-
×InformationNeed Windows 11 help?Check documents on compatibility, FAQs, upgrade information and available fixes.
Windows 11 Support Center. -
-
×InformationNeed Windows 11 help?Check documents on compatibility, FAQs, upgrade information and available fixes.
Windows 11 Support Center. -
- HP Community
- Desktops
- Business PCs, Workstations and Point of Sale Systems
- HP Device Manager affected by Log4j Vulnerability?

Create an account on the HP Community to personalize your profile and ask a question
12-13-2021 12:28 PM - last edited on 12-13-2021 12:54 PM by MarcusC
I noticed the HP Device Manager uses Log4j binaries.
Was wondering if HP is going to address this hopefully sooner than later.
12-29-2021 11:46 PM - edited 12-30-2021 10:01 PM
attacker performs an HTTP request against a target system, which generates a log using Log4j 2 that leverages JNDI to perform a request to the attacker-controlled site. The vulnerability then causes the exploited process to reach out to the site and execute the payload. In many observed attacks, the attacker-owned parameter is a DNS logging system, intended to log a request to the site to fingerprint the vulnerable systems.
01-09-2022 04:01 AM - edited 01-25-2022 09:53 AM
Hi there, Can anyone quantify macys employeeconnection the actual risk to say an N-able server? Is direct access to the server required to take advantage of this, or could it be exploited by someone externally if they can either see the login page or if they are somehow able to sign in to the krogerfeedback.com RMM admin portal? I would think it's the former but trying to wrap my head around just how vulnerable systems are that are running log4j on them.