Application Delivery Management
Application Modernization & Connectivity
CyberRes
IT Operations Management
A critical vulnerability (Log4shell - CVE-2021-44228 / CVE-2021-45046 / CVE-2021-45105) have been identified in Log4j, a logging library used with-in ZENworks and hundred of thousand applications across the globe. An exploitation of these vulnerability allows a malicious user to remotely execute code on a vulnerable device. Micro Focus is taking immediate steps to mitigate it across its products. A statement out lining the response is available here.
This vulnerability can be mitigated by making some file changes and setting up of some environment variables across devices. The fix for this vulnerability for ZENworks Products is now available and is detailed here. Given the severity of vulnerability, Micro Focus recommends immediate fixing of this vulnerability.
Updated - 24th Dec -2021
A consolidated patch/FTF for ZENworks, fixing all the Log4j vulnerabilities is now available.
Top Comments
See also Service Desk 8.2.1 affected by log4j? community.microfocus.com/.../service-desk-8-2-1-affected-by-log4j
See also Is Micro Focus Desktop Containers Impacted by the Log4j vulnerability? community.microfocus.com/.../is-micro-focus-desktop-containers-impacted-by-the-log4j-vulnerability