Log4j vulnerability - Apache Log4j Vulnerability (CVE-2021-45046)
Hello everyone, It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) to craft malicious input data using
Log4j vulnerability - Handling for the DMZ tool
Hello everyone, Note: This is exclusively for customers using the DMZ tool for closed network patching. The DMZ tool alone has a dependency file that uses Log4j library and hence is vulnerable. The rest of Desktop Central / Patch Manager Plus / Vulnerability
Log4j vulnerability - Handling for the DMZ tool
Hello everyone, Note: This is exclusively for customers using the DMZ tool for closed network patching. The DMZ tool alone has a dependency file that uses Log4j library and hence is vulnerable. The rest of Desktop Central / Patch Manager Plus / Vulnerability
Log4j vulnerability - Handling for the DMZ tool
Hello everyone, Note: This is exclusively for customers using the DMZ tool for closed network patching. The DMZ tool alone has a dependency file that uses Log4j library and hence is vulnerable. The rest of Desktop Central / Patch Manager Plus / Vulnerability
Microsoft fixes several high-severity security vulnerabilities in Edge for Business (chromium) 96.0.1054.57 update
Hello everyone, Microsoft Edge for Business (chromium) has been updated to 96.0.1054.57 for Windows, macOS, and Linux. The details of the vulnerabilities fixed are as follows: CVE ID Vulnerability Severity CVE-2021-4098 Insufficient data validation
Microsoft fixes several high-severity security vulnerabilities in Edge for Business (chromium) 96.0.1054.57 update
Hello everyone, Microsoft Edge for Business (chromium) has been updated to 96.0.1054.57 for Windows, macOS, and Linux. The details of the vulnerabilities fixed are as follows: CVE ID Vulnerability Severity CVE-2021-4098 Insufficient data validation
Microsoft fixes several high-severity security vulnerabilities in Edge for Business (chromium) 96.0.1054.57 update
Hello everyone, Microsoft Edge for Business (chromium) has been updated to 96.0.1054.57 for Windows, macOS, and Linux. The details of the vulnerabilities fixed are as follows: CVE ID Vulnerability Severity CVE-2021-4098 Insufficient data validation
Google fixes several high-severity security vulnerabilities in Chrome 96.0.4664.110 stable channel update
Hello everyone, Chrome stable channel has been updated to 96.0.4664.110 for Windows, macOS, and Linux. This update comes with fixes for 5 security vulnerabilities of which CVE-2021-4102 is exploited in the wild. The details of the vulnerabilities fixed
Google fixes several high-severity security vulnerabilities in Chrome 96.0.4664.110 stable channel update
Hello everyone, Chrome stable channel has been updated to 96.0.4664.110 for Windows, macOS, and Linux. This update comes with fixes for 5 security vulnerabilities of which CVE-2021-4102 is exploited in the wild. The details of the vulnerabilities fixed
Google fixes several high-severity security vulnerabilities in Chrome 96.0.4664.110 stable channel update
Hello everyone, Chrome stable channel has been updated to 96.0.4664.110 for Windows, macOS, and Linux. This update comes with fixes for 5 security vulnerabilities of which CVE-2021-4102 is exploited in the wild. The details of the vulnerabilities fixed
Get information back from executed command
There is a powershell command to check if any files related to the Log4J vulnerability exists on an endpoint. I know it doesn't suffice, but to have a start, I would like to run the command on all endpoints and get back the result. I hope this is possible.
Advanced Configlet Documentation
Is there a document that lists all the possible functions that can be called from configlets for advanced scripting? I feel like the "advanced" scripting is super limited based on the URL below. For example can we parse output that is sent back to the
Log4j security issue
What is Manage Engines response to this very recently announced major security issue with regard to Log4j? . https://www.bleepingcomputer.com/news/security/new-zero-day-exploit-for-log4j-java-library-is-an-enterprise-nightmare/ CVE-2021-44228 is the
Patch 32500 Prompting for admin credentials on PCs
Deployed our non critical patches this morning as normal. Bunch of staff ringing me because this patch is prompting when running for administrator credentials..? 32500 MS21-O365C Update for Microsoft 365 Apps for Enterprise Current Channel for x86 2111
Servers vs Workstations
We love Desktop Central! I have read that Desktop Central is great for server management too, but we have only used it for workstations for many years. I am wanting to start deploying it in our servers too. But, our workstations and servers are managed
Visual Studio Express
Hi ALL! I need install Visual Studio Express 2022 (https://visualstudio.microsoft.com/vs/express/) to part of my PCs via DC - how to ??
Is ADSelfService Plus affected by CVE-2021-44228?
Hello Everyone, As stated in the Title, is ADSelfService Plus affected by the log4j Vulnerability CVE-2021-44228 (https://nvd.nist.gov/vuln/detail/CVE-2021-44228) ? If I am right, ADSelfService uses Tomcat, not Apache? Thanks in Advance
Solutions appearing from when raising an incident
We have just implemented solutions and discovered that the system looks at common words for example The, and,at. So when an user is raising a ticket if they are using common words the suggested solutions are brining everything up with The in them this
New incident template form.
