Broadcom Updates
2354Warning Date
Severity Level
Warning Number
Target Sector
21 December, 2021
● Critical
2021-4103
All
Description:
Broadcom has released security updates to address Apache Log4j vulnerability in the following products:
- Automation Point Servers with the NIM-SM Feature Activated
- Mainframe Operational Intelligence
Threats:
A remote attacker could exploit this vulnerability by executing arbitrary code.
Best practice and Recommendations:
The CERT team encourages users to review Broadcom security advisory and apply the necessary updates:
- https://support.broadcom.com/security-advisory/content/security-advisories/Mainframe-Operational-Intelligence-2.0.xx-Log4j-Vulnerabilities-CVE-2021-44228-and-CVE-2021-45046/MFDSA19873
- https://support.broadcom.com/security-advisory/content/security-advisories/Cross-Enterprise-APM-8.x-10.x-Log4j-2-vulnerabilities-CVE-2021-44228-and-CVE-2021-45046/MFDSA19872
- https://support.broadcom.com/security-advisory/content/security-advisories/OPS-MVS-AUTOMATION-POINT-11.7-WITH-NIM-SM-INTEGRATION-FEATURE-LOG4J-VULNERABILITY-CVE-2021-44228/MFDSA19844
- https://support.broadcom.com/security-advisory/content/security-advisories/OPS-MVS-AUTOMATION-POINT-11.6-WITH-NIM-SM-INTEGRATION-FEATURE/MFDSA19843