{"id":2607,"date":"2021-12-14T10:40:36","date_gmt":"2021-12-14T10:40:36","guid":{"rendered":"https:\/\/www.sebae.net\/blog\/?p=2607"},"modified":"2021-12-14T11:00:16","modified_gmt":"2021-12-14T11:00:16","slug":"vmware-workaround-instructions-to-address-cve-2021-44228-in-vcenter-server-and-vcenter-cloud-gateway","status":"publish","type":"post","link":"https:\/\/www.sebae.net\/blog\/vmware-workaround-instructions-to-address-cve-2021-44228-in-vcenter-server-and-vcenter-cloud-gateway\/","title":{"rendered":"VMware Workaround Instructions To Address CVE-2021-44228 In vCenter Server and vCenter Cloud Gateway"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Customers should already be aware of the latest Apache Log4j  vulnerability  which is affecting servers worldwide.  Any system that currently runs Log4j must take action to address this critical vulnerability.  VMware have issued workaround instructions to address CVE-2021-44228 In vCenter Server and vCenter Cloud Gateway.  This  vulnerability has a CVE score of 10 (critical), customers are advised to issue these workarounds immediately.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If customers require assistance from Sebae, please get in <a href=\"https:\/\/www.sebae.net\/contact-us\">touch<\/a> with us.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Updated On: 13\/12\/2021<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">CVE(s):  CVE-2021-44228 <\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-exchange-server-security-updates\"><span id=\"impacted-products\"><strong>Impacted Products<\/strong><\/span><\/h2>\n\n\n\n<ul class=\"is-style-cnvs-list-styled wp-block-list\"><li>VMware vCenter Server and vCenter Cloud Gateway<\/li><\/ul>\n\n\n\n<h2 id=\"2-introduction\" class=\"wp-block-heading\"><strong>2. Introduction<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">CCVE-2021-44228 has been determined to impact vCenter Server 7.0.x, vCenter 6.7.x &amp; vCenter 6.5.x via the Apache Log4j open source component it ships. &nbsp;This vulnerability and its impact on VMware products are documented in the following VMware Security Advisory (VMSA), please review this document before continuing:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">CVE-2021-44228 &#8211;&nbsp;<a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2021-0028.html\" target=\"_blank\" rel=\"noreferrer noopener\">VMSA-2021-0028<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Highlighted sections indicate the most recent updates. See the <strong>Change log<\/strong> at the end of this article for all changes and subscribe the article for updates.<\/p>\n\n\n\n<h3 id=\"impact-risks\" class=\"wp-block-heading\">Impact \/ Risks<\/h3>\n\n\n\n<ul class=\"wp-block-list\"><li>VCHA needs to be removed before executing the steps in this KB article.<\/li><li>Environments with external PSCs need to have the steps taken on both vCenter and PSC appliances.<\/li><\/ul>\n\n\n\n<h3 id=\"resolution\" class=\"wp-block-heading\">Resolution<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The workarounds described in this document are meant to be a temporary solution only.<br>Upgrades documented in the aforementioned advisory should be applied to remediate CVE-2021-44228 when available<\/p>\n\n\n\n<h3 id=\"workaround\" class=\"wp-block-heading\">Workaround<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">To apply the workaround for CVE-2021-44228 with an <strong>automated script,<\/strong> please use the following link:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/kb.vmware.com\/s\/article\/87088\">Python script to automate the workaround steps of VMSA-2021-0028 vulnerability on vCenter Server Appliance<\/a> (Recommended)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To <strong>manually apply the workaround<\/strong> for CVE-2021-44228 to vCenter Server Appliance 7.x and 6.x, skip to the relevant sections below:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To <strong>manually apply the workaround<\/strong> for CVE-2021-44228 to vCenter Server Appliance 7.x and 6.x, skip to the relevant sections below:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/kb.vmware.com\/s\/article\/87081#vCenter7.0\">Click here for vCenter Server Appliance 7.0.x workaround<\/a><br><br><a href=\"https:\/\/kb.vmware.com\/s\/article\/87081#vCenter67\">Click here for vCenter Server Appliance 6.7.x workaround<\/a><br><br><a href=\"https:\/\/kb.vmware.com\/s\/article\/87081#vCenter65\">Click here for vCenter Server Appliance 6.5.x workaround<\/a><br><br><a href=\"https:\/\/kb.vmware.com\/s\/article\/87081#vCenter60\">Click here for vCenter Server Appliance 6.0.x workaround<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Note: <\/strong>For <strong>vCenter Cloud Gateway<\/strong>, only the steps for the <strong>vMon Service<\/strong> and <strong>Analytics Service<\/strong> are necessary.