StoreVirtual Storage
1850762 Members
3708 Online
104055 Solutions
New Discussion

Re: Log4J version 1.2.15 with StoreVIrtual UI

 
adamdb_uk
Frequent Advisor

Log4J version 1.2.15 with StoreVIrtual UI

Hi all,

          our security scanning teams have recently flagged HP Storevirtual UI as having out-dated log4j code within it.

C:\Program Files (x86)\HP\StoreVirtual\UI\UI_lib\log4j-1.2.15.jar

According to the log4j update site @ HPE StoreVirtual is either being checked or not vulnerable however this is not going to wash with our security team. Can anyone advise on the status of log4j with Storevirtual. Is this jar actually used? 

Any advice appreciated.

 

thanks.

2 REPLIES 2
support_s
System Recommended

Query: Log4J version 1.2.15 with StoreVIrtual UI

System recommended content:

1. Notice: (Revision) Apache Software Log4j - Security Vulnerabilities (CVE-2021-44228, CVE-2021-45046, CVE-2021-4104, CVE-2021-45105, CVE-2021-44832)

 

Please click on "Thumbs Up/Kudo" icon to give a "Kudo".

 

Thank you for being a HPE valuable community member.


Accept or Kudo

sbhat09
HPE Pro

Re: Log4J version 1.2.15 with StoreVIrtual UI

Hello @adamdb_uk.,

HPE's log4j notice listed StoreVirtual as 'not affected' by the vulnerability. So, can you please update to the latest version and check with your security team again later?

Regards,
Srinivas Bhat

If you feel this was helpful please click the KUDOS! thumb below!
Note: All of my comments are my own and are not any official representation of HPE.



I work at HPE
HPE Support Center offers support for your HPE services and products when and how you need it. Get started with HPE Support Center today.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]
Accept or Kudo