Skip to main content

Log4j Vulnerability - Please Post All Questions Here


Show first post

344 replies

Forum|alt.badge.img+8
  • Vaulter
  • 53 replies
  • December 16, 2021
Henke wrote:

I downloaded the report showing what servers may be effected by Log4j, but the result isn’t what I expected.

Is there no result in the report immediately once installed to the webconsole?

//Henke

The report is specific to cloud apps, oracle, and sql where archiving, masking, and table level restore is enabled - since this combo is highest risk.

Simplest approach is to just update all those apps anyway regardless, but the report will help you target into the affected servers.

Webconsole is not affected by this vulnerability so it wont be on the report.


Henke
Byte
Forum|alt.badge.img+13
  • Byte
  • 125 replies
  • December 16, 2021
DMCVault wrote:
Henke wrote:

I downloaded the report showing what servers may be effected by Log4j, but the result isn’t what I expected.

Is there no result in the report immediately once installed to the webconsole?

//Henke

The report is specific to cloud apps, oracle, and sql where archiving, masking, and table level restore is enabled - since this combo is highest risk.

Simplest approach is to just update all those apps anyway regardless, but the report will help you target into the affected servers.

Webconsole is not affected by this vulnerability so it wont be on the report.

 

Ahh that explains. I was confused as I didn’t see any of the servers with SQL agent installed in there, but we don’t have that enabled.

Thanks for the answer.

//Henke


Forum|alt.badge.img

I have hotfix SP24 4550 and 4553 tried to push on the Media Agent Server which has Cloud Apps these are not getting deployed and just says still remediation needed ,any one ran into this issue?

 


Forum|alt.badge.img+5
  • Byte
  • 15 replies
  • December 16, 2021
Jordan wrote:

Hi @JSNOPUD ,

 

Your steps are fine up to here getting 11.21.71 installed onto CS and MA.

 

To get the Log4j hotfix installed, please see the pinned article at the top of this thread. Copying relevant part below:

 

Applying HotFix:

To get the hotfix installed, you’ll need to:

  1. Download the relevant updates in the chart below (depending on what Maintenance Releases you have in your CommCell)
  2. Unzip the contents of the download
  3. Run Copy To Cache to add the new updates to your software cache
  4. Push out updates to the clients

 

Using these steps, you can push out the updates to your clients once CS and MA are on 11.21.71.

 

Just another question for clarification with regards to the clients after CS and MA are upgraded to 11.21.71.

Should I immediately install hot fix “11.21 Log4J-2.16 Fix” right away? If so, does that upgrade the clients to 11.21.71 right away? 

Or should I upgrade the clients to 11.21.71 first, and then install “11.21 Log4J-2.16 Fix” to the clients?


Forum|alt.badge.img+1
Jordan wrote:
Jeremy Fisher wrote:

I received the Log4JAffectedServers.xml file from CV Support.  Does Anyone have instructions as to How to Run the Report to see what servers are Vulnerable in my Environment?  The XML report is Located here: https://cloud.commvault.com/webconsole/softwarestore/store.do#!/135/663/21789

Hi @Jeremy Fisher 

 

You should be able to import this report into your webconsole with the import option:

https://documentation.commvault.com/11.25/essential/97429_importing_report_templates.html

 

Thank you

I get “no records Available”. I have 13 SQL boxes that should be reporting

 

 


Forum|alt.badge.img+2
  • Byte
  • 9 replies
  • December 16, 2021

Apparently, unless you specifically have those options for SQL configured on your agent, nothing shows up, correct? You guys should get some credit for cooking up the report but the feedback could be a little clearer from the report. Just saying. Thanks for all you are doing. 

 


Forum|alt.badge.img
Jeremy Fisher wrote:
Jordan wrote:
Jeremy Fisher wrote:

I received the Log4JAffectedServers.xml file from CV Support.  Does Anyone have instructions as to How to Run the Report to see what servers are Vulnerable in my Environment?  The XML report is Located here: https://cloud.commvault.com/webconsole/softwarestore/store.do#!/135/663/21789

Hi @Jeremy Fisher 

 

You should be able to import this report into your webconsole with the import option:

https://documentation.commvault.com/11.25/essential/97429_importing_report_templates.html

 

Thank you

I get “no records Available”. I have 13 SQL boxes that should be reporting

 

 

Same for me as well.. please see above screenshot.. any help for this please?


