cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Re: LOG4J and MWG

Jump to solution

Re: LOG4J and MWG

Jump to solution

Hello,

Continue about Log4J vulnerabilities:


CVE-2021-44228 (CVSS score: 10.0) - A remote code execution vulnerability affecting Log4j versions from 2.0-beta9 to 2.14.1 (Fixed in version 2.15.0) -> FIXED in Version 10.2.5 - OK

CVE-2021-45046 (CVSS score: 9.0) - An information leak and remote code execution vulnerability affecting Log4j versions from 2.0-beta9 to 2.15.0, excluding 2.12.2 (Fixed in version 2.16.0) -> FIXED in Version 10.2.5 - OK

Is MWG affected?
CVE-2021-45105 (CVSS score: 7.5) - A denial-of-service vulnerability affecting Log4j versions from 2.0-beta9 to 2.16.0 (Fixed in version 2.17.0)

Is MWG affected?
CVE-2021-4104 (CVSS score: 8.1) - An untrusted deserialization flaw affecting Log4j version 1.2 (No fix available; Upgrade to version 2.17.0)

 

Any instruction about the mitigate the CVE(s): CVE-2021-4104 and CVE-2021-45106 or any prevision of new release with this corrections?


Best Regards,

 

DSO

Re: LOG4J and MWG

Jump to solution

New CVE-2021-44832.

Do any form of mitigation about this new CVE?

Best Regards

aok71
Level 7
Report Inappropriate Content
Message 14 of 16

Re: LOG4J and MWG

Jump to solution

also the same Question, what about 2.17 ?

Re: LOG4J and MWG

Jump to solution

hi, 10.2.5 fixes the log4j vulnerability problem? that means it is not vulnerable

Re: LOG4J and MWG

Jump to solution

10.2.5 upgraded log4j library version to 2.16.0. This resolved the original Remote Code Execution vulnerability. 

The vulnerabilities associated with log4j discovered after the fact were all deemed to not affect MWG due to the configuration of Java on the system.

Regardless, I'd encourage you to limit WebUI access to those that should have it through Firewall policy.

 

 

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community