Security scan reports CVE-2021-44832 on Aria Suite Lifecycle
search cancel

Security scan reports CVE-2021-44832 on Aria Suite Lifecycle

book

Article ID: 418229

calendar_today

Updated On:

Products

VMware vRealize Suite Lifecycle Manager 8.x

Issue/Introduction

A network security scanner reports CVE-2021-44832 on Aria Suite Lifecycle appliance.

For more details on the CVE refer  CVE-2021-44832

Environment

Aria Suite Lifecycle 8.18.x

Cause

Aria Suite Lifecycle 8.18.x appliance has the affected version of log4j*2.17.0.jar file.

Resolution

Take a non memory snapshot of the Aria Suite Lifecycle Manager . 

Navigate to the common-jars directory by executing command - "  cd /usr/lib/vmware/common-jars " . 

Remove the specific version of the log4j jar file by executing command - "  rm log4j*2.17.0.jar " . 

Validate and confirm product functionality. 

Delete the snapshot . 

 

NOTE: There are higher version of " log4j*2.17.1.jar " files and deleting the older  " log4j*2.17.0.jar " doesn't have any impact in production.