Forum|alt.badge.img+1
MathBob wrote:

Apparently, unless you specifically have those options for SQL configured on your agent, nothing shows up, correct? You guys should get some credit for cooking up the report but the feedback could be a little clearer from the report. Just saying. Thanks for all you are doing. 

 

that is what I will assume as well…  

we are not using those options, like this:

 


Forum|alt.badge.img
  • Bit
  • 2 replies
  • December 16, 2021
Krishan Bhatt wrote:
Jeremy Fisher wrote:
Jordan wrote:
Jeremy Fisher wrote:

I received the Log4JAffectedServers.xml file from CV Support.  Does Anyone have instructions as to How to Run the Report to see what servers are Vulnerable in my Environment?  The XML report is Located here: https://cloud.commvault.com/webconsole/softwarestore/store.do#!/135/663/21789

Hi @Jeremy Fisher 

 

You should be able to import this report into your webconsole with the import option:

https://documentation.commvault.com/11.25/essential/97429_importing_report_templates.html

 

Thank you

I get “no records Available”. I have 13 SQL boxes that should be reporting

 

 

Same for me as well.. please see above screenshot.. any help for this please?

 

Hah same thing I came to find an answer to. 


Mike Struening
Vaulter
Forum|alt.badge.img+23

Hi all, thanks for coming here to discuss!

You are all correct.  If the report shows ‘no items to display’ and ‘no data available’, then you are not affected/vulnerable.  Still wise to apply the latest hotfix anyway, because it’s possible someone turns on the feature tomorrow, though I agree, ideally the report’s output should say something clearer.

I think we added that to the original post, though I’ll go make sure.

Edit: it wasn’t, so I added it to the report directions.  thanks everyone for pointing that out!


Mike Struening
Vaulter
Forum|alt.badge.img+23
JSNOPUD wrote:
Jordan wrote:

Hi @JSNOPUD ,

 

Your steps are fine up to here getting 11.21.71 installed onto CS and MA.

 

To get the Log4j hotfix installed, please see the pinned article at the top of this thread. Copying relevant part below:

 

Applying HotFix:

To get the hotfix installed, you’ll need to:

  1. Download the relevant updates in the chart below (depending on what Maintenance Releases you have in your CommCell)
  2. Unzip the contents of the download
  3. Run Copy To Cache to add the new updates to your software cache
  4. Push out updates to the clients

 

Using these steps, you can push out the updates to your clients once CS and MA are on 11.21.71.

 

Just another question for clarification with regards to the clients after CS and MA are upgraded to 11.21.71.

Should I immediately install hot fix “11.21 Log4J-2.16 Fix” right away? If so, does that upgrade the clients to 11.21.71 right away? 

Or should I upgrade the clients to 11.21.71 first, and then install “11.21 Log4J-2.16 Fix” to the clients?

First the Maintenance Release, then the Hotfix pack.  Need both installs and in the right order.

Using Copy to Cache is always best as it does the work for you once you push the updates out through the GUI.


Forum|alt.badge.img+2
  • Byte
  • 9 replies
  • December 16, 2021

We are required to remove all versions of Log4j including v1.x versions. Will removal of the Log4j v1.x jar files manually have any effect on the CommVault environment? 


Mike Struening
Vaulter
Forum|alt.badge.img+23

Hi @MathBob .  Potentially, yes.  If you are all patched up and remediated, you may still see older versions.  We have some older instances in the installed component structure related to the older generation Log4J 1.x files which are not part of the current CVE Log4J 2.x vulnerability. We are doing further investigation on those conditions to determine a course of action. 

You might also see some affected versions in the updates folder because we keep older files for rollback purposes.  We plan to remove these altogether in a future MR to be extra safe.


Mike Struening
Vaulter
Forum|alt.badge.img+23
Laurent Labonte wrote:

Hi,
we have a question, we have applied the last fix for LOG4J but we saw that Commvault use version 2.15
 

but we can read on the web that hte Version 2.15 was most probably enough to protect us from attack but version 2.16 makes it certain !

do you know if Commvault will have rapidly a new fix for us with version 2.16 ?

Moved this over here; you likely already saw we have the 2.16 fix out now.


