With the onslaught of log4j updates that have been coming out since mid-December 2021, many VMware customers have been anxiously awaiting product updates and workarounds for the vRealize Suite of products.
As of January 18, 2022, all of the products that make up the vRealize Suite are now available at version 8.6.2. Or, in the case of vRealize Network Insight (vRNI), version 6.5.
vRealize Lifecycle Manager (vRLCM) 8.6.2
In version 8.6.1 that was released on January 14, 2022, the log4j components have been updated to version 2.17 to resolve CVE-2021-44228 and CVE-2021-45046. The new 8.6.2 release of vRLCM (January 19, 2022) adds support for vRA 8.6.2, vRA SaltStack Config 8.6.2, vRLI 8.6.2, vROps 8.6.2, vIDM 3.3.6, as well as vRNI 6.5.
Release notes: https://docs.vmware.com/en/VMware-vRealize-Suite-Lifecycle-Manager/8.6/rn/VMware-vRealize-Suite-Lifecycle-Manager-862-Release-Notes.html
What’s New in vRLCM 8.6? (blog post): https://blogs.vmware.com/management/2021/10/whats-new-in-vrealize-suite-lifecycle-manager-8-6.html
vRealize Automation (vRA) 8.6.2
In the new 8.6.2 release of vRealize Automation and vRealize Orchestrator, the log4j components have been updated to version 2.17 to address both CVE-2021-44228 and CVE-2021-45046.
Release notes: https://docs.vmware.com/en/vRealize-Automation/8.6.2/rn/vmware-vrealize-automation-862-release-notes/index.html
What’s New in vRealize Automation, OCT 2021 (blog post): https://blogs.vmware.com/management/2021/10/whats-new-with-vrealize-automation-october-2021.html
vRealize Operations (vROps) 8.6.2
In this new 8.6.2 release of vRealize Operations, the log4j components have been updated to version 2.16 to address both CVE-2021-44228 and CVE-2021-45046. In addition to log4j, there were other security and product improvements in this release, as well. See VMware KB 87154 for more information.
[Update as of 26-JAN-2022]: I just learned that there’s a vROps 8.6 Hot Fix 1 that will update the log4j components to version 2.17. There are also a few other issues that are resolved in this hot fix patch. The full details of this vROps 8.6 Hot Fix 1 can be found in VMware KB 87358.
Release notes: https://docs.vmware.com/en/vRealize-Operations/8.6.2/rn/vrealize-operations-862-release-notes/index.html
What’s New in vRealize Operations 8.6? (blog post): https://blogs.vmware.com/management/2021/10/whats-new-in-vrealize-operations-8-6.html
vROps 8.6 HF1 can be obtained via the VMware Patch Portal.
vRealize Log Insight (vRLI) 8.6.2
This new 8.6.2 release of vRealize Log Insight is technically a maintenance-only release, as the log4j components have been updated to version 2.17 to address both CVE-2021-44228 and CVE-2021-45046. No other additional features were added in this specific release.
Release notes: https://docs.vmware.com/en/vRealize-Log-Insight/8.6.2/rn/vRealize-Log-Insight-862.html
Announcing vRealize Log Insight 8.6 and Cloud: https://blogs.vmware.com/management/2021/10/announcing-vrealize-log-insight-v8-6-and-log-insight-cloud.html
vRealize Network Insight (vRNI) 6.5
The new release of vRealize Network Insight 6.5 not only updates the log4j components to version 2.17, but also adds several new features and capabilities. Some of these features include added support for monitoring and troubleshooting NSX Advanced Load Balancer, support for Cisco ACI, support for Check Point Firewall, and much more. Be sure to visit the release notes for the full list of capabilities and enhancements.
Release notes: https://docs.vmware.com/en/VMware-vRealize-Network-Insight/6.5/rn/vmware-vrealize-network-insight-65-release-notes/index.html
Announcing vRealize Network Insight 6.5 and Cloud: https://blogs.vmware.com/management/2022/01/announcing-vmware-vrealize-network-insight-6-5-and-cloud.html
As always, I hope you found this content useful and thanks for stopping by!