SolarWinds Server & Application Monitor (SAM)


Vendor Data Vendor Patch Exists
Community Data Vulnerable

Vendor Resources

Resource Link
Apache Log4j Critical Vulnerability (CVE-2021-44228) https://www.solarwinds.com/trust-center/security-advisories/cve-2021-44228
Server & Application Monitor (SAM) and the Apache Log4j Vulnerability (CVE-2021-44228) https://support.solarwinds.com/SuccessCenter/s/article/Server-Application-Monitor-SAM-and-the-Apache-Log4j-Vulnerability-CVE-2021-44228?language=en_US

Community Resources

Resource Link
Apache Log4j Critical Vulnerability (CVE-2021-44228) https://www.solarwinds.com/trust-left/security-advisories/cve-2021-44228
Server & Application Monitor (SAM) and the Apache Log4j Vulnerability (CVE-2021-44228) https://support.solarwinds.com/SuccessCenter/s/article/Server-Application-Monitor-SAM-and-the-Apache-Log4j-Vulnerability-CVE-2021-44228?language=en_US

Community Notes

Source Note
NCSC-NL CVE-2021-44228: Vulnerable
NCSC-NL Workarounds available, hotfix under development
CISAGov For more information, please see the following KB article for the latest details specific to the SAM hotfix: link
CISAGov Last Update: 12/23/2021

Sources

Date Attribution Description
2022-01-03 13:16:44 NCSC-NL Updated communityVulnerable. Updated community note. Updated community link Apache Log4j Critical Vulnerability (CVE-2021-44228). Updated community link Server & Application Monitor (SAM) and the Apache Log4j Vulnerability (CVE-2021-44228). Updated community note.
2021-12-30 21:31:50 CISAGov Updated communityVulnerable. Updated vendorPatchExists. Updated vendor link Apache Log4j Critical Vulnerability (CVE-2021-44228). Updated vendor link Server & Application Monitor (SAM) and the Apache Log4j Vulnerability (CVE-2021-44228). Updated community note. Updated community note.