<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 3.0 Patch 5, does it require log4j hotfix? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-3-0-patch-5-does-it-require-log4j-hotfix/m-p/4604279#M574526</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- That's a dilemma&lt;EM&gt;&lt;U&gt; indeed,&lt;/U&gt;&lt;/EM&gt; I don't want to be the always mr. right person. But here there are solutions too, such as importing or migrating/mapping&amp;nbsp; an appliance to a virtual (VM)-copy and testing on a kind of isolated network. All that of course depends on how strong security requirements for the particular Intranet are.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;- &lt;EM&gt;Or even installing a virgin ISE node with the particular ISE-version and testing on it.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
    <pubDate>Wed, 04 May 2022 09:35:28 GMT</pubDate>
    <dc:creator>Mark Elsen</dc:creator>
    <dc:date>2022-05-04T09:35:28Z</dc:date>
    <item>
      <title>ISE 3.0 Patch 5, does it require log4j hotfix?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-0-patch-5-does-it-require-log4j-hotfix/m-p/4603602#M574475</link>
      <description>&lt;P&gt;Hi all&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Basically the title says it all. Does ISE 3.0 Patch 5 still require the Log4j Hotfix? I'm asking because the release notes state&amp;nbsp;CSCwa47133 as fixed, but neither the hotfix notes nor the bug notes have been updated in regards to Patch 5.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Patrick&lt;/P&gt;</description>
      <pubDate>Tue, 03 May 2022 08:35:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-0-patch-5-does-it-require-log4j-hotfix/m-p/4603602#M574475</guid>
      <dc:creator>patoberli</dc:creator>
      <dc:date>2022-05-03T08:35:35Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3.0 Patch 5, does it require log4j hotfix?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-0-patch-5-does-it-require-log4j-hotfix/m-p/4603613#M574476</link>
      <description>&lt;P&gt;as per i know yes it is required to patch.&lt;/P&gt;</description>
      <pubDate>Tue, 03 May 2022 08:52:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-0-patch-5-does-it-require-log4j-hotfix/m-p/4603613#M574476</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-05-03T08:52:09Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3.0 Patch 5, does it require log4j hotfix?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-0-patch-5-does-it-require-log4j-hotfix/m-p/4603791#M574490</link>
      <description>&lt;P&gt;I agree with&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/286878"&gt;@balaji.bandi&lt;/a&gt;&amp;nbsp;that it is required.&lt;/P&gt;
&lt;P&gt;Additional links that should help:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd" target="_blank"&gt;Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwa47133" target="_blank"&gt;CSCwa47133 : Bug Search Tool (cisco.com)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/web/software/283802505/159582/README_Hotpatch_CSCwa47133_Log4j2-fix-2.4-3.0.txt" target="_blank"&gt;https://www.cisco.com/web/software/283802505/159582/README_Hotpatch_CSCwa47133_Log4j2-fix-2.4-3.0.txt&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 May 2022 14:07:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-0-patch-5-does-it-require-log4j-hotfix/m-p/4603791#M574490</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2022-05-03T14:07:23Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3.0 Patch 5, does it require log4j hotfix?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-0-patch-5-does-it-require-log4j-hotfix/m-p/4603829#M574502</link>
      <description>&lt;P&gt;Thanks for your replies. Then it's not really nice that this Bug is listed as resolved with P5.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 May 2022 15:05:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-0-patch-5-does-it-require-log4j-hotfix/m-p/4603829#M574502</guid>
      <dc:creator>patoberli</dc:creator>
      <dc:date>2022-05-03T15:05:29Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3.0 Patch 5, does it require log4j hotfix?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-0-patch-5-does-it-require-log4j-hotfix/m-p/4603835#M574503</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Indeed , but I too am near-sure that it (still) needs to be applied in your case (too). Of course one could look for exploit examples with the searching powers of the Net &lt;EM&gt;but that would indeed require some &lt;U&gt;additional efforts.&lt;/U&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Tue, 03 May 2022 15:22:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-0-patch-5-does-it-require-log4j-hotfix/m-p/4603835#M574503</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2022-05-03T15:22:41Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3.0 Patch 5, does it require log4j hotfix?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-0-patch-5-does-it-require-log4j-hotfix/m-p/4604093#M574517</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/323352"&gt;@patoberli&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;please take a look at: &lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwa47133" target="_blank" rel="noopener"&gt;CSCwa47133 ISE Evaluation log4j CVE-2021-44228&lt;/A&gt;, &lt;STRONG&gt;ISE 3.0 P5&lt;/STRONG&gt; is a &lt;STRONG&gt;Known Fixed Released&lt;/STRONG&gt;:&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="CSCwa47133 00.png" style="width: 730px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/150535i59B71BE2B294C18B/image-dimensions/730x289?v=v2" width="730" height="289" role="button" title="CSCwa47133 00.png" alt="CSCwa47133 00.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Also take a look at &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/3-0/release_notes/b_ise_30_rn.html" target="_blank" rel="noopener"&gt;ISE 3.0 Release Notes&lt;/A&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;IMO you are good and don't need to install the hotfix.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Tue, 03 May 2022 22:55:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-0-patch-5-does-it-require-log4j-hotfix/m-p/4604093#M574517</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2022-05-03T22:55:07Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3.0 Patch 5, does it require log4j hotfix?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-0-patch-5-does-it-require-log4j-hotfix/m-p/4604224#M574520</link>
      <description>&lt;P&gt;Also using exploits might damage the appliance, if still vulnerable. But I hope for the best that P5 indeed includes the patch (it was released some 3-4 months after the log4j patch).&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 May 2022 07:20:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-0-patch-5-does-it-require-log4j-hotfix/m-p/4604224#M574520</guid>
      <dc:creator>patoberli</dc:creator>
      <dc:date>2022-05-04T07:20:39Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3.0 Patch 5, does it require log4j hotfix?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-0-patch-5-does-it-require-log4j-hotfix/m-p/4604279#M574526</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- That's a dilemma&lt;EM&gt;&lt;U&gt; indeed,&lt;/U&gt;&lt;/EM&gt; I don't want to be the always mr. right person. But here there are solutions too, such as importing or migrating/mapping&amp;nbsp; an appliance to a virtual (VM)-copy and testing on a kind of isolated network. All that of course depends on how strong security requirements for the particular Intranet are.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;- &lt;EM&gt;Or even installing a virgin ISE node with the particular ISE-version and testing on it.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Wed, 04 May 2022 09:35:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-0-patch-5-does-it-require-log4j-hotfix/m-p/4604279#M574526</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2022-05-04T09:35:28Z</dc:date>
    </item>
  </channel>
</rss>