<\/p>\n\n\n\n<h3 id=\"vcenter-server-appliance-7-0-x-workaround\" class=\"wp-block-heading\"><a><strong>vCenter Server Appliance 7.0.x Workaround<\/strong><\/a><br><\/h3>\n\n\n\n<h3 id=\"vmon-service\" class=\"wp-block-heading\"><strong>vMON&nbsp;Service<\/strong><\/h3>\n\n\n\n<ol class=\"wp-block-list\"><li>Backup the existing java-wrapper-vmon file<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">cp -rfp \/usr\/lib\/vmware-vmon\/java-wrapper-vmon \/usr\/lib\/vmware-vmon\/java-wrapper-vmon.bak<\/p>\n\n\n\n<ol class=\"wp-block-list\" start=\"2\"><li>Update the java-wrapper-vmon file with a text editor such as vi<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">vi \/usr\/lib\/vmware-vmon\/java-wrapper-vmon<\/p>\n\n\n\n<ol class=\"wp-block-list\" start=\"3\"><li>At the very bottom of the file, replace the very last line with 2 new lines<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Execute this step number &#8216;3&#8217;&nbsp;based on the vCenter version running in your environment.<br>NOTE :- The below update (mentioned in Step number 3) applies ONLY to the vCenter versions listed below&nbsp;:-<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>vCenter 7.0 Update 3, 3a, 3b<\/strong><\/li><li><strong>vCenter 7.0 Update 2, 2a, 2b, 2c, 2d<\/strong><\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Original<br>exec $java_start_bin $jvm_dynargs $security_dynargs $original_args<br>&nbsp; Updated<br>log4j_arg=&#8221;-Dlog4j2.formatMsgNoLookups=true&#8221;<br>exec $java_start_bin $jvm_dynargs $log4j_arg $security_dynargs $original_args<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>NOTE :- The below update (mentioned in Step number 3) applies ONLY to the vCenter versions listed below&nbsp;:-<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>vCenter 7.0 GA, 7.0.0a, 7.0.0b, 7.0.0c, 7.0.0d<\/strong><\/li><li><strong>vCenter 7.0 Update 1, U1a, U1c, U1d<\/strong><\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Original<br>exec $java_start_bin $jvm_dynargs &#8220;$@&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Updated<br>log4j_arg=&#8221;-Dlog4j2.formatMsgNoLookups=true&#8221;<br>exec $java_start_bin $jvm_dynargs $log4j_arg &#8220;$@&#8221;<\/p>\n\n\n\n<ol class=\"wp-block-list\" start=\"4\"><li>Ensure the file permissions are set correctly with the below&nbsp;commands:<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">chown root:cis \/usr\/lib\/vmware-vmon\/java-wrapper-vmon<br>chmod 754 \/usr\/lib\/vmware-vmon\/java-wrapper-vmon<\/p>\n\n\n\n<ol class=\"wp-block-list\" start=\"4\"><li>Restart vCenter Services<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">service-control &#8211;stop &#8211;all<br>service-control &#8211;start &#8211;all<\/p>\n\n\n\n<h3 id=\"update-manager-service\" class=\"wp-block-heading\"><strong>Update Manager Service<\/strong><\/h3>\n\n\n\n<ol class=\"wp-block-list\"><li>Back up the existing start.ini file<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">cp -rfp \/usr\/lib\/vmware-updatemgr\/bin\/jetty\/start.ini \/usr\/lib\/vmware-updatemgr\/bin\/jetty\/start.ini.bak<\/p>\n\n\n\n<ol class=\"wp-block-list\" start=\"2\"><li>Update the start.ini file<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">vi \/usr\/lib\/vmware-updatemgr\/bin\/jetty\/start.ini<\/p>\n\n\n\n<ol class=\"wp-block-list\" start=\"3\"><li>Add the following line to the end of the file<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">-Dlog4j2.formatMsgNoLookups=true<\/p>\n\n\n\n<ol class=\"wp-block-list\" start=\"4\"><li>Restart the Update Manager Service<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">service-control &#8211;restart vmware-updatemgr<\/p>\n\n\n\n<h3 id=\"analytics-service\" class=\"wp-block-heading\"><strong>Analytics Service<\/strong><\/h3>\n\n\n\n<ol class=\"wp-block-list\"><li>Back up the log4j-core-2.8.2.jar file<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">cp -rfp \/usr\/lib\/vmware\/common-jars\/log4j-core-2.8.2.jar \/usr\/lib\/vmware\/common-jars\/log4j-core-2.8.2.jar.bak<\/p>\n\n\n\n<ol class=\"wp-block-list\" start=\"2\"><li>Run the zip command to disable the class<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">zip -q -d \/usr\/lib\/vmware\/common-jars\/log4j-core-2.8.2.jar org\/apache\/logging\/log4j\/core\/lookup\/JndiLookup.class<\/p>\n\n\n\n<ol class=\"wp-block-list\" start=\"3\"><li>Restart the Analytics service<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">service-control &#8211;restart vmware-analytics<\/p>\n\n\n\n<h3 id=\"verify-the-changes\" class=\"wp-block-heading\"><strong>Verify the changes<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Once all sections are complete, use the following steps to confirm if they were implemented successfully.