I'm using the latest version of Dell Storage Manager (20.1.10.79) and I see some of the log4j components have been updated to the 2.17 version, but there is a still a log4j 1.2.13 jar file present. I realize this isn't the vulnerable 2.x version, but it is long out of support and my info sec team is flagging it.
Is it safe to just delete this jar file, is it a necessary part of DSM? Is there another remediation or workaround for this?
@DELL-Charles R Any update on this fix? This post was over a year ago. Was a patch ever released so that we do not need to mark this as a false positive finding?
The log4j 1.2.13 jar file still present in 20.1.2 that @DELL-Chris H mentions. While this version remediates the log4j vulnerability, it contains this very old file that the OP originally inquired about.
Install the latest version, at the moment it's 20.1.20. I can confirm the log4j 1.2.13 jar is no longer in present and was removed at some point.
DELL-Chris H
7 Practitioner
•
9682 Posts
•
48046 Points
0
1
Posted March 28th, 2024 18:55
Eprise,
Based on the article here, it looks like it was corrected on version 10.1.2.
Let me know if this helps.
DELL-Chris H
Social Media and Communities Professional
Dell Technologies | Enterprise Support Services
#IWork4Dell
Did I answer your query? Please click on ‘Mark as Accepted Answer’. ‘Thumbs up’ the posts you like!