Further information is required about implementing mitigation steps for Symantec Endpoint Protection Manager (SEPM) and/or LiveUpdate Administrator (LUA) from SYMSA19793.
Affected version(s)
SEPM 14.3 RU3 build 5427 (14.3.5427.3000) has been released to address these vulnerabilities and is available for download. We recommend all customers migrate their SEPM(s) to this build.
If upgrading immediately is not an option, the following steps can be implemented to mitigate CVE-2021-44228 and CVE-2021-45046 until an upgrade can be completed. Ref. Log4j Security
No SEPM functionality is impacted by implementing these steps. You can revert the System variable as per the steps provided in the additional information below.
SEPM is not impacted. SEPM does not perform context lookup in any of the jars or is the affected log configuration in use.
LUA 2.3.10 which includes log4j build 2.16 to address CVE-2021-44228 is available for download. We recommend all customers migrate their LUAs to this build.
Additional read Symantec Security Advisory for Log4j Vulnerability
LUA is not impacted. LUA's log4J logging configuration does not use Pattern Layout with Context Lookup. ( CVE-2021-45105 )
LUA is not impacted. LUA's usage of log4j does not implement the logging configuration file. ( CVE-2021-44832 )
SEPM is not impacted. SEPM's usage of log4j does not implement the logging configuration file. ( CVE-2021-44832 )
CVE-2020-9488 - No impact as this vulnerability was fixed in Log4J 2.13.1. LUA 2.3.8 onwards Log4J 2.13.2+ is used.
CVE-2019-17571, CVE-2021-4104, CVE-2023-26464, CVE-2022-23302, CVE-2022-23305, CVE-2022-23307 - No impact as LUA 2.3.8 onwards use Log4J 2.13.2+ These vulnerabilities impact Log4J 1.x.
Symantec Security Advisory for Log4j 2 CVE-2021-44228 Vulnerability
Threat Alert: Apache Log4j RCE (CVE-2021-44228) aka Log4Shell
Steps to revert previously mentioned LOG4J_FORMAT_MSG_NO_LOOKUPS System variable mitigation for SEPM or LUA.
[Japanese version] Log4j2 の脆弱性 (CVE-2021-44228, CVE-2021-45046, CVE-2021-45105) に対する管理サーバーと LiveUpdate Administrator の緩和策について