Forum Discussion
The following message should have been presented to administrators logging in after Saturday:
QuoteOn Dec 9th, 2021, various cybersecurity organizations began reporting that a critical-severity vulnerability has been discovered in an application logging component known as “log4j” which is widely used in Java-based applications.
LogicMonitor has evaluated our exposure to the Log4Shell vulnerability and determined that the LM SaaS platform is not affected. We are aware that some versions of the LM Collector include a defective version of log4j, but its architecture has been purposely designed to mitigate such vulnerabilities. However, out of an abundance of caution, we have developed a mitigation strategy for this vulnerability that will definitively prevent exposure.
At this time the Log4Shell mitigation has already been released to the LM platform and each Collector will have automatically updated its configuration file to incorporate the fix on Saturday, Dec 11th. Because each Collector restarts itself on a daily cadence, the updated configuration will automatically take effect on all Collectors no later than Sunday, Dec 12th.
No updates to the Collector software are required to enable the Log4Shell mitigation and no manual intervention is required.
Please reach out to LogicMonitor Technical Support or your Customer Success Manager if you have any questions or concerns.
Related Content
- 2 years ago
- 5 months ago
- 5 months agoAnonymous