Networking-Forums.com

Professional Discussions => Vendor Advisories => Topic started by: Netwörkheäd on December 13, 2021, 06:37:33 PM

Title: Cisco Security Advisory - Vulnerability in Apache Log4j Library Affecting Cisco Products: December 2021
Post by: Netwörkheäd on December 13, 2021, 06:37:33 PM
Vulnerability in Apache Log4j Library Affecting Cisco Products: December 2021

On December 9, 2021, the following vulnerability in the Apache Log4j Java logging library affecting all Log4j2 versions prior to 2.15.0 was disclosed:



For a description of this vulnerability, see the Fixed in Log4j 2.15.0 section of the Apache Log4j Security Vulnerabilities page. 


To help detect exploitation of this vulnerability, Cisco has released Snort rules at the following location: Talos Rules 2021-12-13


This advisory will be updated daily around the following times: 1500 UTC/10:00 AM ET, 1900 UTC/2:00 PM ET, 2300 UTC/6:00 PM ET.


This advisory is available at the following link:
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd



     
         
Security Impact Rating:  Critical
   
   
       
CVE: CVE-2021-44228
Source: Vulnerability in Apache Log4j Library Affecting Cisco Products: December 2021 (https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd?vs_f=Cisco%20Security%20Advisory&vs_cat=Security%20Intelligence&vs_type=RSS&vs_p=Vulnerability%20in%20Apache%20Log4j%20Library%20Affecting%20Cisco%20Products:%20December%202021&vs_k=1)