Log4j vulnerability Information

Question: How are Microix products affected by the current vulnerability of Log4j?

Microix products (Workflow Modules Client, Web Companion, HTML Approval, Web Time) are currently not using the Log4j java libraries and our applications are not compatible to be hosted on Apache servers. Therefore our products should not be affected by the Log4j library vulnerability. Additionally, our internal software used by our team to communicate with customers were also confirmed to not be affected as well:


Simplehelp.com (Remote Connection Software)
Solar Winds (FTP and File Share)
Helpdesk (Jitbit)
DevExpress (UI Components)


Information about Log4j vulnerability…

A VULNERABILITY IN a widely used logging library has become a full-blown security meltdown, affecting digital systems across the internet. Hackers are already attempting to exploit it, but even as fixes emerge, researchers warn that the flaw could have serious repercussions worldwide. 

The problem lies in Log4j, a ubiquitous, open source Apache logging framework that developers use to keep a record of activity within an application. Security responders are scrambling to patch the bug, which can be easily exploited to take control of vulnerable systems remotely. At the same time, hackers are actively scanning the internet for affected systems. Some have already developed tools that automatically attempt to exploit the bug, as well as worms that can spread independently from one vulnerable system to another under the right conditions.

Source…A Log4J Vulnerability Has Set the Internet 'On Fire' | WIRED




Creation date: 12/14/2021 9:32 AM      Updated: 12/14/2021 9:33 AM
Files
OriginalEmail.eml
8.4 KB