Remove 2021 Remove Blog Remove Code Remove Internet
article thumbnail

What is Log4Shell? The Log4Shell vulnerability explained (and what to do about it)

Dynatrace

The vulnerability, published as CVE-2021-44228 , enables a remote attacker to take control of a device on the internet, if the device is running certain versions of Log4j 2. Apache issued a patch for CVE-2021-44228, version 2.15, on December 6. What is Log4j 2, and what does it do?

Internet 261
article thumbnail

Log4j 2 Vulnerability: Identifying and Minimizing Production Risk

Dynatrace

Log4Shell, a zero-day exploit affecting the popular Apache package was made public on December 9, 2021. It results in remote code execution (RCE) by submitting a specially composed request. Public Internet Exposure. Java processes with public-facing internet exposures are an easy target for this type of abuse.

Java 240
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Trending Sources

article thumbnail

How Dynatrace uses Dynatrace to combat the Log4j vulnerability (Log4Shell)

Dynatrace

On December 9, 2021, the first indicators of the Log4j vulnerability (Log4Shell) began to reverberate across the world. As organizations started learning about Log4Shell from news feeds, blogs, and social media, the Dynatrace security team—and Dynatrace Application Security—kicked into action. Dynatrace news.

article thumbnail

Log4Shell vulnerability: Identifying and minimizing production risk

Dynatrace

Log4Shell, a zero-day vulnerability affecting the popular Apache package was made public on December 9, 2021. It results in remote code execution (RCE) by submitting a specially composed request. Public Internet Exposure. Java processes with public-facing internet exposures are an easy target for this type of abuse.

Java 186
article thumbnail

Why vulnerability management enhances your cloud application security strategy

Dynatrace

Consider the Log4j vulnerability, which affected millions of devices after it emerged in December 2021. By contrast, a real-time observability platform with code-level application insights can automatically identify vulnerabilities at runtime. Why vulnerability management is crucial for today’s cyberthreats (Read: Log4Shell).

Strategy 222
article thumbnail

Protect your organization against zero-day vulnerabilities

Dynatrace

Although IT teams are thorough in checking their code for any errors, an attacker can always discover a loophole to exploit and damage applications, infrastructure, and critical data. The vulnerability enables a remote attacker to take control of a device on the internet if the device is running certain versions of Log4j 2.

Java 188
article thumbnail

Log4Shell highlights need for secure digital transformation with observability, vulnerability management

Dynatrace

In December 2021, a security vulnerability known as Log4Shell emerged with force. This zero-day vulnerability enables a remote attacker to take control of a device or Internet-based application if the device or app runs certain versions of Log4j 2, a popular Java library. Code-level visibility shows what matters—and what can wait.