<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>Verify if the vMon services were started with the new -Dlog4j2.formatMsgNoLookups=true parameter:<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">ps auxww | grep formatMsgNoLookups<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Check if the processes include -Dlog4j2.formatMsgNoLookups=true<\/p>\n\n\n\n<ol class=\"wp-block-list\" start=\"2\"><li>Verify the Update Manager changes are shown under &#8220;System Properties&#8221; in the output of the following two commands:<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">cd \/usr\/lib\/vmware-updatemgr\/bin\/jetty\/<br>java -jar start.jar &#8211;list-config<br>&nbsp;<br><em>System Properties:<br>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br>&nbsp;log4j2.formatMsgNoLookups = true (\/usr\/lib\/vmware-updatemgr\/bin\/jetty\/start.ini<\/em>)<\/p>\n\n\n\n<ol class=\"wp-block-list\" start=\"3\"><li>Verify the Analytics Service changes:<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">grep -i jndilookup \/usr\/lib\/vmware\/common-jars\/log4j-core-2.8.2.jar | wc -l<br>&nbsp; This should return 0 lines&nbsp;<\/p>\n\n\n\n<h3 id=\"vcenter-server-appliance-6-7-x-workaround\" class=\"wp-block-heading\"><a><strong>vCenter Server Appliance 6.7.x Workaround<\/strong><\/a><\/h3>\n\n\n\n<h4 id=\"vmon-service-2\" class=\"wp-block-heading\"><strong>vMON&nbsp;Service<\/strong><\/h4>\n\n\n\n<ol class=\"wp-block-list\"><li>Backup the existing java-wrapper-vmon file<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">cp -rfp \/usr\/lib\/vmware-vmon\/java-wrapper-vmon \/usr\/lib\/vmware-vmon\/java-wrapper-vmon.bak<\/p>\n\n\n\n<ol class=\"wp-block-list\" start=\"2\"><li>Update the java-wrapper-vmon file with a text editor such as vi<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">vi \/usr\/lib\/vmware-vmon\/java-wrapper-vmon<\/p>\n\n\n\n<ol class=\"wp-block-list\" start=\"3\"><li>At the very bottom of the file, replace the very last line with 2 new lines<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Original exec $java_start_bin $jvm_dynargs &#8220;$@&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><br>Updated<br>log4j_arg=&#8221;-Dlog4j2.formatMsgNoLookups=true&#8221;<br>exec $java_start_bin $jvm_dynargs $log4j_arg &#8220;$@&#8221;&nbsp;<\/p>\n\n\n\n<ol class=\"wp-block-list\" start=\"3\"><li>Restart vCenter Services<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">service-control &#8211;stop &#8211;all<br>service-control &#8211;start &#8211;all<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Note:<\/strong> If the services do not start, ensure the file permissions are set correctly with these commands:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>chown root:cis \/usr\/lib\/vmware-vmon\/java-wrapper-vmon<\/li><li>chmod 754 \/usr\/lib\/vmware-vmon\/java-wrapper-vmon<\/li><\/ul>\n\n\n\n<h3 id=\"analytics-service-2\" class=\"wp-block-heading\"><strong><u>Analytics Service<\/u><\/strong><\/h3>\n\n\n\n<h4 id=\"note-the-below-workaround-analytics-service-is-applicable-for-vcenter-server-appliance-6-7-update-3o-and-older-versions-only-vcenter-server-appliance-6-7-update-3p-is-by-default-covered-by-vmon-s\" class=\"wp-block-heading\"><strong>NOTE:- The below workaround (Analytics service) is applicable for vCenter Server Appliance 6.7 Update 3o and Older versions only. vCenter Server Appliance 6.7 Update 3p is by default covered by vMON Service workaround and is verified with the &#8216;ps auxww&#8217; command.&nbsp;<\/strong><\/h4>\n\n\n\n<ol class=\"wp-block-list\"><li>Back up the log4j-core-2.8.2.jar file<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">cp -rfp \/usr\/lib\/vmware\/common-jars\/log4j-core-2.8.2.jar \/usr\/lib\/vmware\/common-jars\/log4j-core-2.8.2.jar.bak<\/p>\n\n\n\n<ol class=\"wp-block-list\" start=\"2\"><li>Run the zip command to disable the class<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">zip -q -d \/usr\/lib\/vmware\/common-jars\/log4j-core-2.8.2.jar org\/apache\/logging\/log4j\/core\/lookup\/JndiLookup.class<\/p>\n\n\n\n<ol class=\"wp-block-list\" start=\"3\"><li>Restart the Analytics service<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">service-control &#8211;restart vmware-analytics &nbsp;<\/p>\n\n\n\n<h3 id=\"cm-service\" class=\"wp-block-heading\"><strong>CM Service<\/strong><\/h3>\n\n\n\n<ol class=\"wp-block-list\"><li>Back up the log4j-core.jar file<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">cp -rfp \/usr\/lib\/vmware-cm\/lib\/log4j-core.jar \/usr\/lib\/vmware-cm\/lib\/log4j-core.jar.bak<\/p>\n\n\n\n<ol class=\"wp-block-list\" start=\"2\"><li>Run the zip command to disable the class<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">zip -q -d \/usr\/lib\/vmware-cm\/lib\/log4j-core.jar org\/apache\/logging\/log4j\/core\/lookup\/JndiLookup.class<\/p>\n\n\n\n<ol class=\"wp-block-list\" start=\"3\"><li>Restart the CM service<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">service-control &#8211;stop vmware-cm<br>service-control &#8211;start vmware-cm<\/p>\n\n\n\n<h3 id=\"secure-token-service\" class=\"wp-block-heading\"><br><strong>Secure Token Service<\/strong><\/h3>\n\n\n\n<ol class=\"wp-block-list\"><li>Back up and edit the the&nbsp;vmware-stsd file<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">cp \/etc\/rc.d\/init.d\/vmware-stsd \/root\/vmware-stsd.bak vi \/etc\/rc.d\/init.d\/vmware-stsd<\/p>\n\n\n\n<ol class=\"wp-block-list\" start=\"2\"><li>Find the section labeled start_service(). Insert a new line near line 266, just before &#8220;$DAEMON_CLASS start&#8221; with &#8220;-Dlog4j2.formatMsgNoLookups=true \\&#8221; as seen in the example:<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">start_service()<br>{<br>&nbsp; perform_pre_startup_actions<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&nbsp; local retval<br>&nbsp; JAVA_MEM_ARGS=`\/usr\/sbin\/cloudvm-ram-size -J vmware-stsd`<br>&nbsp; $JSVC_BIN -procname $SERVICE_NAME \\<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; -home $JAVA_HOME \\<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; -server \\<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;snip&gt;<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; -Dauditlog.dir=\/var\/log\/audit\/sso-events&nbsp; \\<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <span class=\"has-inline-color has-red-color\">-Dlog4j2.formatMsgNoLookups=true \\<\/span><br>&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;$DAEMON_CLASS start<\/p>\n\n\n\n<ol class=\"wp-block-list\" start=\"3\"><li>Restart the vmware-stsd service<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">service-control &#8211;stop vmware-stsd<br>service-control &#8211;start vmware-stsd<\/p>\n\n\n\n<h3 id=\"identity-management-service\" class=\"wp-block-heading\"><strong>Identity Management Service<\/strong><\/h3>\n\n\n\n<ol class=\"wp-block-list\"><li>Back up and edit the the&nbsp;vmware-sts-idmd file<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">cp \/etc\/rc.d\/init.d\/vmware-sts-idmd \/root\/vmware-sts-idmd.bak vi \/etc\/rc.d\/init.d\/vmware-sts-idmd<\/p>\n\n\n\n<ol class=\"wp-block-list\" start=\"2\"><li>Insert a new line near line 177 before &#8220;$DEBUG_OPTS \\&#8221; with &#8220;-Dlog4j2.formatMsgNoLookups=true \\&#8221; as seen in the example:<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">$JSVC_BIN -procname $SERVICE_NAME \\<br>&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp; -wait 120 \\<br>&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp; -server \\<br>&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp; &lt;snip&gt;<br>&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp; -Dlog4j.configurationFile=file:\/\/$PREFIX\/share\/config\/log4j2.xml \\<br>&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;<span class=\"has-inline-color has-red-color\"> -Dlog4j2.formatMsgNoLookups=true \\<\/span><br>&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp; $DEBUG_OPTS \\<br>&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp; $DAEMON_CLASS<\/p>\n\n\n\n<ol class=\"wp-block-list\" start=\"3\"><li>Restart the vmware-sts-idmd service<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">service-control &#8211;stop vmware-sts-idmd<br>service-control &#8211;start vmware-sts-idmd<\/p>\n\n\n\n<h3 id=\"verify-the-changes-2\" class=\"wp-block-heading\"><strong>Verify the changes<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Once all sections are complete, use the following steps to confirm if they were implemented successfully.<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>Verify if the stsd, idmd, and vMon controlled services were started with the new -Dlog4j2.formatMsgNoLookups=true parameter:<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">ps auxww | grep formatMsgNoLookups<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Check if the processes include -Dlog4j2.formatMsgNoLookups=true<\/p>\n\n\n\n<ol class=\"wp-block-list\" start=\"2\"><li>Verify the Analytics Service changes:<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">grep -i jndilookup \/usr\/lib\/vmware\/common-jars\/log4j-core-2.8.2.jar | wc -l<br>&nbsp; This should return 0 lines<\/p>\n\n\n\n<ol class=\"wp-block-list\" start=\"3\"><li>Verify the CM Service changes:<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">grep -i jndilookup \/usr\/lib\/vmware-cm\/lib\/log4j-core.jar | wc -l<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This should return 0 lines<\/p>\n\n\n\n<h3 id=\"vcenter-server-appliance-6-5-x-workaround\" class=\"wp-block-heading\"><a><strong>vCenter Server Appliance 6.5.x Workaround&nbsp;<\/strong><\/a><\/h3>\n\n\n\n<h4 id=\"vmon-service-3\" class=\"wp-block-heading\"><strong>vMON&nbsp;Service<\/strong><\/h4>\n\n\n\n<ol class=\"wp-block-list\"><li>Backup the existing java-wrapper-vmon file<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">cp -rfp \/usr\/lib\/vmware-vmon\/java-wrapper-vmon \/usr\/lib\/vmware-vmon\/java-wrapper-vmon.bak<\/p>\n\n\n\n<ol class=\"wp-block-list\" start=\"2\"><li>Update the java-wrapper-vmon file with a text editor such as vi<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">vi \/usr\/lib\/vmware-vmon\/java-wrapper-vmon<\/p>\n\n\n\n<ol class=\"wp-block-list\" start=\"3\"><li>At the very bottom of the file, replace the very last line with 2 new lines<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Original exec $java_start_bin $jvm_dynargs &#8220;$@&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><br>Updated<br>log4j_arg=&#8221;-Dlog4j2.formatMsgNoLookups=true&#8221;<br>exec $java_start_bin $jvm_dynargs $log4j_arg &#8220;$@&#8221;&nbsp;<\/p>\n\n\n\n<ol class=\"wp-block-list\" start=\"3\"><li>Restart vCenter Services<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">service-control &#8211;stop &#8211;all<br>service-control &#8211;start &#8211;all<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Note:<\/strong> If the services do not start, ensure the file permissions are set correctly with these commands:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>chown root:cis \/usr\/lib\/vmware-vmon\/java-wrapper-vmon<\/li><li>chmod 754 \/usr\/lib\/vmware-vmon\/java-wrapper-vmon<\/li><\/ul>\n\n\n\n<h3 id=\"cm-service-2\" class=\"wp-block-heading\"><strong>CM Service<\/strong><\/h3>\n\n\n\n<ol class=\"wp-block-list\"><li>Back up the log4j-core.jar file<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">cp -rfp \/usr\/lib\/vmware-cm\/lib\/log4j-core.jar \/usr\/lib\/vmware-cm\/lib\/log4j-core.jar.bak<\/p>\n\n\n\n<ol class=\"wp-block-list\" start=\"2\"><li>Run the zip command to disable the class<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">zip -q -d \/usr\/lib\/vmware-cm\/lib\/log4j-core.jar org\/apache\/logging\/log4j\/core\/lookup\/JndiLookup.class<\/p>\n\n\n\n<ol class=\"wp-block-list\" start=\"3\"><li>Restart the CM service<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">service-control &#8211;stop vmware-cm<br>service-control &#8211;start vmware-cm<\/p>\n\n\n\n<h3 id=\"secure-token-service-2\" class=\"wp-block-heading\"><strong>Secure Token Service<\/strong><\/h3>\n\n\n\n<ol class=\"wp-block-list\"><li>Back up and edit the the&nbsp;vmware-stsd file<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">cp \/etc\/rc.d\/init.d\/vmware-stsd \/root\/vmware-stsd.bak vi \/etc\/rc.d\/init.d\/vmware-stsd<\/p>\n\n\n\n<ol class=\"wp-block-list\" start=\"2\"><li>Find the section labeled start_service(). Insert a new line near line 266, just before &#8220;$DAEMON_CLASS start&#8221; with &#8220;-Dlog4j2.formatMsgNoLookups=true \\&#8221; as seen in the example:<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">start_service()<br>{<br>&nbsp; perform_pre_startup_actions<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&nbsp; local retval<br>&nbsp; $JSVC_BIN -procname $SERVICE_NAME \\<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; -home $JAVA_HOME \\<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; -server \\<br>&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&lt;snip&gt;<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; -Dauditlog.dir=\/var\/log\/audit\/sso-events&nbsp; \\<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <span class=\"has-inline-color has-red-color\">-Dlog4j2.formatMsgNoLookups=true \\<\/span><br>&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;$DAEMON_CLASS start<\/p>\n\n\n\n<ol class=\"wp-block-list\" start=\"3\"><li>Restart the vmware-stsd service<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">service-control &#8211;stop vmware-stsd<br>service-control &#8211;start vmware-stsd<\/p>\n\n\n\n<h3 id=\"identity-management-service-2\" class=\"wp-block-heading\"><strong>Identity Management Service<\/strong><\/h3>\n\n\n\n<ol class=\"wp-block-list\"><li>Back up and edit the the&nbsp;vmware-sts-idmd file<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">cp \/etc\/rc.d\/init.d\/vmware-sts-idmd \/root\/vmware-sts-idmd.bak vi \/etc\/rc.d\/init.d\/vmware-sts-idmd<\/p>\n\n\n\n<ol class=\"wp-block-list\" start=\"2\"><li>Insert a new line near line 177 before &#8220;$DEBUG_OPTS \\&#8221; with &#8220;-Dlog4j2.formatMsgNoLookups=true \\&#8221; as seen in the example:<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">$JSVC_BIN -procname $SERVICE_NAME \\<br>&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp; -wait 120 \\<br>&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp; -server \\<br>&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp; &lt;snip&gt;<br>&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp; -Dlog4j.configurationFile=file:\/\/$PREFIX\/share\/config\/log4j2.xml \\<br>&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp; <span class=\"has-inline-color has-red-color\">-Dlog4j2.formatMsgNoLookups=true \\<\/span><br>&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp; $DEBUG_OPTS \\<br>&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp; $DAEMON_CLASS<\/p>\n\n\n\n<ol class=\"wp-block-list\" start=\"3\"><li>Restart the vmware-sts-idmd service<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">service-control &#8211;stop vmware-sts-idmd<br>service-control &#8211;start vmware-sts-idmd<\/p>\n\n\n\n<h3 id=\"psc-client-service\" class=\"wp-block-heading\"><strong>PSC Client Service<\/strong><\/h3>\n\n\n\n<ol class=\"wp-block-list\"><li>Back up and edit the vmware-psc-client file<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">cp -rfp \/etc\/rc.d\/init.d\/vmware-psc-client \/root\/vmware-psc-client.bak<br>vi \/etc\/rc.d\/init.d\/vmware-psc-client<\/p>\n\n\n\n<ol class=\"wp-block-list\" start=\"2\"><li>Insert a new line near line 300, just before &#8220;$DAEMON_CLASS start&#8221; with &#8220;-Dlog4j2.formatMsgNoLookups=true \\&#8221; as seen in the example:<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">$JSVC_BIN -procname $SERVICE_NAME \\<br>&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;-home $JAVA_HOME \\<br>&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;-server \\<br>&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&lt;snip&gt;&nbsp;&nbsp; &nbsp;<br>&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;-Djava.io.tmpdir=&#8221;$CATALINA_BASE\/temp&#8221; \\<br>&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;<span class=\"has-inline-color has-red-color\">-Dlog4j2.formatMsgNoLookups=true \\<\/span><br>&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;$DAEMON_CLASS start<\/p>\n\n\n\n<ol class=\"wp-block-list\" start=\"3\"><li>Restart the vmware-psc-client service<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">service-control &#8211;stop vmware-psc-client<br>service-control &#8211;start vmware-psc-client &nbsp;<\/p>\n\n\n\n<h3 id=\"verify-the-changes-3\" class=\"wp-block-heading\"><strong>Verify the changes<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Once all sections are complete, use the following steps to confirm if they were implemented successfully.