Remove log4j-vulnerability-faqs
article thumbnail

CVE-2021-44228, CVE-2021-45046, CVE-2021-4104: Frequently Asked Questions About Log4Shell and Associated Vulnerabilities

Tenable

CVE-2021-44228, CVE-2021-45046, CVE-2021-4104: Frequently Asked Questions About Log4Shell and Associated Vulnerabilities. A list of frequently asked questions related to Log4Shell and associated vulnerabilities. What is Log4j? Log4j is a widely used Java logging library included in Apache Logging Services. Satnam Narang.

.Net 98
article thumbnail

Are You Ready for the Next Log4Shell? Tenable’s CSO and CIO Offer Their Advice

Tenable

Tenable CIO Patricia Grant and CSO Robert Huber share insights and best practices to help IT and cybersecurity leaders and their teams weather the next cyber crisis of Log4j proportions. Now, the one-year anniversary of the earth-shaking Log4j event offers an opportunity to take stock and ponder key questions, such as: “What did we learn?”

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Spring4Shell FAQ: Spring Framework Remote Code Execution Vulnerability

Tenable

Spring4Shell FAQ: Spring Framework Remote Code Execution Vulnerability. As more information becomes available, we will update this FAQ with additional details about the vulnerability, including Tenable product coverage. Has a CVE been assigned to this vulnerability? Is Spring4Shell related to Log4Shell?

article thumbnail

Cybersecurity Snapshot: 6 Things That Matter Right Now

Tenable

5 | Don’t take your eye off the Log4j ball. Log4j: It’s a marathon race not a sprint. Like an insufferable houseguest who overstays his welcome, the cataclysmic Log4j vulnerability will be around for a long time – possibly as much as a decade after its earth-shaking discovery in December of last year. And much more!

article thumbnail

Cybersecurity Snapshot: Log4j Anniversary, CI/CD Risks, Infostealers, Email Attacks, OT Security

Tenable

Get the latest on the anniversary of the Log4j crisis; OWASP’s top CI/CD risks; a surge of infostealer malware; the fund transfer fraud — business email compromise connection; and more! . 1 - One year after Log4j crisis, what have we learned? To get all the details, read the blog “ Are You Ready for the Next Log4Shell?

article thumbnail

Ivanti Product Update, April 2022

Ivanti

In August 2021, Ivanti acquired RiskSense , a pioneer in risk-based vulnerability management and prioritization. Those offerings are now known as the following: Ivanti Neurons for Risk-Based Vulnerability Management (RBVM). Ivanti Neurons for Vulnerability Knowledge Base (VULN KB). x formula for any vulnerability with a CVSS 3.x