
- Owner
Austin Grimes to Bryan Hutchison


Amit Aggarwal (Flexera Software)
Flexera Cloud Migration and Modernization has upgraded the OS for RN150 and FlexDeploy to Debian 12. The VMware images based on Debian 12 are now available for download.
Documentation :
Cloud Migration and Modernization: 2022 Q1 Release Summary
What’s in this release? Cloud Migration and Modernization has released 5 significant improvements to the Cloud Migration platform (formerly RISC) in Q1 2022, which consist of:
What’s in this release? Cloud Migration and Modernization has released 4 significant improvements to the Cloud Migration platform (formerly RISC) in Q3/Q4 2021, which consist of:
Summary
A high severity (CVSS score 8.1) vulnerability in Apache Log4j 1.2 has been publicly disclosed. The vulnerability has been assigned the identifier CVE-2021-4104. This Apache Log4j component is included in in the RISC Platform releases prior to SAAS-2021-12-29.
Additionally, two vulnerabilities with the identifiers CVE-2021-41527 and CVE-2021-41528 related to the User Interface have been addressed.
This article describes the potential impact of the vulnerabilities on the RISC Platform.
Vulnerability descriptions
CVE-2021-4104The National Vulnerability Database describes the CVE-2021-4104 vulnerability at https://nvd.nist.gov/vuln/detail/CVE-2021-4104 as follows (current as of Jan 20, 2022):
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-44228. Note this issue only affects Log4j 1.2 when specifically configured to use JMSAppender, which is not the default.
CVE-2021-41527An error related to the 2-factor authorization (2FA) can potentially be exploited to bypass the 2FA. The vulnerability requires that the 2FA setup hasn’t been completed.
CVE-2021-41528An error when handling authorization related to the import / export interfaces can potentially be exploited to access the import / export functionality with low privileges.
Mitigation options
Additional information
Flexera would like to thank Robert Gilbert (amroot) (https://www.linkedin.com/in/robertgilbert808 ) for helping to identify the vulnerabilities with the identifiers CVE-2021-41527 and CVE-2021-41528 under a responsible disclosure process.

0_K Bussey (Flexera Software)
Users can create customized business cases that include:
This will help build a complete picture of your future in cloud.
The question you should ask yourself is how big is that pie slice in your environment?
Daily we are now tagging servers with their performance profile based on several key metrics collected.
You’ll be able to see where you’re at operational risk from servers performing poorly and where you can find savings by retiring devices.
Request a Demo Executive SummarySummarize and Illuminate What's Important.Our new Executive Summary report samples data and visualizations from across the platform to produce a single, presentable, user experience. Now you can take users on a quick tour of the platform and the value streams it provides by putting the analysis front and center.
The report can be used in conjunction with your own analysis done in the new Cloud Cost Views, Total Cost of Ownership, and the Migration Scorecard. In this way you can produce customized presentations to send on to any interested executive sponsor.

