Servers - General
1819504 Members
3281 Online
109603 Solutions
New Discussion

CVE-2021-44228 (Apache Log4j vulnerability)

 
Jacques Carriere
Regular Advisor

CVE-2021-44228 (Apache Log4j vulnerability)

Good day,

Does HP have any updates or patches concerning the CVE-2021-44228 (Apache Log4j vulnerability)?

 

Jacques

  

4 REPLIES 4
Stephan G
Regular Advisor

Re: CVE-2021-44228 (Apache Log4j vulnerability)

I also try to get official statements about that. 
As HPE has many software products basing on *unix - i would say. Many affected.
I would say - they are busy trying to find them

Document - Notice: Apache Software Log4j - Security Vulnerability CVE-2021-44228 | HPE Support

I would suspect that HPE Oneview is vulnerable somehow as the search get some hits

hpe oneview "log4j" - Google Suche

 

Sheep1
Regular Visitor

Re: CVE-2021-44228 (Apache Log4j vulnerability)

We would also be interested in whether OneView or ILO are affected by this in any way.

This github page makes it seem like it might be using log4j but not what version:

GitHub - HewlettPackard/oneview-sdk-java: Java SDK for HPE OneView

SanjeevGoyal
HPE Pro

Re: CVE-2021-44228 (Apache Log4j vulnerability)

Hello,

I would suggest you follow the below customer advisory for more clarification.

Notice: (Revision) Apache Software Log4j - Security Vulnerability CVE-2021-44228
https://support.hpe.com/hpesc/public/docDisplay?docId=emr_na-a00120086en_us

If you feel this was helpful please click the KUDOS! thumb below and accept the solution.
Regards,


I am a HPE Employee.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]

Accept or Kudo

techin
Valued Contributor

Re: CVE-2021-44228 (Apache Log4j vulnerability)