Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Last modified: 2021-12-14

Problem

There’s a are known bug bugs in the Apache Log4j2 library that allows an attacker to perform RCE attack :

...

...

Solution

To patch the vulnerabilities in CVE-2021-44228 and CVE-2021-45046 please update vprotect to the following versions:

...

Instructions on how to upgrade the vProtect are available in the Documentation

The vulnerability CVE-2021-45105 will be patched in the next vProtect release (information in this article will be updated as soon as the fixed has been released) however it’s worth mentioning that this CVE causes a Denial of Service attack which poses a low risk to end-users as vProtect installations should not be exposed to the Internet and as for the moment of writing this article there are no known ways to exploit this vulnerability in vProtect software.