<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>Verify if the stsd, idmd, psc-client, and vMon controlled services were started with the new -Dlog4j2.formatMsgNoLookups=true parameter:<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">ps auxww | grep formatMsgNoLookups<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Check if the processes include -Dlog4j2.formatMsgNoLookups=true<\/p>\n\n\n\n<ol class=\"wp-block-list\" start=\"2\"><li>Verify the CM Service changes:<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">grep -i jndilookup \/usr\/lib\/vmware-cm\/lib\/log4j-core.jar | wc -l<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This should return 0 lines<\/p>\n\n\n\n<h3 id=\"vcenter-server-appliance-6-0-u3j-workaround\" class=\"wp-block-heading\"><a><strong>vCenter Server Appliance 6.0 U3j Workaround<\/strong><\/a><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">vCenter Server Appliance 6.0 U3j is no longer in general support but has also been identified as vulnerable to CVE-2021-44228 due to the Performance Charts service. Mitigation steps have been identified as follows:<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>Back up and edit \/usr\/lib\/vmware-perfcharts\/wrapper\/conf\/wrapper.conf on the appliance and add a new line just below &#8220;wrapper.java.additional.13=-Dlog4j.configurationFile=file:\/etc\/vmware-perfcharts\/log4j2.xml&#8221; (line 72) with the following content:<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">wrapper.java.additional.14=-Dlog4j2.formatMsgNoLookups=true<\/p>\n\n\n\n<ol class=\"wp-block-list\" start=\"2\"><li>Save the file, stop the service and then start it through service-control:<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">service-control &#8211;stop vmware-perfcharts<br>service-control &#8211;start vmware-perfcharts<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><br><strong>Note<\/strong>: <strong>vCenter Server Appliance versions 6.0GA &#8211; 6.0U3i are <u>not<\/u> vulnerable<\/strong>. However, versions 6.0 U3a\/b\/c\/d\/e\/f were found to contain the following unused vulnerable jar files. No impact on the product has been observed after removing these jar files.<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>\/opt\/pivotal\/pivotal-tc-server-standard\/templates\/gemfire-p2p\/lib\/log4j-core-2.1.jar<\/li><li>\/opt\/pivotal\/pivotal-tc-server-standard\/templates\/gemfire-p2p\/lib\/log4j-api-2.1.jar<\/li><li>\/opt\/pivotal\/pivotal-tc-server-standard\/templates\/gemfire-cs\/lib\/log4j-core-2.1.jar<\/li><li>\/opt\/pivotal\/pivotal-tc-server-standard\/templates\/gemfire-cs\/lib\/log4j-api-2.1.jar<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Related Information To revert the workarounds, replace the modified files with the backups created in each step.<br>VCHA needs to be disabled before executing the steps in this KB.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Change log:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>December 12th 2021 &#8211; 11:20 PST: Updated Knowledge Base article advising workarounds for 6.5\/6.7 partially address the vulnerability.<\/li><li>December 12th 2021 &#8211; 16:00 PST: Added steps for stsd, idmd and psc-client services to the workaround sections for 6.5 and 6.7.<\/li><li>December 12th 2021 &#8211; 17:00 PST: Added workaround for VCSA 6.0U3j.<\/li><li>December 12th 2021 &#8211; 18:30 PST: Added additional information for older versions of VCSA 6.0.<\/li><li>December 12th 2021 &#8211; 20:30 PST: Updated versions with vulnerable jar files in VCSA 6.0.<\/li><li>December 13th 2021 &#8211; 01:57 PST: Updated the steps in the vMON service commands for permission validation<\/li><li>December 13th 2021 &#8211; 16:30 PST: Simplified and re-arranged beginning of workaround section (no new content). Added clarification to 6.7U3p analytics verification steps. Updated cm service restart commands. Added highlighting to changelog.<\/li><li>December 13th 2021 &#8211; 20:05 PST: Removed&nbsp;DBCC Utility Workaround step from this article.&nbsp;VMware has tested this and does not have any impact or risk hence the workaround section was removed.