Click to chat
  • Solutions
    • Solutions
    • Artificial Intelligence
    • Data Analytics
    • Epicor for Distribution
    • Epicor for Manufacturing
    • IT Support
    • Managed Services
    • Microsoft 365
    • Microsoft Azure
    • Microsoft Licensing Support
    • Security
  • Innovation
    • Innovation
    • AI for Epicor
    • Cybersecurity
    • Data Analytics
    • Epicor in Azure
    • Epicor Kinetic ERP
    • Microsoft 365
    • Microsoft Azure
    • SaaS
  • Helpdesk
  • Resources
    • Resources
      • Resources
      • 2W Conversations
      • News Releases
      • Product Demo’s
      • Quick Tech Talks
      • Webinars
    • Blogs
  • About 2W
    • About Us
    • Contact Us
    • IT News
  • Join the Team
  • Client Login
  • Solutions
    • Solutions
    • Artificial Intelligence
    • Data Analytics
    • Epicor for Distribution
    • Epicor for Manufacturing
    • IT Support
    • Managed Services
    • Microsoft 365
    • Microsoft Azure
    • Microsoft Licensing Support
    • Security
  • Innovation
    • Innovation
    • AI for Epicor
    • Cybersecurity
    • Data Analytics
    • Epicor in Azure
    • Epicor Kinetic ERP
    • Microsoft 365
    • Microsoft Azure
    • SaaS
  • Helpdesk
  • Resources
    • Resources
      • Resources
      • 2W Conversations
      • News Releases
      • Product Demo’s
      • Quick Tech Talks
      • Webinars
    • Blogs
  • About 2W
    • About Us
    • Contact Us
    • IT News
  • Join the Team
  • Client Login
Contact Us
Home / IT News / High Severity Vulnerability Just Uncovered, Action Needed

High Severity Vulnerability Just Uncovered, Action Needed

12/14/21
Categories:
  • Uncategorized

Last week, a new vulnerability was discovered and documented in a very public fashion. The official title for this vulnerability is CVE-2021-44228, but the unofficial nickname for it is log4shell. Log4Shell is a high severity vulnerability (CVE-2021-44228, CVSSv3 10.0) impacting multiple versions of the Apache Log4j 2 utility. 

The vulnerability allows for unauthenticated remote code execution. Log4j 2 is an open-source Java logging library developed by the Apache Foundation. Log4j 2 is widely used in many applications and is present, as a dependency, in many services. These include enterprise applications as well as numerous cloud services. Because it is a component of a larger application, it is a lot harder to build a list of what can be vulnerable. Until fully confirmed, one must assume that all java applications are vulnerable to this bug.  

It might be easier to think about log4j like a tool in a toolbox. We can look at a toolbox and say, “Yeah, that’s probably got an adjustable wrench in it,” but until we go check, we cannot say for certain whether there is a wrench in it.  

Many enterprise and cloud applications including several large and well-known vendors utilize Log4j, and therefore, could have this vulnerability. A community list of vendors and publishers’ announcements and positions is in process and lives here: GitHub Gist Security Advisory 

Another good reference can be found here: HC3: LogJ4 Sector Alert Bulletin 

Everyone needs to be cognizant of the seriousness of this vulnerability, and the fact that it is being exploited in the wild. As time goes on, 2W will do our best to assess any places where this vulnerability may exist, communicate, and remediate them appropriately. Most of the effort to address this vulnerability will be to keep apps, software, and operating systems up to date. We recommend you take care of your environment and ensure your partners are doing the same in theirs. 

If you have further questions or need help, give us a call. 2W Tech is a technology service provider with IT Consultants on staff that have a wide berth of experience with cybersecurity and cyber defense solutions. 

Read More:

Epicor ERP Planning and Scheduling Module

The Importance of Regular Network Assessments

Back to IT News

Copyright © 2025, 2W Technologies, Inc.

2W Tech is a leading technology service provider specializing in cutting-edge solutions for the manufacturing and distribution industry, including Epicor ERP, Epicor P21, IT support and infrastructure, Azure cloud services, Microsoft 365, cybersecurity, artificial intelligence, data analytics, and comprehensive managed technology programs.

Epicor in AzureTM and ResolveIQTM are registered trademarks of 2W Technologies, INC.

As an esteemed Epicor Platinum Elite Partner and a Microsoft Tier 1 Cloud Services Partner, we are dedicated to delivering unparalleled service and support. For more information, please contact us at 262-686-5070 or visit our website here.