Statement on Apache Log4j2 remote code execution Vulnerability

Original release date: December 16, 2021

 

Security Notice

For the disclosed Apache Log4j2 vulnerabilities (CVE-2021-44228, CVE-2021-45046, CVE-2021-45105), ZTE's affected products have provided solutions and actively carried out fixing work.

The customer can contact ZTE's global customer support team for specific information.

 

Update Records

December 16, 2021, initial release.

December 28, 2021, updated CVE-2021-44228 (in progress), and added CVE-2021-45046, CVE-2021-45105 descriptions.

August 3, 2022, updated security notice.

 

Global Customer Support Center

http://support.zte.com.cn/support/web/Contact.aspx?_langType=en

 

ZTE PSIRT

https://www.zte.com.cn/global/cybersecurity/ztepsirt.html