Apache Log4J Zero Day Vulnerability
Background:
CSI is actively investigating a remote code execution vulnerability (CVE-2021-44228) – deemed “Log4Shell” that was discovered on 9th December.
Who is affected?
Systems using Apache Log4j2 version 2.14.1 and earlier are affected. Also affected are any products that bundle log4j2 by default.
What is CSI doing in response?
CSI is working with vendors to understand the scope of services and systems affected by this vulnerability and planning remediation efforts.
We are investigating and taking action for CSI services that may be potentially impacted.
We will communicate to any clients who are impacted and help customers detect, investigate and mitigate attacks.
Additional information can be found on the NCSC website below:
https://www.ncsc.gov.uk/news/apache-log4j-vulnerability
Read more like this

IBM Power
Every IBM i Estate Needs Securing – Here’s Why
A Different Angle on Risk If the Board of Directors asked you tomorrow, “does our IBM i environment require security…

IBM Power
The Ultimate IBM Power11 Buyers Guide
EXCLUSIVE INSIGHT The Market Asked, IBM Power11 Delivered You could call it a paradigm shift, or a change in attitude,…

IBM Power
Levelling Up from Legacy IBM Power Systems (An EOS Guide)
Why Modernisation Matters Modernisation is often about market competitiveness and relevance. For modernised organisations, offboarding outdated hardware is a matter…
Ready to talk?
Get in touch today to discuss your IT challenges and goals. No matter what’s happening in your IT environment right now, discover how our experts can help your business discover its competitive edge.