VM Access Proxy
Snow Software provided guidance regarding the Log4j vulnerability (CVE-2021-44228) on 15th December 2021 and 16th December 2021 based on recommendations from the Apache Software Foundation. This KB includes updated guidance (21 December 2021) based on a new Log4j vulnerability (CVE-2021-45105).
Flaws in Log4j. a key Java-logging framework developed by the open-source Apache Software Foundation, are the most high-profile security vulnerabilities on the internet right now. The two Log4j vulnerabilities reported by cve.mitre.org are as follows:
- CVE-2021-44228 comes with a severity score of 10 out of 10. Snow Software, with many other companies across the globe, became aware of this vulnerability on Friday, December 10, 2021. In response, on 20 December 2021, Snow Software released Commander 8.10.0/8.10.1 and VM Access Proxy 3.6 (versions that included Log4j 2.16.0 that was reported by Apache Software Foundation to address CVE-2021-44228). .
- CVE-2021-45105 comes with a severity score of 7.5 out of 10. Regretfully, Snow Software became aware of this flaw after releasing Commander 8.10.0/8.10.1 and VM Access Proxy 3.6.
Affected Versions and Recommendations
- Affected versions: VM Access Proxy 3.4 through VM Access Proxy 3.6
- CVE record(s): CVE-2021-44228 and CVE-2021-45105
- Snow Recommendation
- Customers should upgrade to VM Access Proxy 3.7 at the earliest opportunity. This version contains Log4j 2.17.0, which the Apache Software Foundation states will address CVE-2021-45105.
Related Articles
Snow Commander - LOG4J2.XML library version used is exposed to VULNERABILITY ( CVE-2021-44228 ) 5Number of Views Validating the VM Access Proxy Configuration 12Number of Views How Are Commander VM Access Proxy Sessions Connected? 8Number of Views Video: VM Access Proxy Installation 9Number of Views Supplementary Steps for Upgrading to Commander VM Access Proxy 3.8 6Number of Views
Hi, I am Reva - Ask me anything.
No new updates
Thanks for the feedback!
Your feedback has been saved.Rate this response:
Add Additional feedback ( Optional )
Are you sure you want to cancel
the case creation?
Are you sure you want to cancel the case creation?
Are you sure you want to close this case
| Products | Region | Phone Numbers |
|---|---|---|
| FlexNet Operations FlexNet Embedded FlexNet Publisher FlexNet Connect FlexNet Code Insight InstallAnywhere InstallShield |
North America * |
+1 630-332-2513 (toll) +1 877-279-2853 (toll-free in North America) |
| Europe * |
+44 1925 944367 (toll) +44 800 047 8642 (toll-free in Europe) |
|
| Japan * | +81 3-4540-5335 (select option 2) | |
| Australia * |
+61 3 9895 2177 +61 1800 560 603 (toll-free in Australia) |
|
|
Usage Intelligence (formerly
Revulytics) Compliance Intelligence |
Please use the Case Portal to submit your support ticket or reach out to your Revenera contact. | |
Case id: 00001065
Activity: Status change: 2 hours ago