IBM Support

Security Bulletin: IBM Spectrum Fusion HCI is vulnerable to denial of service and arbitrary code execution due to Apache Log4j (CVE-2021-45105, CVE-2021-45046)

Security Bulletin


Summary

Multiple vulnerabilities in Apache Log4j (CVE-2021-45105, CVE-2021-45046) could allow an attacker to execute arbitrary code and denial of service. These vulnerabilities may affect IBM Spectrum Scale Container Native Storage Access and IBM Spectrum Protect Plus, which are part of the IBM Spectrum Fusion HCI appliance. The fix includes includes Apache Log4j v.2.17.

Vulnerability Details

Refer to the security bulletin(s) listed in the Remediation/Fixes section

Affected Products and Versions

Affected Product(s)Version(s)
IBM Spectrum Fusion HCI2.1

Remediation/Fixes

IBM strongly recommends addressing the vulnerabilities now. The fix for these vulnerabilities is in IBM Spectrum Fusion HCI version 2.1.2. See the following page for upgrade instructions: https://www.ibm.com/support/pages/node/6488389

Upgrading to IBM Spectrum Fusion HCI version 2.1.2 will automatically pick up and upgrade the embedded components IBM Spectrum Scale and IBM Spectrum Protect plus to remediate the Apache Log4j vulnerabilities (CVE-2021-45105, CVE-2021-45046) in those components, respectively.

If you have already followed the workarounds in https://www.ibm.com/support/pages/node/6529312 for CVE-2021-44228,

you will still need to upgrade to IBM Spectrum Fusion v2.1.2 to remediate CVE-2021-45105, CVE-2021-45046.

 

Note: If you upgrade to IBM Spectrum Fusion HCI v2.1.2, then you do not need to follow the workarounds specified in the previous Security Bulletin for CVE-2021-44228: https://www.ibm.com/support/pages/node/6529312

 

Workarounds and Mitigations

See Remediation/Fixes above.

Get Notified about Future Security Bulletins

References

Off

Change History

13 Jan 2022: Initial Publication

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

Document Location

Worldwide

[{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SSXY2BQ","label":"IBM Spectrum Fusion HCI Software"},"Component":"","Platform":[{"code":"PF040","label":"RedHat OpenShift"}],"Version":"2.1","Edition":"","Line of Business":{"code":"LOB26","label":"Storage"}}]

Document Information

Modified date:
19 January 2022

Initial Publish date:
13 January 2022

UID

ibm16542092