<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CVE-2021-44228 Apache Log4j Vulnerability in NetApp Products in VMware Solutions Discussions</title>
    <link>https://community.netapp.com/t5/VMware-Solutions-Discussions/CVE-2021-44228-Apache-Log4j-Vulnerability-in-NetApp-Products/m-p/430303#M9879</link>
    <description>&lt;P&gt;Out of curiosity, were you applying this workaround?:&lt;BR /&gt;&lt;A href="https://kb.netapp.com/Advice_and_Troubleshooting/Data_Protection_and_Security/SnapCenter/SnapCenter_Plug-in_for_VMware_vSphere__-_CVE-2021-4428_Apache_Log4j_Vulnerability_-_Workaround" target="_blank"&gt;https://kb.netapp.com/Advice_and_Troubleshooting/Data_Protection_and_Security/SnapCenter/SnapCenter_Plug-in_for_VMware_vSphere__-_CVE-2021-4428_Apache_Log4j_Vulnerability_-_Workaround&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 20 Dec 2021 17:03:27 GMT</pubDate>
    <dc:creator>colsen</dc:creator>
    <dc:date>2021-12-20T17:03:27Z</dc:date>
    <item>
      <title>CVE-2021-44228 Apache Log4j Vulnerability in NetApp Products</title>
      <link>https://community.netapp.com/t5/VMware-Solutions-Discussions/CVE-2021-44228-Apache-Log4j-Vulnerability-in-NetApp-Products/m-p/430038#M9875</link>
      <description>&lt;P&gt;NetApp's list of affected/not affected products is available here:&lt;/P&gt;&lt;P&gt;&lt;A href="https://security.netapp.com/advisory/ntap-20211210-0007/" target="_blank"&gt;CVE-2021-44228 Apache Log4j Vulnerability in NetApp Products | NetApp Product Security&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At this moment, here is the list of Affected Products:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Brocade SAN Navigator (SANnav)&lt;/LI&gt;&lt;LI&gt;Cloud Manager&lt;/LI&gt;&lt;LI&gt;ONTAP Tools for VMware vSphere&lt;/LI&gt;&lt;LI&gt;SnapCenter Plug-in for VMware vSphere&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Wed, 04 Jun 2025 10:07:39 GMT</pubDate>
      <guid>https://community.netapp.com/t5/VMware-Solutions-Discussions/CVE-2021-44228-Apache-Log4j-Vulnerability-in-NetApp-Products/m-p/430038#M9875</guid>
      <dc:creator>Blissitt</dc:creator>
      <dc:date>2025-06-04T10:07:39Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2021-44228 Apache Log4j Vulnerability in NetApp Products</title>
      <link>https://community.netapp.com/t5/VMware-Solutions-Discussions/CVE-2021-44228-Apache-Log4j-Vulnerability-in-NetApp-Products/m-p/430039#M9876</link>
      <description>&lt;P&gt;As far as the snapcenter plug-in. After completing the workaround that vmware provided for the vcenter 7, my snapcenter would no longer deploy. I implemented the workaround for the snapcenter and the plug in still wont deploy on the snapcenter. Any ideas or suggestions?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Error deploying plug-in. org.apache.felix.resolver.reason.ReasonException: Unable to resolve /usr/lib/vmware-vsphere-ui/server/work/tmp/8066464305686214632com.netapp.scvm.webclient-4.5.0.6025788.esa/scvm_webui_service.jar: missing requirement org.apache.aries.subsystem.core.archive.ImportPackageRequirement: namespace=osgi.wiring.package, attributes={}, directives={filter=(&amp;amp;(osgi.wiring.package=org.springframework.web.servlet.view.velocity)(version&amp;gt;=0.0.0)), resolution=mandatory, uses=javax.servlet,javax.servlet.http,org.apache.velocity,org.apache.velocity.app,org.apache.velocity.context,org.apache.velocity.exception,org.apache.velocity.tools.generic,org.springframework.beans,org.springframework.beans.factory,org.springframework.context,org.springframework.ui.velocity,org.springframework.web.context,org.springframework.web.servlet.view}, resource=/usr/lib/vmware-vsphere-ui/server/work/tmp/8066464305686214632com.netapp.scvm.webclient-4.5.0.6025788.esa/scvm_webui_service.jar org.apache.felix.resolver.Candidates$MissingRequirementError.toException(Candidates.java:1340) org.apache.felix.resolver.Candidates$MissingRequirementError.toException(Candidates.java:1341) org.apache.felix.resolver.ResolverImpl.doResolve(ResolverImpl.java:433) org.apache.felix.resolver.ResolverImpl.resolve(ResolverImpl.java:420) org.apache.felix.resolver.ResolverImpl.resolve(ResolverImpl.java:413)&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 23:30:41 GMT</pubDate>
      <guid>https://community.netapp.com/t5/VMware-Solutions-Discussions/CVE-2021-44228-Apache-Log4j-Vulnerability-in-NetApp-Products/m-p/430039#M9876</guid>
      <dc:creator>IA-joesmith</dc:creator>
      <dc:date>2021-12-13T23:30:41Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2021-44228 Apache Log4j Vulnerability in NetApp Products</title>
      <link>https://community.netapp.com/t5/VMware-Solutions-Discussions/CVE-2021-44228-Apache-Log4j-Vulnerability-in-NetApp-Products/m-p/430072#M9877</link>
      <description>&lt;P&gt;I am missing&amp;nbsp;Virtual Storage Console (VSC, VASA Provider, and SRA virtual appliance) from the list.&lt;BR /&gt;Does it have a different name on the list?&lt;/P&gt;</description>
      <pubDate>Tue, 14 Dec 2021 20:12:57 GMT</pubDate>
      <guid>https://community.netapp.com/t5/VMware-Solutions-Discussions/CVE-2021-44228-Apache-Log4j-Vulnerability-in-NetApp-Products/m-p/430072#M9877</guid>
      <dc:creator>vcon</dc:creator>
      <dc:date>2021-12-14T20:12:57Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2021-44228 Apache Log4j Vulnerability in NetApp Products</title>
      <link>https://community.netapp.com/t5/VMware-Solutions-Discussions/CVE-2021-44228-Apache-Log4j-Vulnerability-in-NetApp-Products/m-p/430075#M9878</link>
      <description>&lt;P&gt;The new product name is ONTAP Tools for VMware vSphere (at this moment, version 9.8P1, which may or may not have Log4j fixes - you'll have to check).&amp;nbsp; It's the same product as&amp;nbsp;Virtual Storage Console for VMware vSphere, but with some bug fixes and a better name.&amp;nbsp; Unfortunately, NetApp didn't sufficiently advertise this change and I kept running the old 9.7 version until I lost five VMs on one of my vVols, likely due to those bugs which have since been addressed.&amp;nbsp; I have since removed ONTAP Tools for VMware vSphere from my environment because VAAI now provides the Native Snapshots I wanted and I no longer needed vVols.&amp;nbsp; I also wanted to reduce complexity.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The upgrade from 9.7 to 9.8 was uneventful for me and the new version worked well while I ran it.&amp;nbsp; If you want to upgrade to 9.8P1, maybe make sure that 9.8P1 is not "older" (by date) than the version you're upgrading from.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Dec 2021 20:43:36 GMT</pubDate>
      <guid>https://community.netapp.com/t5/VMware-Solutions-Discussions/CVE-2021-44228-Apache-Log4j-Vulnerability-in-NetApp-Products/m-p/430075#M9878</guid>
