Start a Conversation

Solved!

Go to Solution

613

February 9th, 2022 03:00

Log4J library in OMC Nagios Core plugin

Hello community,

 

I'm writing this because I have a little question. I'm using Dell EMC openManage plugin for Nagios Core (v3.1). It seems like this plugin uses the library log4j-1.2.6 that in theory is not an exploitable version, however it is a very outdated one and IT CYB team request us to update it. Do you know if there is a problem in changing/update that library using a 2.x version not vulnerable?

I'm not sure what methods is the plugin using from that library, but if anyone could confirm that we could use the newset version without problems, could be perfect.

Thanks in advance.

BR,
Juanma.

February 16th, 2022 23:00

At the end, if you disable the log function you can delete that library without any problem.

No Events found!

Top