cognitive cybersecurity intelligence

News and Analysis

Search

What is the Log4j Vulnerability?

Log4Shell (CVE-2021-44228) is a remote code execution vulnerability affecting some versions of Log4J, particularly Apache Log4J 2 (versions 2.14.1 and earlier). This flaw stems from how these versions handle Java Naming and Directory Interface (JNDI) lookups. It allows hackers to execute malicious code remotely by tricking this older JNDI functionality into executing a download command from a server containing malware.

Source: www.ibm.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts