12-13-2021 04:52 AM
Are there any checks or verifications known to see if ISE was not infiltrated by someone using log4j?
12-17-2021 09:28 AM
I was encountering the same issue. Turns out when I first downloaded the file it was 20KB, tried again it was 5KB. It could be that the hot-fix that was downloaded was corrupted somehow. Re-download the hot-fix and try again, that worked for me.
12-17-2021 07:17 AM
Hello -
We successfully applied the hot fix ise-apply-CSCwa47133_Ver_24_30_allpatches-SPA.tar.gz to our ISE nodes last night.
Our Risk Management team is asking for the version of log4j that is now installed.
Can you please verify what version we're now running?
12-20-2021 02:54 AM
@Gwendolyn Lapasky: The hotfix ise-apply-CSCwa47133_Ver_24_30_allpatches-SPA.tar.gz does not change the log4j version. The developers just removed the JndiLookup.class from the jar file.
12-17-2021 04:29 PM - edited 12-17-2021 04:29 PM
12-27-2021 02:09 AM
Still no guidelines to verify for exploit ?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide