Loading

CVE-2021-44228

Skip Feed
  1. Hi Snow Community

    We have put together some guidelines and insights about how Snow can help with finding potential installations affected by CVE-2021-44228 (aka, "Log4Shell"). As we learn more we will be sure to update and improve the advice we've given here: https://community.flexera.com/s/article/How-Snow-can-help-with-CVE-2021-44228


  2. Can we get detailed rationale for why the unaffected Snow products are unaffected?

    Thank you for all your quick work on this topic!

     

    My vulnerability team - in addition to confirming that our purchased products are not vulnerable to the Dec. 2021 log4j exploit - wants to also collect each vendor's rationale for why they are not vulnerable to the exploit. Example explanations include: product X uses log4j version y.y.y, which is not vulnerable; product X includes a vulnerable version of log4j, but through configuration log4j is disabled.

     

    Can you provide this detail for each of your non-vulnerable products? Thank you again for your time!

    Expand Post

    • Jorge Ortiz (Flexera Software)

      Jonathan,

       

      I am happy to say that all of the Snow License Manager products are unaffected by the Log4J exploit as we do not utilize this within our application. Snow Commander is a completely different product not stemming from Snow License Manager which is why we announced the problem and resolution. This is covered in https://community.flexera.com/s/article/Vulnerability-in-Log4j-CVE-2021-45105

       

      If you have any additional questions/concerns feel free to respond or open a support ticket with the Snow team.

       

      Kind Regards,

       

      Gabe Ortiz

      Snow Software Inc

      Expand Post

  3. Can I have an official statement from Snow that SLM, SIM, Si are not affected by Log4j problem? Except perhaps Commander?
    Question with a best answer.

    Best Answer

    Hi all I wanted to share that there has been a new post on the New & Updates group: https://community.flexera.com/s/feed/0D5690000B5879cCQA

     

    Also that we have put together some guidelines and insights about how Snow can help with finding potential installations affected by CVE-2021-44228. As we learn more we will be sure to update and improve the advice we've given here: https://community.flexera.com/s/article/How-Snow-can-help-with-CVE-2021-44228

    Expand Post
    Karen Peacock by Karen Peacock (Flexera Software)

    1 of 12

  4. 1 of 5

  5. 1 of 4
    • I thought that this idea might be useful for future investigations perhaps. It might be helpful to have the option to use Snow to look for a suspicious file hash.

  6. How do we identify applications, devices, and services using the Log4J library (regarding CVE-2021-44228) or maybe Snow itself does?
    Question with a best answer.

    Best Answer

    Hi all I wanted to share that there has been a new post on the New & Updates group: https://community.flexera.com/s/feed/0D5690000B5879cCQA

     

    Also that we have put together some guidelines and insights about how Snow can help with finding potential installations affected by CVE-2021-44228. As we learn more we will be sure to update and improve the advice we've given here: https://community.flexera.com/s/article/How-Snow-can-help-with-CVE-2021-44228

    Expand Post
    Karen Peacock by Karen Peacock (Flexera Software)

    1 of 40
    • the EXTENSIONS_BLACKLIST and EXTENSIONS_WHITELIST are NOT related to what data is transferred between Snow Inventory Server and Snow License Manager. These settings are only controlling what kind of files you can upload as attachments to Snow License Manager.

       

      For example, to ensure that nobody can upload a potentially harmful executable as an attachment to an agreement, "exe" is by default a part of the EXTENSIONS_BLACKLIST setting. You can also choose to do whitelisting of attachments, which is stricter. Adding "pdf" to the EXTENSIONS_WHITELIST will ONLY allow PDF documents as attachments in SLM.

      Expand Post

End of Feed
6 Chatter Feed Items
ALL CONVERSATIONS
UNSOLVED
ARTICLES
10 Posts
5 Articles

Related Topics

Loading
CVE-2021-44228 | Flexera