      <dc:creator>Blissitt</dc:creator>
      <dc:date>2021-12-14T20:43:36Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2021-44228 Apache Log4j Vulnerability in NetApp Products</title>
      <link>https://community.netapp.com/t5/VMware-Solutions-Discussions/CVE-2021-44228-Apache-Log4j-Vulnerability-in-NetApp-Products/m-p/430303#M9879</link>
      <description>&lt;P&gt;Out of curiosity, were you applying this workaround?:&lt;BR /&gt;&lt;A href="https://kb.netapp.com/Advice_and_Troubleshooting/Data_Protection_and_Security/SnapCenter/SnapCenter_Plug-in_for_VMware_vSphere__-_CVE-2021-4428_Apache_Log4j_Vulnerability_-_Workaround" target="_blank"&gt;https://kb.netapp.com/Advice_and_Troubleshooting/Data_Protection_and_Security/SnapCenter/SnapCenter_Plug-in_for_VMware_vSphere__-_CVE-2021-4428_Apache_Log4j_Vulnerability_-_Workaround&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Dec 2021 17:03:27 GMT</pubDate>
      <guid>https://community.netapp.com/t5/VMware-Solutions-Discussions/CVE-2021-44228-Apache-Log4j-Vulnerability-in-NetApp-Products/m-p/430303#M9879</guid>
      <dc:creator>colsen</dc:creator>
      <dc:date>2021-12-20T17:03:27Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2021-44228 Apache Log4j Vulnerability in NetApp Products</title>
      <link>https://community.netapp.com/t5/VMware-Solutions-Discussions/CVE-2021-44228-Apache-Log4j-Vulnerability-in-NetApp-Products/m-p/430874#M9882</link>
      <description>&lt;P&gt;This is the affected products below:&lt;/P&gt;&lt;H4&gt;Affected Products&lt;/H4&gt;&lt;UL&gt;&lt;LI&gt;Active IQ Unified Manager for Linux&lt;/LI&gt;&lt;LI&gt;Active IQ Unified Manager for Microsoft Windows&lt;/LI&gt;&lt;LI&gt;Active IQ Unified Manager for VMware vSphere&lt;/LI&gt;&lt;LI&gt;Brocade SAN Navigator (SANnav)&lt;/LI&gt;&lt;LI&gt;Cloud Insights Acquisition Unit&lt;/LI&gt;&lt;LI&gt;Cloud Manager&lt;/LI&gt;&lt;LI&gt;Cloud Secure Agent&lt;/LI&gt;&lt;LI&gt;NetApp SolidFire, Enterprise SDS &amp;amp; HCI Storage Node (Element Software)&lt;/LI&gt;&lt;LI&gt;ONTAP Tools for VMware vSphere&lt;/LI&gt;&lt;LI&gt;OnCommand Insight&lt;/LI&gt;&lt;LI&gt;SnapCenter Plug-in for VMware vSphere&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Can anyone confirm if FAS2650 - Release 9.2P1 is part of it? I don't know which product it belongs to.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jan 2022 07:08:04 GMT</pubDate>
      <guid>https://community.netapp.com/t5/VMware-Solutions-Discussions/CVE-2021-44228-Apache-Log4j-Vulnerability-in-NetApp-Products/m-p/430874#M9882</guid>
      <dc:creator>jcj112516</dc:creator>
      <dc:date>2022-01-13T07:08:04Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2021-44228 Apache Log4j Vulnerability in NetApp Products</title>
      <link>https://community.netapp.com/t5/VMware-Solutions-Discussions/CVE-2021-44228-Apache-Log4j-Vulnerability-in-NetApp-Products/m-p/430894#M9883</link>
      <description>&lt;P&gt;That's part of:&lt;/P&gt;&lt;P&gt;Clustered Data ONTAP&lt;/P&gt;&lt;P&gt;Which is not affected&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jan 2022 16:03:23 GMT</pubDate>
      <guid>https://community.netapp.com/t5/VMware-Solutions-Discussions/CVE-2021-44228-Apache-Log4j-Vulnerability-in-NetApp-Products/m-p/430894#M9883</guid>
      <dc:creator>bretta</dc:creator>
      <dc:date>2022-01-13T16:03:23Z</dc:date>
    </item>
  </channel>
</rss>

