BSI issues red alert warning on software
2021-12-13
The BSI, on Saturday (Dec 11) issued a red alert warning on a flawed piece of widely-used software, saying it posed an "extremely critical threat" to web servers.
The BSI said in a statement on its website, a vulnerability in a Java-based library known as Log4j can be exploited to allow a complete takeover of the affected system.
"The reason for this assessment is the very wide distribution of the affected product and the associated impact on countless other products. The vulnerability is also easily exploitable, and a proof-of-concept is publicly available. The BSI is aware of world- and Germany-wide mass scans as well as attempted compromises. Initial successful compromises are also being publicly reported", the BSI said.
The BSI said that although there was a security update for Log4j all products using it also needed to be adapted, recommending that companies and organizations implemented the measures outlined in the cyber security warning.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.