Dec 14, 2021
A vulnerability in Log4j, a very popular Java-based logging tool, has been weaponized. The threat is impacting millions.
ALISO VIEJO, Calif. - Dec. 14, 2021 - PRLog -- Syxsense, a global leader in IT and endpoint security management, announced the ability to scan for Log4j using Syxsense Secure, identifying endpoints that are exposed to this new vulnerability.
"Although a number of popular IT management and security tools are vulnerable, Syxsense is pleased to confirm that it does NOT use Log4j," commented Ashley Leonard, CEO of Syxsense. "It imperative that IT departments respond quickly to this new threat by scanning their environment and identifying exposed endpoints."
A vulnerability in Log4j which is a very popular Java-based logging tool has been weaponized. All versions of Log4j prior to 2.14.1 are vulnerable, this does not just impact the stand-alone installer. Any application which uses Log4j for log file management or LDAP queries could also be vulnerable, unfortunately where this is the case, the vendor must provide updates for those 3rd party updates.
The Scope metric captures whether a vulnerability in one vulnerable component impacts resources in components beyond its security scope.
What makes this extra serious, is that the Scope (also known as a Jump Point) is Changed – meaning that exploitation of this vulnerability could allow the attacked to affect resources beyond the security scope managed by the security authority of the vulnerable component.
CVE-2021-44228 – CVSS Score: 10
Syxsense Risk Alert
YOUR NEWS, OUR NETWORK.
Do you have Great News you want to tell the world?
Be it updates about your business or your community, you can make sure that it’s heard by submitting your story to our network reaching hundreds of news sites across 6 verticals.