The Log4J vulnerability (CVE-2021-44228) affects Java-based applications using Log4j 2 versions 2.0 through 2.14. The majority of Access Group products are built on .NET and are not affected.
Three Access Group products were identified as using the Log4j library and have since been patched.
As a precaution, all public-facing systems have been scanned for this vulnerability and returned a negative result. Next-generation firewalls are in place to block this attack in transit, and XDR and EDR systems are deployed to detect and block any indicators of compromise on hosted systems.
Some third-party products in use have been identified as potentially vulnerable. These are internally facing only and remediation will be scheduled as it becomes available.
If you have any further questions about this vulnerability, raise a case for assistance.
