Database Management
Database Performance Analyzer (DPA) and the Apache Log4j Vulnerabilities: CVE-2021-44228, CVE-2021-45046, CVE-2021-45105, CVE-2021-4104, and CVE-2021-44832
In December 2021, five CVEs were released for third-party vulnerabilities detected in Apache Log4j software, which is used widely across the software industry. This third-party component is used in very limited instances within a small subsection of SolarWinds products. This article describes how the following security bulletins affect SolarWinds DPA: CVE-2021-44228, CVE-2021-45046, CVE-2021-45105, CVE-2021-4104, and CVE-2021-44832.
First published date
Last published date
Overview
In December 2021, the following security bulletins were released for third-party vulnerabilities detected in Apache Log4j:
- CVE-2021-44228
- CVE-2021-45046
- CVE-2021-45105
- CVE-2021-4104
- CVE-2021-44832
(© 2021 National Institute of Standards and Technology, available at nvd.nist.gov, obtained on January 7, 2022)
Apache Log4j is a popular Java logging library from Apache Software that is incorporated into a wide range of enterprise software. Vulnerabilities indicated in these CVEs affect numerous software companies. This third-party component is used in very limited instances within a small subsection of SolarWinds products.
Only CVE-2021-44228, CVE-2021-45046, and CVE-2021-45105, and CVE-2021-44832 affect SolarWinds SAM and SolarWinds DPA. Those four CVEs do not affect any other SolarWinds or N-able (formerly SolarWinds MSP) products.
CVE-2021-4104 does not affect any SolarWinds or N-able products.
This article describes how to resolve the issue if you are running DPA 2021.1.x, DPA 2021.3.x, or DPA 2022.1 RC1. To learn about SAM, see Server & Application Monitor (SAM) and the Apache Log4j Vulnerabilities: CVE-2021-44228, CVE-2021-45046, and CVE-2021-4104.
Additional resources include:
- Apache Log4j Critical Vulnerability (CVE-2021-44228) Security Advisory Summary (© 2021 The Apache Software Foundation, available at logging.apache.org/, obtained on December 13, 2021)
- Apache Log4j Security Vulnerabilities (© 2021 The Apache Software Foundation, available at logging.apache.org/, obtained on December 13, 2021)
- Apache Releases Log4j Version 2.15.0 to Address Critical RCE Vulnerability Under Exploitation (© 2021 Department of Homeland Security, available at cisa.gov, obtained on December 13, 2021)
Product section
Cause
- CVE-2021-44228
- CVE-2021-45046
- CVE-2021-45105
- CVE-2021-44832
Resolution
Affected versions
IMPORTANT! Perform these steps only if you are running one of the following versions of DPA:
- DPA 2021.1.x
- DPA 2021.3.x
- DPA 2022.1 RC1
Where is each CVE fixed?
| CVE | Log4j version that fixes the CVE | How to get the fix |
|---|---|---|
| CVE-2021-44228 | 2.15 (Released December 9, 2021) |
If you previously applied DPA 2021.1.x Hotfix 2 or DPA 2021.3.x Hotfix 2, you have this fix. If not, see Upgrade or apply a Hotfix below. |
| CVE-2021-45046 | 2.16 (Released December 13, 2021) |
If you previously applied DPA 2021.1.x Hotfix 2 or DPA 2021.3.x Hotfix 2, you have this fix. If not, see Upgrade or apply a Hotfix below. |
| CVE-2021-45105 | 2.17 (Released December 17, 2021) |
If you previously applied DPA 2021.1.x Hotfix 3, upgraded to DPA 2021.3.7451, or upgraded from DPA 2022.1 RC1 to DPA 2022.1 RC2, you have this fix. If not, see Upgrade or apply a Hotfix below. |
| CVE-2021-44832 | 2.17.1 (Released December 28, 2021) | See Upgrade or apply a Hotfix below. |
Upgrade or apply a Hotfix
On January 7, 2022, SolarWinds made releases available that install version 2.17.1 of the affected files. Version 2.17.1 fixes CVE-2021-44228, CVE-2021-45046, CVE-2021-45105, and CVE-2021-44832.
| If you are running: | Do this: |
|---|---|
| DPA 2021.1.x | Apply DPA 2021.1.x Hotfix 4. |
| DPA 2021.3.x | Apply DPA 2021.3.x Hotfix 3. |
| DPA 2022.1 RC2 | Upgrade to DPA 2022.1 GA or later |
To apply a Hotfix, download the Hotfix for your DPA version from the Customer Portal, and then follow the installation instructions in the associated release notes.
To upgrade, download the new version from the Customer Portal, and then follow the installation instructions in the DPA Installation and Upgrade Guide.
NOTE: Manually replacing the affected files is not recommended. SolarWinds recommends upgrading or applying a hotfix. If you have problems upgrading or applying a hotfix, please contact Support.