3 ms·
I had to deal with the opposite problem this week. My company uses Qualys for our vulnerability management stuff and after our security guys ran their scans thr
by flh 5y ago
I had to deal with the opposite problem this week. My company uses Qualys for our vulnerability management stuff and after our security guys ran their scans throughout the network over the weekend we had a bunch of false positives. Seems that they were alerting on log4j-api in addition to log4j-core (only log4j-core is impacted per Apache). Looks like Qualys fixed it on Monday though so this shouldn't be a problem going forward if anyone else uses them.
https://blog.qualys.com/vulnerabilities-threat-research/2021/12/10/apache-log4j2-zero-day-exploited-in-the-wild-log4shell https://blog.qualys.com/vulnerabilities-threat-research/2021...