ESX Virtualization

VMware ESXi, vSphere, VMware Backup, Hyper-V... how-to, videos....

Nakivo Backup and Replication - #1 Backup solution for Virtual, physical, cloud, NAS and SaaS

Menu
  • Certification
      • VCP-DCV vSphere 8
          • vcp2024-125.
        • Close
    • Close
  • VMware
    • Configuration Maximums
    • vSphere
      • vSphere 8.0
      • vSphere 7.0
      • vSphere 6.7
      • vSphere 6.5
      • vSphere 6.0
      • Close
    • VMworld
      • VMware EXPLORE 2024
      • VMware EXPLORE 2023
      • VMware EXPLORE 2022
      • VMworld 2019
      • VMworld 2018
      • VMworld 2017
      • VMworld 2016
      • VMworld 2015
      • VMworld 2014
      • VMworld 2013
      • VMworld 2012
      • VMworld 2011
      • Close
    • Close
  • Microsoft
    • Windows Server 2012
    • Windows Server 2016
    • Windows Server 2019
    • Close
  • Categories
    • Tips – VMware, Microsoft and General IT tips and definitions, What is this?, How this works?
    • Server Virtualization – VMware ESXi, ESXi Free Hypervizor, VMware vSphere Server Virtualization, VMware Cloud and Datacenter Virtualization
    • Backup – Virtualization Backup Solutions, VMware vSphere Backup and ESXi backup solutions.
    • Desktop Virtualization – Desktop Virtualization, VMware Workstation, VMware Fusion, VMware Horizon View, tips and tutorials
    • How To – ESXi Tutorials, IT and virtualization tutorials, VMware ESXi 4.x, ESXi 5.x and VMware vSphere. VMware Workstation and other IT tutorials.
    • Free – Free virtualization utilities, ESXi Free, Monitoring and free backup utilities for ESXi and Hyper-V. Free IT tools.
    • Videos – VMware Virtualization Videos, VMware ESXi Videos, ESXi 4.x, ESXi 5.x tips and videos.
    • Home Lab
    • Reviews – Virtualization Software and reviews, Disaster and backup recovery software reviews. Virtual infrastructure monitoring software review.
    • Close
  • Partners
    • NAKIVO
    • StarWind
    • Zerto
    • Xorux
    • Close
  • This Web
    • News
    • ESXi Lab
    • About
    • Advertise
    • Archives
    • Disclaimer
    • PDFs and Books
    • Close
  • Free
  • Privacy policy

Runecast can help to detect vulnerability in Apache Log4j Java library

By Vladan SEGET | Last Updated: December 15, 2021

Shares

As you might hear, there is a new flaw in Apache Log4j, a Java library for logging error messages in applications. This vulnerability is the most high-profile security vulnerability on the internet right now as it impacts many different platforms that run Java.

VMware strongly recommends that organizations who are impacted by CVE-2021-44228 review the guidance in the context of all workloads and other systems. This issue affects billions of systems, software packages, and devices globally.

How does it work? The hacker can send a request to any endpoint which writes its content into the application's log file. The application can get rerouted, and then load and execute untrusted code from a malicious external server.

If an attacker manages to exploit it on a vulnerable server, they basically are able to execute arbitrary code and potentially take full control of the system. This information has been published publicly as Proof-of-Concept and apparently the vulnerability is easy to exploit so this makes this situation particularly dangerous.

Log4Shell Vulnerability Scan

Runecast offers the possibility to detect this issue within your environment. Simply go to this page and request a free scan. You'll be offered a 7 day Runecast trial for unlimited assets. Please note that this applies only to qualified organizations so putting in some erroneous information won't cut it. I'd imagine that trying it with some free e-mail accounts won't be useful and most likely rejected as well. So please don't do that. Runecast folks simply trying to help you to discover this vulnerability within your environment.

Runecast customers can simply update their Runecast VA to the latest version and initiate a scan as the definition of remote code execution vulnerability CVE-2021-44228 is now integrated into the product.

