12-12-2021 07:59 PM
Hello,
Could someone please advise which version of ISE is not affected by the log4j vulnerability?
What is the workaround if any ?
Cheers,
Gan
Solved! Go to Solution.
12-16-2021 03:57 AM
use the following command:
ise/admin# application install ise-apply-CSCwa47133_Ver_24_30_allpatches-SPA.tar.gz LOCAL
Note: LOCAL is the name of my repository that points to disk:
repository LOCAL
url disk:/
I always prefer to put the patch on the disk:
ise/admin# dir
Directory of disk:/
...
4747 Dec 16 2021 05:56:27 ise-apply-CSCwa47133_Ver_24_30_allpatches-SPA.tar.gz
3413 Dec 16 2021 05:57:46 ise-rollback-CSCwa47133_Ver_24_30_allpatches-SPA.tar.gz
...
It took 10 to 15 min in a LAB environment.
Hope this helps !!!
12-12-2021 08:58 PM
Only log4j versions 2.x.x are vulnerable. Apps using log4j 1.x.x are NOT vulnerable, so no action needs to be taken on applications using the older log4j versions.
12-12-2021 09:29 PM
I thought Apache foundation is to update all versions of log4j, as the no longer supported 1.x stream is open to this and others RCE exploits
12-13-2021 12:19 AM
Are you sure? I'm reading because 1.0 is no longer supported its also impacted.
12-13-2021 12:51 AM - edited 12-13-2021 03:49 PM
Bit misleading as in CSCwa47133 it does not state that ISE is running older version, it also lists all versions from 2.6 to 3.1 as affected.
12-13-2021 03:45 PM - edited 12-13-2021 03:54 PM
Do we know on which version of log4j ISE 2.7.0.356 is using?
12-13-2021 04:27 PM
please take a look at Cisco ISE 2.7 Release Notes, search for log4j.
Note: CSCvs66551 Multiple Vulnerabilities in apache log4j ... solved on 2.7 P5.
Hope this helps !!!
12-16-2021 10:26 AM
looks to be 2.11 (plus some older versions)
that is .... if I am reading it right ... no guarantee of that
12-13-2021 05:21 PM
Hi @Marcelo Morais ,
Thanks for the info. However the 2.7 version patch 5 is addressing an another vulnerability.
The new patch for this vulnerability will be in patch 7.
12-13-2021 05:46 PM
12-13-2021 05:59 PM
This bug CSCvs66551 is for a vulnerability dated on the 2019 and it is not relevant.Bug Search Tool (cisco.com)
I dont believe it fixes the issue. If you go on this link Bug Search Tool (cisco.com), there is still no fixed release.
12-13-2021 06:24 PM
Ahh my bad, I saw it was updated today with patches listed against it...... thought it was the current issues.
12-15-2021 11:54 PM
Cisco provided a Hot Patch for the log4j PSIRT bug - CSCwa47133.: ise-apply-CSCwa47133_Ver_24_30_allpatches-SPA.tar.gz (15-Dec-2021).
Hope this helps !!!
12-16-2021 12:26 AM - edited 12-16-2021 12:26 AM
Thanks Marcelo,
I am already in process of applying it on my second node.
Out of interest, is someone able to confirm if this patch is going to be persistent, that is, if I am running ISE 2.7 Patch 4 as that is the highest version mention to be compatible with Cisco DNA Center 2.2.2.3 on 2.7 platform. If this later gets compatibility for Patch 6 and I install the patch, do I have to be concerned that this hotfix gets removed and needs to be reapplied?
Thanks in advance.
12-16-2021 12:36 AM
Hi @AigarsK ,
I always prefer to rollback the Hot Patch before applying a regular ISE Patch release.
You are able to use the "show application" command to check the Hot Patch installation or the "show logging application hotpatch.log" to check if the Hot Patch was installed successfully.
Hope this helps !!!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide