Unsolved

2 Intern

 • 

222 Posts

3231

December 14th, 2021 05:00

log4j question

Hi,

On 4 of our servers we can see that OpenMange using log4j-1.2.13.jar en log4j-core-2.3.D1.jar

How can we mitigate this issue? how can we patch this problem?

I try to see if there is an update available for e.i poweredge R640, but cannot find any relevent security patch!

Thanks

2 Intern

 • 

222 Posts

December 14th, 2021 06:00

Sorry, it looks like the Log4j is related to Storage manger of Our SAN and not Open manage. still question remining is, is there any patch for this product?

Thanks 

4 Operator

 • 

2.9K Posts

December 14th, 2021 09:00

The issue was discovered on 12/10 and is being evaluated in our product portfolio, at this point in time. The NIST website has mitigation steps hosted on their page, but there is no software patch available yet.

 

The second provided link is a Dell article with additional information, including affected products, unaffected products, and those currently under review. There is also a link to the Dell Security Advisory page, which will provide more information as it becomes available.

 

https://dell.to/3m5aOh3

 

https://dell.to/3m5aOO5

2 Intern

 • 

222 Posts

December 14th, 2021 10:00

thanks for update,

Dell affected procduct documents says that Storage Center is not affected, we are usein Dell EMC storage center client to manage our SAN, is this the same as storage center?

Thanks

4 Operator

 • 

2.9K Posts

December 14th, 2021 12:00

I believe it is the same product, yes. The only other product with a similar name that I can think of is the Compellent Storage Center OS. 

1 Message

December 15th, 2021 06:00

Storage Center is the OS running on Compellent SANs. Storage Manager is the application used to connect to and manage Compellent SANs. They are two separate products. Storage Center has been confirmed to be unaffected.

To my knowledge Dell has not released information on Storage Manager but it does appear to have the affected version of log4j. We've removed the class manually while we wait for official guidance/patching from Dell.

2 Intern

 • 

222 Posts

December 22nd, 2021 07:00

Hi, Thank you for your reply, we have Storage manager client on some of our servers and I can see that Dell still did not come up with any patch. How did you remove the class manually for this product?

Thanks

No Events found!

Top