VMware just published a patch for SRM 8.5.0.2 where Apache log4j is updated to version 2.16 to resolve CVE-2021-44228 and CVE-2021-45046. If you are running Site Recovery Manager 8.5, upgrade to Site Recovery Manager 8.5.0.2. See Upgrading Site Recovery Manager in Site Recovery Manager 8.5 Installation and Configuration for instructions about upgrading Site Recovery Manager. If you use vSphere…
Read moreTag: CVE-2021-44228
Additional step for vCenter Server CVE-2021-44228 and CVE-2021-45046 workaround.
VMware just updated their KB adding additional step which needs to be run even if someone already did apply workaround. This additional step is to remove all JndiLookup classes per Apache Software Foundation guidance. This step has been automated by script remove_log4j_class.py. NOTE: If you have already completed the steps in this article or used the…
Read moreWorkaround instructions to address CVE-2021-44228 in Site Recovery Manager
As we are still waiting for patch to be released, here is a workaround provided by VMware which need to be applied to Site Recovery Manager. Run list: Make sure SSH access is enabled (appliance at 8.3 or newer) Login to SRM Appliance Manager Interface as admin Click ACCESS In the SSH pane, click Enable…
Read moreWorkaround instructions to address CVE-2021-44228 and CVE-2021-45046 in vRealize Operations 8.x
This is most up-to-date document on how to remediate CVE-2021-44228 and CVE-2021-45046. On 15th of December 2021 VMware added workaround steps related to CVE-2021-45046. I will show you how to apply workaround. Please remember this is temporary solution as we are waiting for patch from VMware. RUN LIST: Log into the vRealize Operations Manager Admin…
Read more