Hi, New incident from fetched mail is created with "Default template" from Incident Template list, or we can select template used for create incidents from e-mail? I want to assign Site and Group for specific requester. I created new rule under "Incident
Apache Log4Shell vulnerability (CVE-2021-44228)
The identified Log4Shell vulnerability (CVE-2021-44228) is classified as a Zero-Day Vulnerability. The name Log4Shell refers to the fact that this bug is present in a popular Java logging library called Log4j, which when exploited, can allow attackers
Apache Log4Shell vulnerability (CVE-2021-44228)
The identified Log4Shell vulnerability (CVE-2021-44228) is classified as a Zero-Day Vulnerability. The name Log4Shell refers to the fact that this bug is present in a popular Java logging library called Log4j, which when exploited, can allow attackers
Patch Tuesday December 2021 - Updates
Hello everyone, Here is the list of supported December 2021 Patch Tuesday updates New Security Bulletins : 2021-12 Security Only Quality Update for Windows Server 2008 (KB5008271) (ESU) (CVE-2021-41333) (CVE-2021-43883) (CVE-2021-43893) 2021-12 Security
Patch Tuesday December 2021 - Updates
Hello everyone, Here is the list of supported December 2021 Patch Tuesday updates New Security Bulletins : 2021-12 Security Only Quality Update for Windows Server 2008 (KB5008271) (ESU) (CVE-2021-41333) (CVE-2021-43883) (CVE-2021-43893) 2021-12 Security
Patch Tuesday December 2021 - Updates
Hello everyone, Here is the list of supported December 2021 Patch Tuesday updates New Security Bulletins : 2021-12 Security Only Quality Update for Windows Server 2008 (KB5008271) (ESU) (CVE-2021-41333) (CVE-2021-43883) (CVE-2021-43893) 2021-12 Security
Log4j vulnerability in ServiceDesk Plus Cloud edition
I would like to know if our SDP Cloud is or has been vulnerable to log4j. On the forum I only read about the on-prem editions.
log4shell: ADSelfService vulnerable (CVE-2021-44228)
Hello ManageEngine, I investigate all our Systems about CVE-2021-44228. One system is ADSelfService Build 6116. It uses Java, but log4j to? Is this system vulnerable? Is there a fix, patch or workaround for this?
cve-2021-44228 ADAudit and ADSelf Service Guidance
Hello, I wanted to check if these two applications were susceptible to the Log4j vulnerability and what we could do to mitigate if they were? Thank you!
log4j
Hi there, I have seen and implemented the fix for AD Manager but I also need a fix for eventlog analyzer and elastic search/log 360 under the Managine Engine folder. Do you have the requirements for these?
[Security advisory for CVE-2021-44525] Authentication bypass vulnerability in ManageEngine Password Manager Pro
Hi there, The security advisory addresses an authentication bypass vulnerability identified in the product, ManageEngine Password Manager Pro versions up to 12001 [CVE-2021-44525].Given the severity of this vulnerability, we strongly urge all customers
Deprecation of few existing internal APIs
Dear users, We would like to inform you all that existing APIs used for "System Update Notification" and "Product Overview" will be deprecated from version 12004 and the support will be completely removed by March 2022. We highly recommend you to switch
Change Management - Approval & CAB
Hi, Change Management - We have 1st approval, 2nd approval and 3rd conditional approval processes at the consultancy stage. However, we are not able to display approval approvals in the advisory area. We are greeted with the note "This Change is configured
Log4j AD Audit Plus CVE-2021-44228
Hi, i found Log4j-* in /ManageEngine/ADAuditPlus/apps/dataengine-xnode/lib Is there any fix or workaround?
Replacing default image
Hello, I'm trying to replace logos on SDP. I was able to customize the login page, but when requesters passwords expired, or they were forced to create a new password, the opened page for the new password shows the default logo of the SDP. I couldn't
Service Desk Plus - Apache Log4j 2
Hi, According to the recent "Apache Log4j Security Vulnerabilities", may I know how to identify the versions of the Log4j.jar. Current file I have is dated 5/5/2020. And please advise how to apply the fix? Note: I cannot find the "log4j-core" in directory.
[Security Advisory] Supportcenter Plus is not affected by CVE-2021-44228
Dear Users, We would like to inform you that Supportcenter Plus is not affected by the recent RCE vulnerability (CVE-2021-44228) reported in the Log4j framework. What is CVE-2021-44228 vulnerability? According to the Apache foundation, the reported
Important: SDP IOS Push Notification certificate has expired
Dear User ServiceDesk Plus IOS push notification certificate expired on 12th December 2021. Hence to overcome push notification issue, please follow the below steps : 1. Shut down the Servicedesk Plus application. 2. Navigate into <SDP_home>\conf folder.
CVE-2021-44228 AKA Log4j vulnerability for App Manager
Hello, Has it been determined if the latest build of Application Manager Plus is affected by the log4j vulnerability? If so what remediation/mitigation steps should be taken?
Looking for Comment on the log4j vulnerability
Looking for Comment on the log4j vulnerability and how ServiceDesk MSP is specifically affected. I don't see that there's been a comprehensive statement regarding ManageEngine products overall. https://pitstop.manageengine.com/portal/en/community/topic/log4j-cve-2021-44228-query-manage-engine-service-desk-plus
Precautionary steps to protect Log360 UEBA from Log4j vulnerabilities CVE-2021-45046, CVE-2021-44228, CVE-2021-45105, and CVE-2021-44832
In Log360 UEBA , the affected log4j version is used in the bundled dependency. Our security experts are analyzing the issue and as of now, we have no conclusive evidence of our product being affected by it. However, we strongly recommend all our customers
ServiceDesk Plus Log4j.jar
Is anyone aware of plans for Zoho to update Log4j in ServiceDesk Plus? Current file I have ServiceDesk\lib\log4j.jar is dated 17/03/2020 and there are no new service packs that I can see that related to the recently announced security vulnerabilities.
Next Page