Information for our customers
For the past week, the internet has been dominated by the log4j security vulnerability. Log4j is a framework for logging application messages in Java and is essentially a de facto standard.
On December 10, 2021, a zero-day vulnerability in log4j version 2 was disclosed. Attackers can exploit this vulnerability to execute malicious code on affected host systems. The first ransomware attacks have already taken place. According to the BSI, the vulnerability has created an „extremely critical threat situation,“ and a „Red Alert“ is in effect.
Your data protection management solution, 2B Advice PrIME, is not affected by this security vulnerability. We have evaluated the hosting infrastructure for the 2B Advice PrIME SaaS solution with regard to the log4j vulnerability and can confirm that we are not affected. Log4j is not integrated into our products and services in any way. Furthermore, the third-party components used in our solutions are not affected by the log4j vulnerability.
- Companies and consumers can find further information on detection and response on the BSI website:
bsi.bund.de/EN/topics/companies-and-organizations/information-and-recommendations/recommendations-by-target/web-applications/log4j/log4j_node.html




