{"id":12021,"date":"2022-07-18T07:00:00","date_gmt":"2022-07-18T15:00:00","guid":{"rendered":"https:\/\/formtek.com\/blog\/?p=12021"},"modified":"2022-07-15T10:21:02","modified_gmt":"2022-07-15T18:21:02","slug":"log4j-vulnerability-minimal-damage-to-date-but-risks-classified-as-long-term-endemic","status":"publish","type":"post","link":"https:\/\/formtek.com\/blog\/log4j-vulnerability-minimal-damage-to-date-but-risks-classified-as-long-term-endemic\/","title":{"rendered":"Log4j Vulnerability: Minimal Damage to Date, but Risks Classified as Long-Term Endemic"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.dhs.gov\/news\/2022\/07\/14\/cyber-safety-review-board-releases-report-its-review-log4j-vulnerabilities-and\" data-type=\"URL\" data-id=\"https:\/\/www.dhs.gov\/news\/2022\/07\/14\/cyber-safety-review-board-releases-report-its-review-log4j-vulnerabilities-and\">The Cyber Safety Review Board<\/a> last week Thursday released a report on the effect of the Log4j vulnerability on US government agencies.  The report found that agencies spent tens of thousands of hours patching the problem since it was first reported.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.dhs.gov\/person\/robert-silvers\" data-type=\"URL\" data-id=\"https:\/\/www.dhs.gov\/person\/robert-silvers\">Rob Silvers<\/a>, Department of Homeland Security Under Secretary, <a href=\"https:\/\/www.washingtonpost.com\/politics\/log4j-software-flaw-endemic-new-cyber-safety-panel-says\/2022\/07\/14\/5079c39c-0389-11ed-8beb-2b4e481b1500_story.html\" data-type=\"URL\" data-id=\"https:\/\/www.washingtonpost.com\/politics\/log4j-software-flaw-endemic-new-cyber-safety-panel-says\/2022\/07\/14\/5079c39c-0389-11ed-8beb-2b4e481b1500_story.html\">said that<\/a> \u201cLog4j is one of the most serious software vulnerabilities in history.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Log4j is Apache Open Source Software used as a standard library for being able to log diagnostic information from Java programs.  Java and Log4j are widely used in building business software applications.  The vulnerability discovered in the Log4j code would allow hackers to execute any software code on the target computer.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The government report emphasized that while the vulnerability had been extremely disruptive that there was little evidence of malicious damage caused by it.  The report found that &#8220;at the time of writing, the board is not aware of any significant Log4j-based attacks on critical infrastructure systems. Somewhat surprisingly, the board also found that to date, generally speaking, exploitation of Log4j occurred at lower levels than many experts predicted, given the severity of the vulnerability.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The report also concluded that because of Log4j&#8217;s ubiquitous use that it likely will &#8220;be exploited for years to come.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.linkedin.com\/in\/pacethomas\/\" data-type=\"URL\" data-id=\"https:\/\/www.linkedin.com\/in\/pacethomas\/\">Thomas Pace<\/a>, a former Department of Energy cybersecurity lead, <a href=\"https:\/\/www.theregister.com\/2022\/07\/14\/dhs_warns_expect_log4j_risks\/\" data-type=\"URL\" data-id=\"https:\/\/www.theregister.com\/2022\/07\/14\/dhs_warns_expect_log4j_risks\/\">said that<\/a> &#8220;just because these attacks have not been detected does not mean that they haven&#8217;t happened. We know for a fact that threat actors are exploiting known vulnerabilities across industries. Critical infrastructure is no different.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Silvers agreed, saying that &#8220;this event is not over.&#8221;<\/p>\n<div class=\"lightsocial_container\"><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/digg.com\/submit?url=https%3A%2F%2Fformtek.com%2Fblog%2Flog4j-vulnerability-minimal-damage-to-date-but-risks-classified-as-long-term-endemic%2F&amp;title=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/digg.png\" alt=\"Digg This\" title=\"Digg This\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.reddit.com\/submit?url=https%3A%2F%2Fformtek.com%2Fblog%2Flog4j-vulnerability-minimal-damage-to-date-but-risks-classified-as-long-term-endemic%2F&amp;title=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/reddit.png\" alt=\"Reddit This\" title=\"Reddit This\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.stumbleupon.com\/submit?url=https%3A%2F%2Fformtek.com%2Fblog%2Flog4j-vulnerability-minimal-damage-to-date-but-risks-classified-as-long-term-endemic%2F&amp;title=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/stumbleupon.png\" alt=\"Stumble Now!\" title=\"Stumble Now!