Log4Shell – FirstWare IDM-Portal not affected

14.12.2021

The NCSC is highlighting a critical vulnerability in Apache Log4j. The major vulnerability, named Log4Shell, was discovered on December 10, 2021 in the Java library Log4j developed by the Apache Software Foundation.

The FirstWare IDM-Portal of FirstAttribute is not affected by this.

FirstAttribute software solutions

FirstAttribute customers are not at risk from this security issue.

Here is an overview of the most important facts:

  1. FirstAttribute’s software and services do not use Log4j.
  2. The development is not done in Java.
  3.  Web applications developed by FirstAttribute do not use Apache web server technology for deployment.

Our software and services are not affected::

It is not necessary to update the existing installations. However, we generally recommend using the latest version and performing regular updates. To download the latest versions or make an appointment with our specialists, see links above.

Note: An update for Log4j is available

A patch was hastily released by the Apache Foundation over the weekend, but it needs to be installed by server owners. Some affected companies, such as Mojang, the publisher of Minecraft, have also posted several warnings on their respective websites, asking all server owners to apply the proposed update as soon as possible.

Enhanced security with FirstWare IDM-Portal

FirstWare IDM-Portal focuses primarily on the security of your identity and enterprise data.

With the help of controlled user and authorization management (incl. automation and approval workflows), security measures such as SSO, MFA or RBAC as well as detailed auditing, the IDM-Portal increases the security of your company. The most important goals are to ensure precisely fitting access rights, to automate routine tasks and to strengthen the adherence to legal regulations (= avoid compliance violations).

For the FirstAttribute AG team, the security of your data is a high priority topic. We continuously monitor and improve our software and services to ensure that our customers can handle their data securely.

If you have any questions about the Log4Shell attack or would like to verify the security of FirstWare IDM-Portal, please feel free to contact us.

Search

Latest Posts

Who writes?

Why IDM-Portal?

Behind this blog is us: the FirstAttribute team, thinking through IAM and IGA from start to finish every single day.

Our Customer Service team shares insights from real customer projects, including what works well and what we learn along the way. Our developers write about the technology they implement themselves, always looking for solutions that make things easier and more secure for our customers. And together, we all keep a close eye on what is currently moving our industry.

We hope our blog posts provide you with valuable information. In any case, getting in touch with us is worth it. In a personal conversation, we believe these topics can be discussed best.

Categories