Forum|alt.badge.img+1
  • Bit
  • 2 replies
  • December 16, 2021

Very useful article guys.  Loved the clarity.    There is a lot of confusion out in the field and a lot of security groups are in panic mode getting fixes implemented.  The Vulnerability Report was a godsend.  Well done.   AMJ


Forum|alt.badge.img
  • Bit
  • 4 replies
  • December 17, 2021
m.rieder wrote:

We have successfully installed the Hotfix for our 11.20.77 environment. In the Java Console the applied hotfixes are shown as expected:

But when we perform a scan for vulnerable log4j files, by using the command line utility form lunasec (https://www.lunasec.io/docs/blog/log4j-zero-day-mitigation-guide/), the affected file gets still determined under the following path: "C:\Program Files\Commvault\ContentStore\Updates\SP20-HotFix-4560\GxHomeDir\Base\DbJars\DbArchiveEngine.jar"

Is that an expected situation?

Regards,
Matthias

 

We are also seeing this DBArchiveEngine.Jar here C:\Program Files\Commvault\ContentStore\Base\DbJars\DbArchiveEngine.jar after patching and our security team is concerned; did dev ever answer back regarding this?

 


Forum|alt.badge.img+11
  • Vaulter
  • 135 replies
  • December 17, 2021

Hi @BHorner , @m.rieder ,

 

This path here is where CV stores the older binaries that are replaced by a hotfix. Please ignore these are these files are essentially dormant and will be deleted during the next full MR pack install. It is only showing up because loose hotfixes automatically copy/save the old replaced filers “just in case”. 

These files should be of no concern as no process / code will call upon this to be actively run. 

 

Thank you

 


Forum|alt.badge.img
  • Bit
  • 1 reply
  • December 17, 2021

Hello! I am on FR 11.24 MR 23. Is the fix included in the MR 25 if I update to it ? Or do I still need to apply the fix.


Forum|alt.badge.img+15
mciobanu wrote:

Hello! I am on FR 11.24 MR 23. Is the fix included in the MR 25 if I update to it ? Or do I still need to apply the fix.

Hi @mciobanu 

The Log4J Fixes have not yet been rolled up into an MR, this is happening very soon and should be released by Dec 24th.

Until MR is provided containing these hotfixes, you will need to apply the hotfixes from 11.24 Log4J-2.16 Fix additionally.

Thanks,

Stuart


Forum|alt.badge.img+15
  • Byte
  • 386 replies
  • December 17, 2021

hi @mciobanu 

For the moment, you need to apply the fix even if you update from MR23 to MR25, as it’s not included in it.


Fernando Souza
Byte
Forum|alt.badge.img+13

Hello @Mike Struening 

The output of the report:
 

 

 


Forum|alt.badge.img+15

Hi @Fernando Souza 

Thanks for highlighting this one, we have updated the FAQ section at the top of the page - please keep checking back regularly as we’re updating the page with all the latest info!

Q: Why does the report show No Data Available or No Items to Display?

A: This means there are no affected clients in this CommCell

Thanks,

Stuart


Forum|alt.badge.img
  • Bit
  • 4 replies
  • December 17, 2021

I can’t log in to the cloud-thing (we never used it and don’t use it).Please provide Update without “Cloud” ASAP. Thx.


Forum|alt.badge.img+15
  • Byte
  • 386 replies
  • December 17, 2021
zahni wrote:

I can’t log in to the cloud-thing (we never used it and don’t use it).Please provide Update without “Cloud” ASAP. Thx.

‘Hi’

Well, then go to your Maintenance Advantage/Support and open a case, at least they’ll provide a download link for your version.

But, yes, maybe a temporary download link from the ‘downloadable’ ESD page would help (from this one: )

https://ma.commvault.com/ESD?fv=11.0  


Forum|alt.badge.img
  • Bit
  • 4 replies
  • December 17, 2021
Laurent wrote:
zahni wrote:

I can’t log in to the cloud-thing (we never used it and don’t use it).Please provide Update without “Cloud” ASAP. Thx.

‘Hi’

Well, then go to your Maintenance Advantage/Support and open a case, at least they’ll provide a download link for your version.

But, yes, maybe a temporary download link from the ‘downloadable’ ESD page would help (from this one: )

https://ma.commvault.com/ESD?fv=11.0  

There is no Log4J fix. Latest build is from Dec 7:

https://ma.commvault.com/HotfixPacks?fv=11.0&sp=20

Today, I had installed 11.20.77 .


Reply


Cookie policy

We use cookies to enhance and personalize your experience. If you accept you agree to our full cookie policy. Learn more about our cookies.

 
Cookie settings