Support Tip: CVE-2021-44228 & CVE-2021-45046 log4j vulnerability for Micro Focus classic CMS


A potential vulnerability has been identified in the Apache log4j library used by Micro Focus classic Universal CMDB and Universal Discovery Probe.

The vulnerabilities could be exploited to allow remote code execution.
CVE References: CVE-2021-44228, CVE-2021-45046

SUPPORTED SOFTWARE VERSIONS (ONLY impacted versions are listed):
Micro Focus Universal CMDB and Universal Discovery Probe – versions
2021.11, 2021.05, 2020.11, 2020.08, 2020.05, 2020.02, 2019.11, 2019.05, 2019.02, 2018.11, 2018.08, 2018.05, 11.0

Note: in all versions, CMS UI (UCMDB Browser), UD Agent, Scanner, SSA, CMS Gateway and Local Client components do not use a version of log4j that has these vulnerabilities, or do not use log4j, so no remediation action needed for these components.

Read the full support tip here.

Jessica Roth

Micro Focus Community Manager
If this answered your question, please mark it as "Suggest as Answer" or "Verify as Answer".
If you found this post useful, please give it a "Like".


Support Tip
Comment List
Related Discussions