Quote from Runecast blog:

The latest version of Runecast (6.0.1.0) has this VMSA implemented and is available as an update. Where automatic updates are enabled, Runecast users should already have this VMSA covered, with offline updates available through the Runecast customer portal as usual. There were a number of affected VMware products that we support: vCenter Server, Horizon, NSX-T, but please note, the list might be expanded as VMware evaluates the vulnerability.

Runecast Product Update

If your Runecast product is not set to update automatically, you can do it manually via the console. (F1 for login)/

BTW, do you remember the console default login and password?

  • login: rcadmin
  • pass: admin

Preferably to change into something different of course.

The appliance reboots itself automatically.

When you connect via UI, you can check that you're running the latest Runecast product and the knowledge definition version within the Settings > Update section.

Which products are affected?

VMware reacted quickly and released a new KB 87068 covering the details. The long list of products that are currently vulnerable can be found here (currently 40 VMware products, but still in evolution !!).

With each product, VMware has a workaround that can be applied manually or automatically. The list of products and the workaround is pretty impressive. VMware is working towards resolutions and will be issuing patches for each of their products itself.

The latest updates on the matter are also covered via Apache Software Foundation which is maintaining the log4j components. They recently issued an updated workaround for CVE-2021-44228, as well as guidance on a second vulnerability, CVE-2021-45046. New information is often learned during an incident, requiring a change in strategy.

Final Words

If you're using Apache or Java within your environment within any of the VMware products, you should definitely be interested as this vulnerability is here. The vulnerability was discovered in December (this month) so it's pretty new. Many admins will “sleep” through by ignoring it and that's the danger.

The Common Vulnerabilities and Exposures (CVEs) and VMware Security Advisories (VMSA) are not there to be pretty but shall be taken seriously especially with flaws affecting so many products. Runecast's expertise via detection of vulnerabilities, misconfiguration, and threads allows admins to have a central point of security and be aware of steps that needs to be taken in order to mitigate the risk by following VMware KB articles and workarounds.

Request your Log4Shell Vulnerability scan here.

Source: Runecast Blog

Shares
5/5 - (1 vote)

| Filed Under: Server Virtualization Tagged With: Log4Shell Vulnerability Scan

About Vladan SEGET

This website is maintained by Vladan SEGET. Vladan is as an Independent consultant, professional blogger, vExpert x16, Veeam Vanguard x9, VCAP-DCA/DCD, ESX Virtualization site has started as a simple bookmarking site, but quickly found a large following of readers and subscribers.

Connect on: Facebook. Feel free to network via Twitter @vladan.

Private Sponsors

Featured

  • Thinking about HCI? G2, an independent tech solutions peer review platform, has published its Winter 2023 Reports on Hyperconverged Infrastructure (HCI) Solutions.
  • Zerto: One Platform for Disaster Recovery, Backup & Cloud Mobility: Try FREE Hands-On Labs Today!
Click to Become a Sponsor

Most Recent

  • Veeam Backup & Replication v13 Beta: A Game-Changer with Linux
  • What is Veeam Data Cloud Vault and how it can help SMBs
  • Nakivo Backup and Replication – Malware Scan Feature
  • Zerto 10 U7 released with VMware NSX 4.2 Support
  • XorMon NG 1.9.0 Infrastructure Monitoring – now also with Veeam Backup Support
  • Heartbeat vs Node Majority StarWind VSAN Failover Strategy
  • Vulnerability in your VMs – VMware Tools Update
  • FREE version of StarWind VSAN vs Trial of Full version
  • Commvault’s Innovations at RSA Conference 2025 San Francisco
  • VMware ESXi FREE is FREE again!

Get new posts by email:

 

 

 

 

Support us on Ko-Fi

 

 

Buy Me a Coffee at ko-fi.com

Sponsors

Free Trials

  • DC Scope for VMware vSphere – optimization, capacity planning, and cost management. Download FREE Trial Here.
  • Augmented Inline Deduplication, Altaro VM Backup v9 For #VMware and #Hyper-V – Grab your copy now download TRIAL.

VMware Engineer Jobs

VMware Engineer Jobs

YouTube

…

Find us on Facebook

ESX Virtualization

…

Copyright © 2025 ·Dynamik-Gen · Genesis Framework · Log in