Endpoint Protection Manager service stops running after patching Log4j vulnerability
search cancel

Endpoint Protection Manager service stops running after patching Log4j vulnerability

book

Article ID: 234870

calendar_today

Updated On:

Products

Endpoint Protection

Issue/Introduction

The Symantec Endpoint Protection Manager (SEPM) service fails to start or unexpectedly stops running after executing Log4j vulnerability mitigation or cleanup scripts.

Reviewing the scm-server-0.log may show missing class errors related to org.apache.logging.log4j.

Environment

Symantec Endpoint Protection Manager 14.3 RU3 (Refresh) Build 5427 (and applicable 14.3.x builds)

Cause

During Log4j vulnerability remediation, the required file log4j-core-*.jar was inadvertently removed or quarantined by antivirus/cleanup scripts from the SEPM installation path.

Resolution

Option 1: Restore the missing JAR file

  1. Stop the Symantec Endpoint Protection Manager and Symantec Endpoint Protection Manager API Service services.

  2. Obtain a matching log4j-core-*.jar file from another SEPM server running the exact same version and build.

  3. Copy the file into the following directory: C:\Program Files (x86)\Symantec\Symantec Endpoint Protection Manager\tomcat\lib\

  4. Start both SEPM services and verify console login.

Option 2: Run a Repair installation

  1. Launch the installer package for the exact SEPM version currently installed (14.3 RU3 Refresh Build 5427 or applicable build).

  2. Select Repair when prompted.

  3. Complete the wizard and restart the SEPM server if required.