Log4j Vulnerability - Please Post All Questions Here



Show first post

344 replies

Userlevel 6
Badge +15

Just a quick tip for those who are using the Java Console and aren’t sure what version / feature release / maintenance release they have installed.. you can confirm by right clicking the client machine (or Commserve/MediaAgent) > properties > version tab 

 


In the above example, 11 = version, 20 = feature release (previously known as service pack), 77 = maintenance release.

You can also view multiple / all your clients from the ‘client computer’ list as per this example:
 

Official Link is here: https://documentation.commvault.com/11.24/expert/2669_viewing_feature_release_details_for_one_or_more_clients.html

 

Badge

Great write up.

Badge

Do we need to apply this hotfix to all Media agents and client servers as well.

 

How to identify the affected clients.?

How to do push install to all clients/media agents if required to install

Userlevel 5
Badge +11

hi @Santhosh Kumar Sathyanarayanan ,

 

MA’s is not needed unless it is on an FR/MR pack that is quite old as it is not recommended to run jobs where clients have higher patch level than MA/CS.

 

Please see top post here on how to identify impacted clients and push install. Basically these would be only the three agents. 


• Cloud Apps package
• Oracle agent - Database archiving, data masking, and logical dump backup
• Microsoft SQL Server agent - Database archiving, data masking, and table level restore

Userlevel 4
Badge +14

Hello Team,

 

Thanks for all of these details ! It helps us a lot !

 

I have Actually :

  • 5 sites freshly updated last month from 11.22.27 to 11.24.7
  • A master site that is still on 11.22.27 (1 Commserve + Commserve DR on AWS + backup AWS)

For the sites that are on 11.24.7, I uderstand that I need to to deploy the maintenance release below on the Commserve. Then copy it to cache with also the Hotfix, then deploy update from the cache all clients.

if the client is not using SQL server agent or Oracle or Cloud Apps is it a problem if I deploy it ?

11.24

11.24.23

11.24 Log4J Fix

 

For the master site Should I follow the same step ? Upgrade from 11.22.27 to 11.24.7, deploy the maintenance release 11.24.23 etc ….

 

Thanks for your help !

 

Badge

It has been clarified in a previous comment that the 11.20 Log4JFix update doesn’t need to be installed on the Media Agents. Does the 11.20 Log4JFix update need to be installed on the Commserve ?

Userlevel 7
Badge +15

Hi @Bloopa , @Mohit Srivastava 

The minimum MR level needs to be deployed to the Commserve to bring the Commserve up to that level, the the log4j hotfixes deployed to affected clients.

If the hotfix is deployed to all clients or some client that isn’t exposed, the hotfix will simply execute, determine no updates apply and exit. So there’s no impact if this fix is deployed to unaffected clients.

In fact this is true of all hotfixes, if they don’t apply to the targeted client, the hotfix installer will tell you no updates apply to this system and then exit.

The Commserve and Media Agents aren’t affected by log4j as they do not have those packages present in their installations. Commserve simply needs to be updated to the minimum level to facilitate push updates to all other clients.

Thanks,

Stuart

Badge

Thanks @Stuart Painter <Removed Incorrect Statement to Avoid Confusion>

Userlevel 6
Badge +15

Hi and thanks for this discussion and explanations so far.:thumbsup:

I may ask a dumb question :nerd: , but.. 

If I only have SQL agents that are only used to perform backups, but not used for archiving, data masking, and no table level restore, then do I need to deploy the hotfix on each server where a SQL agent is deployed ?

Userlevel 7
Badge +15

Hi @Mohit Srivastava 

[Edited]

Please follow the guidance as published at the top of this thread: update to the minimum (or higher) MR for your environment, and then apply Log4j fixes as published to affected clients.

Thanks,

Stuart

Userlevel 7
Badge +15

Hi @Laurent 

Thanks for your perfectly reasonable question :nerd:

SQL Agents not using the identified features may not be as exposed to the log4j vulnerability, but the packages may still be found on those systems. These hotfixes will help clean those up by removing affected packages.

So, the best advice right now is to apply the hotfixes on any potentially affected clients.

