• ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
  • ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
Guidelines
Are you having HotKey issues? Click here for tips and tricks.
HP Recommended
Microsoft Windows Server 2019

 

 

I noticed the HP Device Manager uses Log4j binaries.  

 

Was wondering if HP is going to address this hopefully sooner than later.

5 REPLIES 5
HP Recommended

has there been any update on this at all?

HP Recommended

Still no update?

HP Recommended

According to this HP Webpage, Device Manager is not affected.

 

https://support.hp.com/gb-en/document/ish_5285798-5285675-16

 

HP Recommended

attacker performs an HTTP request against a target system, which generates a log using Log4j 2 that leverages JNDI to perform a request to the attacker-controlled site. The vulnerability then causes the exploited process to reach out to the site and execute the payload. In many observed attacks, the attacker-owned parameter is a DNS logging system, intended to log a request to the site to fingerprint the vulnerable systems.

 

TelltheBell

 

 

HP Recommended

Hi there, Can anyone quantify macys employeeconnection the actual risk to say an N-able server? Is direct access to the server required to take advantage of this, or could it be exploited by someone externally if they can either see the login page or if they are somehow able to sign in to the krogerfeedback.com RMM admin portal? I would think it's the former but trying to wrap my head around just how vulnerable systems are that are running log4j on them.

† The opinions expressed above are the personal opinions of the authors, not of HP. By using this site, you accept the <a href="https://www8.hp.com/us/en/terms-of-use.html" class="udrlinesmall">Terms of Use</a> and <a href="/t5/custom/page/page-id/hp.rulespage" class="udrlinesmall"> Rules of Participation</a>.