0_K Bussey (Flexera Software)
New features designed to get you better data faster.
We're shipping new features to help prioritize migration and modernization opportunities, enrich geolocation details, and streamline the creation of deliverables for stakeholders.
Request a Personalized Demo Optimization ScorecardModern IT environments have scaled to the extent that human sorting and prioritization techniques are falling short. We put our team to work creating a new scorecard that will take many criteria of an IT estate and your input on the relative importance of those criteria and produce a priority list for whatever decisions you're trying to make.
Especially for solution providers and enterprises planning for cloud migration, they can now create a prioritized migration roadmap/plan in minutes. In addition to cloud migration, this feature will allow users to identify opportunities for containerization.
With the Optimization Scorecard, users can:
We've been listening to our users and understand there's a need for organizations to show increased value to executives. Many users were building business cases and summaries for various stakeholders in their organizations and we wanted to make that easier. Now, with a single click you can download a PowerPoint containing detailed metrics about an application stack.
No more taking screenshots and compiling tables into something that's presentable. No more reliance on formatting or exporting Excel sheets. Just press "Download Summary" and you'll be able to open and edit your PowerPoint directly, the way you want it.
Application Summary Exports will enable:
Stay tuned!
Expansion of this feature is coming later this year. What would you like to see in Application Summary Exports? Submit feedback to our team here .
Demo Summary Exports Reserved Instance PricingMany of our users have asked for Reserved Instance pricing to better understand spend in cloud and build business cases. Due to this request, we are adding 1 and 3 year RIs for both AWS and Azure US East region.
Our team is currently heads down on a complete revamp of many of our cloud pricing features, so while this is a small step, it will become a giant leap for our CloudScape module!
Geolocation was one of the most popular features in our Balsam release. We received a lot of feedback on how to make it better and we're happy to announce that we have.
Users can easily see all of their geolocated IPs, filter, and find associated flow data with just a few button clicks.
Check out Geolocation
0_K Bussey (Flexera Software)
The power of discovery lies not in confirming what you know, but in understanding what you don't know. Modern IT environments are incredibly complex. Getting the data you need quickly and surfacing mission critical obstacles is paramount to success.
Our team has been heads down over the past quarter making it easier for you to sift through the noise, deliver brand new lines of analysis and visualization, and keep your environment more secure.
Introducing our Balsam Release.
This update includes features to improve discovery, prioritize security threats, and give you the tools to align IT with the business.
Connect with Customer Success Request a Personal Demo Click the links below to learn more about each featureSecurity Module New Dashboard Enhanced Asset Discovery Security ModuleInformation without context is just data. Many platforms can deliver you data, we place that data in context.
There is a big difference between:
"“My server is connecting to anonymous proxies.”
-and-
“My HR department’s employee database is connecting to anonymous proxies, and Sara owns it.”
"We are passionate about delivering meaningful insights to our users. Our new Security Module combines with the context of applications, business services, and departments to make your data actionable.
We now integrate into the NIST and CIS OVAL CVE repositories. This enables us to determine vulnerabilities on Linux packages (RHEL, SUSE, Debian, Ubuntu, Oracle, and CentOS).
GeolocationAll incoming and outgoing internet connections will be mapped globally. Understand where your users are, and if they are accessing your applications from high-risk areas or anonymous proxies.
Threat Levels & ReportsAlong with a new page for the Threat data, we are introducing a way to rank and prioritize servers in the environment based on their behaviors. E.g. Servers that have existing CVEs with a network attack vector and connect to the internet are of higher priority.
See a Demo on Security New DashboardWhen it's hard to see the forest for the trees, we raise you above the sprawl to see your environment in ways never before possible.
Our new dashboard will present a clearer and more meaningful view of the entire network. We are surfacing metrics about the size of the data lake, how it is changing, and including quick views into threats, stacks, and geolocation.
We believe in making visually compelling experiences for our users to lead to "aha!" moments and drive quicker time to value. Who knew your environment could be so elegant?
The OrbSee the entirety of your environment. Understand which departments, teams, business units are integrated. Understand where you may have risk on personnel or opportunities to share data better.
Assessment and Stack DigestsThe size and complexity of your data lake is one of the most important, and hard to understand parts of an assessment. We are providing our users high level overviews of the size of their assessment and how data collection is changing.
Threats & GeolocationWe're placing new features from our Security module on the dashboard to give users quick insight into their threat assessment, as well as provide an interactive map to give visualization to user distribution.
Demo the New Dashboard Enhanced Asset DiscoveryDiscovery is central to RISC Networks' purpose. This key first step begins the transformation of the unknown to the known.
Understanding and managing this transformation can be difficult, time consuming, and frustrating. We are shipping a feature set designed to:
Additionally, by scheduling discoveries weekly you can now track and report on changes in the environment for purposes of asset management and cloud migration tracking.
We have brought all your assets to one report for you to quickly search, filter, and report on. We're also introducing the ability for you to save and share your page layouts with other users.
Error & Resolution PageWe created an Assets Errors page to significantly reduce the time it takes to troubleshoot network access. This page will surface all device errors we encounter during discovery. We are also adding a suggested resolution so you can quickly share it the network and server admin teams.
Change Over TimeKnow when devices existed and see how your locations, device types, and OS distributions are changing. This will give you visibility into progress toward a migration goal or simply how the environment is changing.
Tour the Assets Page