<\/li><\/ul>\n","protected":false},"excerpt":{"rendered":"Customers should already be aware of the latest Apache Log4j vulnerability which is affecting servers worldwide. Any system&hellip;\n","protected":false},"author":2,"featured_media":2611,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"csco_singular_sidebar":"","csco_page_header_type":"","csco_appearance_grid":"","csco_page_load_nextpost":"","csco_post_video_location":[],"csco_post_video_location_hash":"","csco_post_video_url":"","csco_post_video_bg_start_time":0,"csco_post_video_bg_end_time":0,"footnotes":""},"categories":[16],"tags":[28,50,43],"coauthors":[48],"class_list":["post-2607","post","type-post","status-publish","format-standard","has-post-thumbnail","category-vmware-virtualisation","tag-security-updates","tag-vcsa","tag-vmware","cs-entry","cs-video-wrap"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>VMware Workaround Instructions To Address CVE-2021-44228 In vCenter Server and vCenter Cloud Gateway | Sebae Networks<\/title>\n<meta name=\"description\" content=\"VMware have issued workaround instructions to address CVE-2021-44228 In vCenter Server and vCenter Cloud Gateway.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.sebae.net\/blog\/vmware-workaround-instructions-to-address-cve-2021-44228-in-vcenter-server-and-vcenter-cloud-gateway\/\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"VMware Workaround Instructions To Address CVE-2021-44228 In vCenter Server and vCenter Cloud Gateway | Sebae Networks\" \/>\n<meta property=\"og:description\" content=\"VMware have issued workaround instructions to address CVE-2021-44228 In vCenter Server and vCenter Cloud Gateway.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.sebae.net\/blog\/vmware-workaround-instructions-to-address-cve-2021-44228-in-vcenter-server-and-vcenter-cloud-gateway\/\" \/>\n<meta property=\"og:site_name\" content=\"Sebae Networks\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/sebaenetworks\" \/>\n<meta property=\"article:published_time\" content=\"2021-12-14T10:40:36+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-12-14T11:00:16+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.sebae.net\/blog\/wp-content\/uploads\/2021\/12\/vmware-logo-critical-header.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1920\" \/>\n\t<meta property=\"og:image:height\" content=\"1080\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"James Dean\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@sebaenetworks\" \/>\n<meta name=\"twitter:site\" content=\"@sebaenetworks\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"James Dean\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"VMware Workaround Instructions To Address CVE-2021-44228 In vCenter Server and vCenter Cloud Gateway | Sebae Networks","description":"VMware have issued workaround instructions to address CVE-2021-44228 In vCenter Server and vCenter Cloud Gateway.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.sebae.net\/blog\/vmware-workaround-instructions-to-address-cve-2021-44228-in-vcenter-server-and-vcenter-cloud-gateway\/","og_locale":"en_GB","og_type":"article","og_title":"VMware Workaround Instructions To Address CVE-2021-44228 In vCenter Server and vCenter Cloud Gateway | Sebae Networks","og_description":"VMware have issued workaround instructions to address CVE-2021-44228 In vCenter Server and vCenter Cloud Gateway.","og_url":"https:\/\/www.sebae.net\/blog\/vmware-workaround-instructions-to-address-cve-2021-44228-in-vcenter-server-and-vcenter-cloud-gateway\/","og_site_name":"Sebae Networks","article_publisher":"https:\/\/www.facebook.com\/sebaenetworks","article_published_time":"2021-12-14T10:40:36+00:00","article_modified_time":"2021-12-14T11:00:16+00:00","og_image":[{"width":1920,"height":1080,"url":"https:\/\/www.sebae.net\/blog\/wp-content\/uploads\/2021\/12\/vmware-logo-critical-header.png","type":"image\/png"}],"author":"James Dean","twitter_card":"summary_large_image","twitter_creator":"@sebaenetworks","twitter_site":"@sebaenetworks","twitter_misc":{"Written by":"James Dean","Estimated reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.sebae.net\/blog\/vmware-workaround-instructions-to-address-cve-2021-44228-in-vcenter-server-and-vcenter-cloud-gateway\/#article","isPartOf":{"@id":"https:\/\/www.sebae.net\/blog\/vmware-workaround-instructions-to-address-cve-2021-44228-in-vcenter-server-and-vcenter-cloud-gateway\/"},"author":{"name":"James Dean","@id":"https:\/\/www.sebae.net\/blog\/#\/schema\/person\/6d07e05e3d3e4483117c4e2c3315a89f"},"headline":"VMware Workaround Instructions To Address CVE-2021-44228 In vCenter Server and vCenter Cloud Gateway","datePublished":"2021-12-14T10:40:36+00:00","dateModified":"2021-12-14T11:00:16+00:00","mainEntityOfPage":{"@id":"https:\/\/www.sebae.net\/blog\/vmware-workaround-instructions-to-address-cve-2021-44228-in-vcenter-server-and-vcenter-cloud-gateway\/"},"wordCount":2539,"commentCount":0,"publisher":{"@id":"https:\/\/www.sebae.net\/blog\/#organization"},"image":{"@id":"https:\/\/www.sebae.net\/blog\/vmware-workaround-instructions-to-address-cve-2021-44228-in-vcenter-server-and-vcenter-cloud-gateway\/#primaryimage"},"thumbnailUrl":"https:\/\/www.sebae.net\/blog\/wp-content\/uploads\/2021\/12\/vmware-logo-critical-header.png","keywords":["security updates","vcsa","vmware"],"articleSection":["VMware Virtualisation"],"inLanguage":"en-GB","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.sebae.net\/blog\/vmware-workaround-instructions-to-address-cve-2021-44228-in-vcenter-server-and-vcenter-cloud-gateway\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.sebae.net\/blog\/vmware-workaround-instructions-to-address-cve-2021-44228-in-vcenter-server-and-vcenter-cloud-gateway\/","url":"https:\/\/www.sebae.net\/blog\/vmware-workaround-instructions-to-address-cve-2021-44228-in-vcenter-server-and-vcenter-cloud-gateway\/","name":"VMware Workaround Instructions To Address CVE-2021-44228 In vCenter Server and vCenter Cloud Gateway | Sebae Networks","isPartOf":{"@id":"https:\/\/www.sebae.net\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.sebae.net\/blog\/vmware-workaround-instructions-to-address-cve-2021-44228-in-vcenter-server-and-vcenter-cloud-gateway\/#primaryimage"},"image":{"@id":"https:\/\/www.sebae.net\/blog\/vmware-workaround-instructions-to-address-cve-2021-44228-in-vcenter-server-and-vcenter-cloud-gateway\/#primaryimage"},"thumbnailUrl":"https:\/\/www.sebae.net\/blog\/wp-content\/uploads\/2021\/12\/vmware-logo-critical-header.png","datePublished":"2021-12-14T10:40:36+00:00","dateModified":"2021-12-14T11:00:16+00:00","description":"VMware have issued workaround instructions to address CVE-2021-44228 In vCenter Server and vCenter Cloud Gateway.","breadcrumb":{"@id":"https:\/\/www.sebae.net\/blog\/vmware-workaround-instructions-to-address-cve-2021-44228-in-vcenter-server-and-vcenter-cloud-gateway\/#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.sebae.net\/blog\/vmware-workaround-instructions-to-address-cve-2021-44228-in-vcenter-server-and-vcenter-cloud-gateway\/"]}]},{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.sebae.net\/blog\/vmware-workaround-instructions-to-address-cve-2021-44228-in-vcenter-server-and-vcenter-cloud-gateway\/#primaryimage","url":"https:\/\/www.sebae.net\/blog\/wp-content\/uploads\/2021\/12\/vmware-logo-critical-header.png","contentUrl":"https:\/\/www.sebae.net\/blog\/wp-content\/uploads\/2021\/12\/vmware-logo-critical-header.png","width":1920,"height":1080,"caption":"vmware logo critical header"},{"@type":"BreadcrumbList","@id":"https:\/\/www.sebae.net\/blog\/vmware-workaround-instructions-to-address-cve-2021-44228-in-vcenter-server-and-vcenter-cloud-gateway\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.sebae.net\/blog\/"},{"@type":"ListItem","position":2,"name":"VMware Workaround Instructions To Address CVE-2021-44228 In vCenter Server and vCenter Cloud Gateway"}]},{"@type":"WebSite","@id":"https:\/\/www.sebae.net\/blog\/#website","url":"https:\/\/www.sebae.net\/blog\/","name":"Sebae Networks","description":"Tech Tips, News, Tutorials &amp; Advice","publisher":{"@id":"https:\/\/www.sebae.net\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.sebae.net\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-GB"},{"@type":"Organization","@id":"https:\/\/www.sebae.net\/blog\/#organization","name":"Sebae","url":"https:\/\/www.sebae.net\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.sebae.net\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.sebae.net\/blog\/wp-content\/uploads\/2023\/06\/sebae-logo-icon.png","contentUrl":"https:\/\/www.sebae.net\/blog\/wp-content\/uploads\/2023\/06\/sebae-logo-icon.png","width":512,"height":512,"caption":"Sebae"},"image":{"@id":"https:\/\/www.sebae.net\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/sebaenetworks","https:\/\/x.com\/sebaenetworks"]},{"@type":"Person","@id":"https:\/\/www.sebae.net\/blog\/#\/schema\/person\/6d07e05e3d3e4483117c4e2c3315a89f","name":"James Dean","image":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.sebae.net\/blog\/wp-content\/uploads\/2021\/10\/avatar_user_2_1634496168-96x96.jpg72371c27260698ee55141397050ef40a","url":"https:\/\/www.sebae.net\/blog\/wp-content\/uploads\/2021\/10\/avatar_user_2_1634496168-96x96.jpg","contentUrl":"https:\/\/www.sebae.net\/blog\/wp-content\/uploads\/2021\/10\/avatar_user_2_1634496168-96x96.jpg","caption":"James Dean"},"sameAs":["https:\/\/www.sebae.net"],"url":"https:\/\/www.sebae.net\/blog\/author\/jdean\/"}]}},"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/www.sebae.net\/blog\/wp-json\/wp\/v2\/posts\/2607","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.sebae.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.sebae.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.sebae.net\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.sebae.net\/blog\/wp-json\/wp\/v2\/comments?post=2607"}],"version-history":[{"count":2,"href":"https:\/\/www.sebae.net\/blog\/wp-json\/wp\/v2\/posts\/2607\/revisions"}],"predecessor-version":[{"id":2612,"href":"https:\/\/www.sebae.net\/blog\/wp-json\/wp\/v2\/posts\/2607\/revisions\/2612"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.sebae.net\/blog\/wp-json\/wp\/v2\/media\/2611"}],"wp:attachment":[{"href":"https:\/\/www.sebae.net\/blog\/wp-json\/wp\/v2\/media?parent=2607"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.sebae.net\/blog\/wp-json\/wp\/v2\/categories?post=2607"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.sebae.net\/blog\/wp-json\/wp\/v2\/tags?post=2607"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www.sebae.net\/blog\/wp-json\/wp\/v2\/coauthors?post=2607"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}