Statements or fixes for CVE-2021-44832
search cancel

Statements or fixes for CVE-2021-44832

book

Article ID: 232128

calendar_today

Updated On:

Products

CA Spectrum

Issue/Introduction

There is a detected vulnerability in Spectrum 21.2.6 which is outline in CVE-2021-44832:

https://nvd.nist.gov/vuln/detail/CVE-2021-44832

Environment

DX NetOps Spectrum Release : 21.2.6

Cause

Vulnerability

Resolution

CVE-2021-44832: NIST : National Vulnerability Database : CVE-2021-44832 Detail

Severity of this vulnerability is not deemed high risk.

  • local system root\administrator access is required for this vulnerability to be exploited.
  • CVE-2021-44832 is fixed in log4j 2.17.1
  • log4j 2.17.1 will be included in release 21.2.8.

Additional Information

NETOPS general : KB : CVE-2021-44228 & CVE-2021-45046: Is DX Netops vulnerable to the Log4J security issue?

SPECTRUM : KB : CVE-2021-44228 & CVE-2021-45046: DX Netops Spectrum log4j vulnerability

PC/DA/DR : KB : CVE-2021-44228, CVE-2021-45046 & CVE-2021-44832: Is DX Netops Performance Management (PM) affected by the Remote code injection in log4j vulnerability?