Tag: CVE-2021-44228

VMware Site Recovery Manager is getting patch to resolve CVE-2021-44228 and CVE-2021-45046.

SRM

VMware just published a patch for SRM 8.5.0.2 where Apache log4j is updated to version 2.16 to resolve CVE-2021-44228 and CVE-2021-45046. If you are running Site Recovery Manager 8.5, upgrade to Site Recovery Manager 8.5.0.2. See Upgrading Site Recovery Manager in Site Recovery Manager 8.5 Installation and Configuration for instructions about upgrading Site Recovery Manager. If you use vSphere…

Read more

Additional step for vCenter Server CVE-2021-44228 and CVE-2021-45046 workaround.

vCenter

VMware just updated their KB adding additional step which needs to be run even if someone already did apply workaround. This additional step is to remove all JndiLookup classes per Apache Software Foundation guidance. This step has been automated by script remove_log4j_class.py. NOTE: If you have already completed the steps in this article or used the…

Read more

Workaround instructions to address CVE-2021-44228 and CVE-2021-45046 in vRealize Operations 8.x

Aria Security Advisory

This is most up-to-date document on how to remediate CVE-2021-44228 and CVE-2021-45046. On 15th of December 2021 VMware added workaround steps related to CVE-2021-45046. I will show you how to apply workaround. Please remember this is temporary solution as we are waiting for patch from VMware. RUN LIST: Log into the vRealize Operations Manager Admin…

Read more