Symantec Alert
2707Warning Date
Severity Level
Warning Number
Target Sector
12 December, 2021
● Critical
2021-4011
All
Description:
Symantec has released a security alerts to address Apache Log4j vulnerability in the following products:
- Symantec Endpoint Protection Manager (SEPM)
- 14.3
- Symantec Advanced Authentication
- 9.1
- 9.1.01
- 9.1.0
Threats:
Remote attacker could exploit this vulnerability by executing arbitrary code.
Best practice and Recommendations:
To mitigate the impact of the vulnerability on the products, please do the following:
- Set the system environment variable "LOG4J_FORMAT_MSG_NO_LOOKUPS" to "true"
- Restart all Java components (Admin, UDS, AFM, RestAPI) and the SEPM system services
For more information: