Database Management

Database Performance Analyzer (DPA) and the Apache Log4j Vulnerabilities: CVE-2021-44228, CVE-2021-45046, CVE-2021-45105, CVE-2021-4104, and CVE-2021-44832

In December 2021, five CVEs were released for third-party vulnerabilities detected in Apache Log4j software, which is used widely across the software industry. This third-party component is used in very limited instances within a small subsection of SolarWinds products. This article describes how the following security bulletins affect SolarWinds DPA: CVE-2021-44228, CVE-2021-45046, CVE-2021-45105, CVE-2021-4104, and CVE-2021-44832.

First published date

12/13/2021 1:29 AM

Last published date

5/8/2023 11:29 PM

Overview

In December 2021, the following security bulletins were released for third-party vulnerabilities detected in Apache Log4j:

Apache Log4j is a popular Java logging library from Apache Software that is incorporated into a wide range of enterprise software. Vulnerabilities indicated in these CVEs affect numerous software companies. This third-party component is used in very limited instances within a small subsection of SolarWinds products.

Only CVE-2021-44228, CVE-2021-45046, and CVE-2021-45105, and CVE-2021-44832 affect SolarWinds SAM and SolarWinds DPA. Those four CVEs do not affect any other SolarWinds or N-able (formerly SolarWinds MSP) products.

CVE-2021-4104 does not affect any SolarWinds or N-able products.

This article describes how to resolve the issue if you are running DPA 2021.1.x, DPA 2021.3.x, or DPA 2022.1 RC1. To learn about SAM, see Server & Application Monitor (SAM) and the Apache Log4j Vulnerabilities: CVE-2021-44228, CVE-2021-45046, and CVE-2021-4104.

Additional resources include:

Product section

Database Performance Analyzer

Cause

  • CVE-2021-44228
  • CVE-2021-45046
  • CVE-2021-45105
  • CVE-2021-44832

Resolution

Affected versions

IMPORTANT! Perform these steps only if you are running one of the following versions of DPA:

  • DPA 2021.1.x
  • DPA 2021.3.x
  • DPA 2022.1 RC1

Where is each CVE fixed?

CVELog4j version that fixes the CVEHow to get the fix
CVE-2021-442282.15
(Released December 9, 2021)

If you previously applied DPA 2021.1.x Hotfix 2 or DPA 2021.3.x Hotfix 2, you have this fix. 

If not, see Upgrade or apply a Hotfix below.

CVE-2021-450462.16
(Released December 13, 2021)

If you previously applied DPA 2021.1.x Hotfix 2 or DPA 2021.3.x Hotfix 2, you have this fix. 

If not, see Upgrade or apply a Hotfix below.

CVE-2021-451052.17
(Released December 17, 2021)

If you previously applied DPA 2021.1.x Hotfix 3, upgraded to DPA 2021.3.7451, or upgraded from DPA 2022.1 RC1 to DPA 2022.1 RC2, you have this fix. 

If not, see Upgrade or apply a Hotfix below.

CVE-2021-448322.17.1 (Released December 28, 2021)See Upgrade or apply a Hotfix below.

Upgrade or apply a Hotfix

On January 7, 2022, SolarWinds made releases available that install version 2.17.1 of the affected files. Version 2.17.1 fixes CVE-2021-44228, CVE-2021-45046, CVE-2021-45105, and CVE-2021-44832. 

If you are running:Do this:
DPA 2021.1.xApply DPA 2021.1.x Hotfix 4.
DPA 2021.3.xApply DPA 2021.3.x Hotfix 3.
DPA 2022.1 RC2Upgrade to DPA 2022.1 GA or later

To apply a Hotfix, download the Hotfix for your DPA version from the Customer Portal, and then follow the installation instructions in the associated release notes.

To upgrade, download the new version from the Customer Portal, and then follow the installation instructions in the DPA Installation and Upgrade Guide.

NOTE: Manually replacing the affected files is not recommended. SolarWinds recommends upgrading or applying a hotfix. If you have problems upgrading or applying a hotfix, please contact Support.