
Solved!
Go to SolutionDell Storage Manager Client log4j 1.2.13
I'm using the latest version of Dell Storage Manager (20.1.10.79) and I see some of the log4j components have been updated to the 2.17 version, but there is a still a log4j 1.2.13 jar file present. I realize this isn't the vulnerable 2.x version, but it is long out of support and my info sec team is flagging it.
Is it safe to just delete this jar file, is it a necessary part of DSM? Is there another remediation or workaround for this?
Thanks
Responses (0)
Solutions (0)