Thanks,

Stuart

Badge

Thanks @Stuart Painter ,I’ve deleted my previous statement to avoid any confusion to others. Our Commvault environment is already on 11.20.82. Do we just need to copy software updates from 11.20 Log4J Hotfix to cache and push to Oracle/SQL clients ?

Userlevel 6
Badge +15

Thanks @Stuart Painter 

So, I understand and acknowledge that until this fix is applied, I would remain exposed to this vulnerability, if used by another exploitation that would find this log4j in the commvault folders.

I’m pondering the urge to download and push the fix, while I’ve just upgraded last thursday to 11.24.23 and today to 11.24.25, and perform another update session on my servers, quite exhausting as I have technical and environmental constraints that prevent me from just pushing the updates to all the clients. 

I have to update hundreds of servers like ten by ten, depending on locations, bandwidth, activity (as probably the most of us do have to :smiley: ). 

So I forwarded the threat details to my security team and am waiting for advice from them to push that hotfix, or maybe wait for next FR24.hp26 to be released tomorrow that would potentially include this fix.. Yes, no guarantee for this, I can still dream of it :wink:   

Userlevel 3
Badge +11

My Commserve doesnt have SQL or Oracle iDA installed and is at version 11.24.21 . I dont want to patch my CS as it will involve downtime , i will install MR 11.24.23 + log4jfix patch only on all my oracle and SQL clients . Let me know if this approach is correct ?

Userlevel 7
Badge +15

Hi @Mohit Srivastava 

Thank you for clearing up the posts.

Minimum version for SP20 is 11.20.77, as you are already above this and running 11.20.82, copying the Log4j hotfixes to the cache and deploying to clients is your next step.

Thanks,

Stuart

 

 

Userlevel 7
Badge +15

Hi @Mohit Chordia 

Ideally, updating Commserve first is best practice, but if you need to avoid the downtime, patching clients separately in the meantime  will be fine.

Please remember to loop back and update the Commserve when you can arrange the downtime.

Thanks,

Stuart

Badge

Hello!

Is V10 SP 15 also impacted ? CommServe , Media Agents and Clients included ..

Which version of LOG4J is used by V10 SP15 please ?

Thanks

Userlevel 7
Badge +15

Hi @Libor 

Support for V10 ended in December 2017, so no new hotfixes will be provided for V10 beyond SP15.

Log4j versions affected by this vulnerability are 2.0-2.14. Apache have provided a fix for this vulnerability in 2.15.

Thanks,

Stuart

Userlevel 2
Badge +9

Will Commvault release a general MR containing this fix, and when is it expected?

Regards.

Badge

Hi @Libor 

Support for V10 ended in December 2017, so no new hotfixes will be provided for V10 beyond SP15.

Log4j versions affected by this vulnerability are 2.0-2.14. Apache have provided a fix for this vulnerability in 2.15.

Thanks,

Stuart

Understand but i am not asking for hot fix or so. I am asking if V10 SP15 is impacted by

CVE-2021-44228.

Also i would like to know which log4j version is used in  V10 SP15 ?

I would like to know this so i can be aware of possible risk and maybe to apply some workarounds because our environment does not allow update to higher version ATM.

Thank You!

We are currently running 11.20.82. We have around 120 SQL agents that are currently vulnerable. Would you be able to confirm if we can push out the fix to these clients as it would save us hours of additional work.

Badge +1

Hello,

If we have Cloud Apps should we install fix on access node?

Badge

Hello,

I run this update: v11SP24_Available_HotFix4552_WinX64 and the wizard close some services ans after around a 1 minute, the wizard close with no message and nothing.

What I need to do?

Thank you

Badge +4

Hello @JSNOPUD @Jordan 

Customer is having below queries on the Vulnerability..


-- Commserv and Media agents are not affect by this Vulnerability?
-- After extracting the package customer is seeing 2 packages, which package they need to choose for installing (HOTFIX3911, HOTFIX3913)

-- After installing how can we confirm the hotfix is applied? We can check in the Version of the client Machine but is there any other way to check

 

 

 

Badge

We are currently running 11.20.82. We have around 120 SQL agents that are currently vulnerable. Would you be able to confirm if we can push out the fix to these clients as it would save us hours of additional work.

I’d like to second this, please can you confirm the above?

Reply