cancel
Showing results for 
Search instead for 
Did you mean: 

[CVE-2021-44228] Apache Log4j2 RCE

dawoon_lee
New Contributor II

Hello.

Our customer is running a Ruckus SmartZone (sz-100) controller.
The version of the controller is 5.1.1.0.598.


The customer asked if the SmartZone has the following this security vulnerabilities.

** Vulnerability: [CVE-2021-44228] Apache Log4j2 RCE

Thank you for your valuable answers to the above questions.

93 REPLIES 93

@JTakaMT Yes the patch that needs to be uploaded is only .ksp file. Thank you for sharing your inputs that would help others.

Best Regards

vineet

kristphr
New Contributor III

@JTakaMT thank you for this!

@JTakaMT:  thank you, I should have mentioned that as well, since our TAC director runs on a Mac and did see that too.

@vineet_nejawala :  can you or Sameer please update the KBA with the MAC-specific guidance re: the decompression process?

Allan.

Allan T. Grohe Jr.
==
Knowledge Management Program Director
for RUCKUS Customer Services & Support

@allan_grohe 

This has been updated on article.

Best Regards

Vineet

ludia_it
New Contributor II

Just finished patching. (vSZ 6) 

I tried to restart the services after the patch as documented (service restart) on the first node but after 1 hour it was still waiting on the same services to get up. 

I had to reboot the node (reload).

On the second one, I just used the (reload) command.