As of December 28, new build product binaries which cover the first four CVE's were made available for versions 21.1.1, 21.2.1, and 21.2.2, which includes Log4j v2.17. Review of code shows that SteelConnect EX is NOT VULNERABLE to CVE-2021-44832.
To ensure the proper code is installed, please download the appropriate .bin file and apply to your existing systems. If you install using the other methods (.iso, .ova, .tbz2), you must download and install the new .bin file in order to get the new version of Log4j.
Links to the .bin files are listed below:
SteelConnect-EX Analytics
21.2.2 https://support.riverbed.com/bin/support/download?sid=u43k3cp4ek0euosmtn08geg0mf
21.2.2 (Ubuntu) https://support.riverbed.com/bin/support/download?sid=jvlvit67m93oq03vdkpmq19ho5
21.2.1 https://support.riverbed.com/bin/support/download?sid=j0dh60nalah6pahq71j5q9dtcn
21.2.1 (Ubuntu) https://support.riverbed.com/bin/support/download?sid=38ulvcbqfn3k9hhfhi18qvdjb7
21.1.1 https://support.riverbed.com/bin/support/download?sid=sg2vakog4tksvkduo7124qanru
SteelConnect-EX Director
21.2.2 https://support.riverbed.com/bin/support/download?sid=hlu676lfd2blq00a45fiankfb6
21.2.2 (Ubuntu) https://support.riverbed.com/bin/support/download?sid=k88t3mg4q4b708s17c475mpisi
21.2.1 https://support.riverbed.com/bin/support/download?sid=glmrd53m0o4rqkpqmcmqtpcf2g
21.2.2 (Ubuntu) https://support.riverbed.com/bin/support/download?sid=i07dl96ltvph8gu6m8l6msa61v
21.1.1 https://support.riverbed.com/bin/support/download?sid=202ikmq61q1enggqe8paohidr8
Previously a patch for CVE-2021-44228 only was made available on the Support site on Dec 15 2021 at the following links:
If you have applied this patch already, Riverbed recommends you proceed to update the entire installation with the newly available build.