Impact of CVE-2021-44228 Apache Log4j Vulnerability on NetBackup SaaS Protection (NSP)

Impact of CVE-2021-44228 Apache Log4j Vulnerability on NetBackup SaaS Protection (NSP)

Article: 100052125
Last Published: 2021-12-17
Ratings: 0 0
Product(s): NetBackup SaaS Protection

Summary 

Apache Log4j 2.x (2.0 to 2.14.1) JNDI features used in configuration, log message, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints.  An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled.   

More information is available from the Apache Announcement.   While this issue has been resolved in the Log4j 2.16.0, compatibility and installation of this version is still under investigation.

Mitigation 

After an in-depth analysis of the NetBackup SaaS Protection (NSP) product and supporting technologies, the NSP team concluded there is no risk to customers from an external perspective. Customers do not have mitigation steps required/recommended for any version of the NSP product.

From an internal / backend perspective, the NSP Team has identified potential risks due to this vulnerability and is implementing preventative and detective controls, including planned upgrades to NSP supporting components, such as Elastic Search and Tika. Affected components will be upgraded in late January, or early February, after appropriate regression testing is completed. The NSP Team is also implementing, from a detective perspective, technologies that will identify unusual behavior on the NSP Virtual Machines. 

Questions 

For questions or problems regarding these vulnerabilities please contact Veritas Technical Support (https://www.veritas.com/support

Note: This document is being reviewed frequently, and this note will be removed once all affected versions have been identified and mitigations are in place. 

 

Disclaimer

THE SECURITY ADVISORY IS PROVIDED "AS IS" AND ALL EXPRESS OR IMPLIED CONDITIONS, REPRESENTATIONS AND WARRANTIES, INCLUDING ANY IMPLIED WARRANTY OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE OR NON-INFRINGEMENT, ARE DISCLAIMED, EXCEPT TO THE EXTENT THAT SUCH DISCLAIMERS ARE HELD TO BE LEGALLY INVALID. VERITAS TECHNOLOGIES LLC SHALL NOT BE LIABLE FOR INCIDENTAL OR CONSEQUENTIAL DAMAGES IN CONNECTION WITH THE FURNISHING, PERFORMANCE, OR USE OF THIS DOCUMENTATION. THE INFORMATION CONTAINED IN THIS DOCUMENTATION IS SUBJECT TO CHANGE WITHOUT NOTICE.

 

 

Was this content helpful?