Planners had a vulnerability flagged and would like to know how they are impacted by it.
Users are concerned as to whether the Apache Log4j vulnerability CVE-2021-44228 poses a threat.
Orchestrate is a .NET based software and does not use Java, therefore Apache Log4J is not a vulnerability.
As a precaution, we have scanned our public facing estate to look for this vulnerability and that has come back negative. In addition to this we have next-gen firewalls in our hosting environment, that block this attack in transit and systems that detect and block any IOCs discovered on our hosts.
More information on the vulnerability can be found on: https://pages.theaccessgroup.com/Response-Log4J-Dec21.html.
