Critical Vulnerability Affecting Your CSUF Servers

This vulnerability affects many vendor software, including Apache and Java

There is a recent report of a critical vulnerability that impacts numerous software products currently used on campus. Please see the   CISA Log4j (CVE-2021-44228) Vulnerability Guidance Opens in new window for details and list of software affected.


What is required of me?

Please review the software list and verify with your vendor whether there is a patch to address this (and other) vulnerabilities.  Please apply the patch immediately.

 

If your vendor has not yet released a patch, please follow the   Log4j Vulnerability Response PlaybookOpens in new window   to remediate immediately.

 

Install   Palo Alto Cortex (TRAPS)   on your servers.