cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2698
Views
5
Helpful
4
Replies

CSCwa47745 - Evaluation of vmanage for Log4j RCE

mohamad.masri
Level 1
Level 1

Hi Team ,

 

Anyone know if these fixed releases have been published yet ? Can't find 20.7* in software downloads , latest seems to be 20.6Cisco Bug Discussions

4 Replies 4

Ciscouserz
Level 1
Level 1

Im running vManage 20.6.2 (the latest release) and it affected byt vulnerability, I can send an exploit successful to vManage.

cdipietro
Level 1
Level 1

According to TAC, the BU stated that fixed releases will be published by end of this week.

20.7.1

20.6.2.1

20.5.1.1

20.4.2.1

20.3.4.1

 

Take that with a grain of salt, things may change, but this is what I was told.

 

mwhisen
Level 5
Level 5

We all want patched software, but if you are on 20.3 or I think the post is 20.6 I would not increase the second point level to fix the log4j. While some of these are not yet posted on CCO. They are in flight and if you open a TAC case and escalate if it is ready then they can make it available as special file access. If you have not run into challenges on moving up point releases on vManage please be extremely careful and read the release notes.