\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/buzz.yahoo.com\/buzz?targetUrl=https%3A%2F%2Fformtek.com%2Fblog%2Flog4j-vulnerability-minimal-damage-to-date-but-risks-classified-as-long-term-endemic%2F&amp;headline=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/yahoo_buzz.png\" alt=\"Buzz This\" title=\"Buzz This\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.dzone.com\/links\/add.html?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Flog4j-vulnerability-minimal-damage-to-date-but-risks-classified-as-long-term-endemic%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/dzone.png\" alt=\"Vote on DZone\" title=\"Vote on DZone\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.facebook.com\/sharer.php?t=&amp;u=https%3A%2F%2Fformtek.com%2Fblog%2Flog4j-vulnerability-minimal-damage-to-date-but-risks-classified-as-long-term-endemic%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/facebook.png\" alt=\"Share on Facebook\" title=\"Share on Facebook\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/delicious.com\/save?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Flog4j-vulnerability-minimal-damage-to-date-but-risks-classified-as-long-term-endemic%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/delicious.png\" alt=\"Bookmark this on Delicious\" title=\"Bookmark this on Delicious\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.dotnetkicks.com\/kick\/?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Flog4j-vulnerability-minimal-damage-to-date-but-risks-classified-as-long-term-endemic%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/dotnetkicks.png\" alt=\"Kick It on DotNetKicks.com\" title=\"Kick It on DotNetKicks.com\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/dotnetshoutout.com\/Submit?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Flog4j-vulnerability-minimal-damage-to-date-but-risks-classified-as-long-term-endemic%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/dotnetshoutout.png\" alt=\"Shout it\" title=\"Shout it\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.linkedin.com\/shareArticle?mini=true&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Flog4j-vulnerability-minimal-damage-to-date-but-risks-classified-as-long-term-endemic%2F&amp;title=&amp;summary=&amp;source=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/linkedin.png\" alt=\"Share on LinkedIn\" title=\"Share on LinkedIn\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.technorati.com\/faves?add=https%3A%2F%2Fformtek.com%2Fblog%2Flog4j-vulnerability-minimal-damage-to-date-but-risks-classified-as-long-term-endemic%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/technorati.png\" alt=\"Bookmark this on Technorati\" title=\"Bookmark this on Technorati\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/twitter.com\/home?status=Reading+https%3A%2F%2Fformtek.com%2Fblog%2Flog4j-vulnerability-minimal-damage-to-date-but-risks-classified-as-long-term-endemic%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/twitter.png\" alt=\"Post on Twitter\" title=\"Post on Twitter\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.google.com\/buzz\/post?url=https%3A%2F%2Fformtek.com%2Fblog%2Flog4j-vulnerability-minimal-damage-to-date-but-risks-classified-as-long-term-endemic%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/google_buzz.png\" alt=\"Google Buzz (aka. Google Reader)\" title=\"Google Buzz (aka. Google Reader)\" \/><\/a><\/div><\/div>","protected":false},"excerpt":{"rendered":"<p>The Cyber Safety Review Board last week Thursday released a report on the effect of the Log4j vulnerability on US government agencies. The report found that agencies spent tens of thousands of hours patching the problem since it was first<span class=\"ellipsis\">&hellip;<\/span><\/p>\n<div class=\"read-more\"><a href=\"https:\/\/formtek.com\/blog\/log4j-vulnerability-minimal-damage-to-date-but-risks-classified-as-long-term-endemic\/\">Read more &#8250;<\/a><\/div>\n<p><!-- end of .read-more --><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[78],"tags":[],"class_list":["post-12021","post","type-post","status-publish","format-standard","hentry","category-code-development"],"_links":{"self":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/posts\/12021","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/comments?post=12021"}],"version-history":[{"count":1,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/posts\/12021\/revisions"}],"predecessor-version":[{"id":12022,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/posts\/12021\/revisions\/12022"}],"wp:attachment":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/media?parent=12021"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/categories?post=12021"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/tags?post=12021"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}