HPE Updates
2443Warning Date
Severity Level
Warning Number
Target Sector
21 December, 2021
● Critical
2021-4101
All
Description:
HPE has released security updates to address Apache Log4j vulnerability in the following products:
- HPE Dynamic SIM Provisioning (DSP)
- DSP3.3, DSP3.1, DSP3.4
- HPE Remote SIM Provisioning Manager (RSPM)
- RSPM1.3.2, RSPM1.4.1
- HPE 3PAR Service Processors
- SP 5.x version Prior to 5.0.9.2
- HPE Real Time Management System (RTMS) -
- Prior to RTMS 3.00.72.1
Threats:
A remote attacker could exploit this vulnerability by executing arbitrary code.
Best practice and Recommendations:
The CERT team encourages users to review HPE security advisory and apply the necessary updates:
- https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=hpesbgn04222en_us
- https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=hpesbgn04223en_us
- https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=hpesbgn04219en_us
- https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=hpesbgn04224en_us