• Linkedin
JOS SG
  • Home
  • Solutions

      Consultancy, Deployment & Migration

      • Everything-as-a-Services
      • Enterprise Security Services
      • Enterprise Application Services
      • SharePoint Services
      • Business & Robotic Process Automation
      • VAPT Security Consultancy

      IT-as-a-Service

      • Hardware Maintenance Service
      • System Maintenance Services
      • Managed Services

      Digital Transformation

      • Empower your Future Workforce
      • Future Workplace
      • Transform with IT
      • Retail IT Transformation
      • Agreements Automation
  • Resources
  • Contact Us
jos-rpa
Rise of the Bot: Get more done with less
December 9, 2021
Revamp endpoint security in the never normal
January 31, 2022

Log4j Security Advisory

What happened?

Log4j is an open-source, Java-based logging framework commonly used by enterprise applications and cloud services. A remote code execution vulnerability (CVE-2021-44228) is affecting Log4j versions 2.0-beta9 to 2.14.1. By submitting a specially craft request to a vulnerable system, depending on how the system is configured, an attacker could instruct that system to download and subsequently execute a malicious payload. 

It is advised that users pay close attention to the official product support information made available and also in their cloud provider support information center for the valid mitigation information. 

Current Remediation

For users who built their business platform with opensource tools, please refer to the support information of those tools to understand the necessary packages and overall mitigation measures that may be known. 

For users who deploys NGFW/WAF with Threat Prevention Module, search for CVE within their modules and enable the signature set to provide for immediate mitigation measures. 

Known Affected Products
Products Products
Apache Struts
Apache Solr
Apache Druid
Apache Flink
Apache Dubbo
Flume
ElasticSearch
Logstash
Kafka
Workaround

For users who are still unsure which products are vulnerable, click here to follow the process to manage the incident. 

  • Log case directly into their support and seek official stance and information on how “log4j affected product line” and tag the request as urgent. 
  • Use the official information and mitigation advisory as highlighted by the vendor
  • Monitor the information daily until the affected issue is resolved.
    – Most product vendors could have a large product line which may be under investigation process and require some time to release their patches
  • Look out for patches made available and implement to fix your affected product line. 

For more information about the presented vulnerabilities, please refer to the following articles.

  • AWS Log4j2 Issue Security Bulletin
  • Google Cloud Armor Blog
  • Red Hat Security Bulletin
  • Apache Logging Services

If you require further information or a consultation, please reach out to our team of Cybersecurity Solutions Experts.

21 Dec 2021 | Original articles from National Institute of Standards and Technology (NIST)

RELATED POSTS

VMware Security Advisory

Read More »
March 20, 2021

F5 Networks Security Advisory

Read More »
March 26, 2021

Aruba Security Advisory

Read More »
March 15, 2021

Log4j Security Advisory

Read More »
December 21, 2021
Share
93

Blog Categories

Enjoy Peace of Mind with JOS IT-as-a-Ser

https://www.jos.com.sg/wp-content/uploads/2022/06/JOS-ITaaS-1.mp4

Recent Post

  • SUTD gets a SPEED bump with JOS November 9, 2023
  • JOS Services Brochure September 14, 2023
  • JOS Enterprise Applications Brochure September 14, 2023
  • JOS Enterprise Security Brochure September 14, 2023
  • JOS Big Data & Analytics Brochure September 14, 2023

Company

  • About Us
  • Contact Us

Solutions

  • Cloud
  • Enterprise Security
  • Enterprise Applications
  • SharePoint Services
  • Automation Services

IT-as-a-Service

  • About ITaaS
  • Hardware Maintenance
  • System Maintenance
  • Managed Services

Resources

  • Brochures
  • Infographic
  • Videos
  • Articles
  • Security Advisory

JOS (SG) Pte. Ltd.

Copyright © 2023 JOS (SG) Pte. Ltd. All rights reserved.

 Privacy Policy | Terms & Conditions

We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept All”, you consent to the use of all the cookies. However, you may visit your cookie settings to provide a controlled consent.
Read MoreAccept All
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT