnerability

Customers who have implemented the configuration change to mitigate the issue, which later were found to be incomplete do NOT need to revert anything. Upgrading to SSMC 3.8.2.1 fully fixes the reported issue.

Note that the version reported in the lower right corner after the upgrade will show "3.8.2.1.9"

 



I work at HPE
HPE Support Center offers support for your HPE services and products when and how you need it. Get started with HPE Support Center today.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]
Accept or Kudo
sbhat09
HPE Pro

Re: SSMC and log4j vulnerability

Hello @andrewk4,

My source of information (from developers) confirmed that SSMC 3.8.2.1 or above is safe against the current log4j vulnerability.

Though the release notes don't mention directly, it states that "the version includes important security fixes and adhere to NIST SP 800-53 guidelines". Please check the details of the guidelines for additional details.

Regards,
Srinivas Bhat

If you feel this was helpful please click the KUDOS! thumb below!
Note: All of my comments are my own and are not any official representation of HPE.



I work at HPE
HPE Support Center offers support for your HPE services and products when and how you need it. Get started with HPE Support Center today.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]
Accept or Kudo

Re: SSMC and log4j vulnerability

SSMC with version 3.3.1 running as a service on windows is most likly impacted.

You should move to the appliance model and run with the latest version.

Note that the development of SSMC for windows has stopped with version 3.3.1 in April 2018.

Since then, no further fixes were implemented and the version therefore most likly has other missing security fixes as well.

HPE always recommends to update to the latest version,, or solution..

Hope that helps 

 



I work at HPE
HPE Support Center offers support for your HPE services and products when and how you need it. Get started with HPE Support Center today.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]
Accept or Kudo
areus
Occasional Visitor

Re: SSMC and log4j vulnerability

And how can we move to the appliance model? I've inherited the administration of a 3PAR system and need to keep it running, but I have no idea how to replace the current SSMC with the latest SSMC that HPE is offering. Please advise.