Security Vulnerability Notification - 50123 (Log4Shell)
Good morning Oracle Support -
I am posting this discussion regarding the Log4j vulnerability.
Note: This client runs on Micros 5.5.2 version.
This is a security vulnerability that potentially allows a threat actor to compromise a device using the java library. The vulnerability is found in log4j, an open-source logging library used by apps and services across the internet.
Update: Threat intelligence indicates that there is a high probability that attempts to exploit this vulnerability will increase dramatically in the next 7-10 days, as the mechanisms of exploit become more widely known.
Update: NTE IT has identified a number of systems that may be vulnerable to this threat and have applied mitigation to these impacted systems, where practical.