![Log4J Vulnerability Announcement](https://cynical-zorilla.transforms.svdcdn.com/production/photo-1516259762381-22954d7d3ad2-cropentropycstinysrgbfitmaxfmjpgixidMnwxMTc3M3wwfDF8c2VhcmNofDF8fGNvZGV8ZW58MHx8fHwxNjM5NDA0MDA5ixlibrb-1.2.1q80w2000.jpg?w=1920&h=1080&q=100&fm=webp&fit=clip&dm=1727093441&s=781d9d47d5440936eac395ce18a0bcc3)
Log4J Vulnerability Announcement
UPDATE: 16/12/2021 1030hrs
Cryoserver is also not vulnerable to the https://nvd.nist.gov/vuln/detail/CVE-2021-45046 variant - as we are not using the affected version of Log4J.
UPDATE: 14/12/2021 1630hrs
Following our previous announcement, we are pleased to confirm that no version of Cryoserver is vulnerable to CVE-2021-44228
Our initial examination of Cryoserver versions <v9.5.0 led us to believe that there existed a back-end vulnerability that could potentially be exploited. We have now confirmed that this is not the case.
Cryoserver customers pre-version 9.5 should nevertheless schedule an upgrade at some point in the future as good practice.
13/12/2021 1400hrs
On Friday 10th December, Apache announced a critical vulnerability within the LOG4J logging library for Java, called Log4Shell or LogJam.
At 10/10 severity, this is comfortably one of the most serious IT vulnerabilities to have been discovered in recent memory, as Log4J is often installed on both Linux and Windows systems either directly, or often as a requirement of another package or system.
Log4J is included on servers built by Cryoserver.
All our Cloud services
Are not vulnerable to CVE-2021-44228
On-premises versions of Cryoserver on or above v.9.5.0
v9.5.0 released in January 2021 are not vulnerable to CVE-2021-44228
Versions prior to v9.5.0 are partially vulnerable, as described below.
CVE-2021-44228 Attack Vectors:
Please see:
https://www.lunasec.io/docs/blog/log4j-zero-day/
Web Site Attack Vector
The attacker uses the public website to initiate the attack.
No versions of Cryoservers' are vulnerable to this attack vector.
Back-End Attack Vector
The administrator of Cryoserver has set up an outbound connection to an LDAP server that is under the control of an attacker.
The attacker manipulates the remote LDAP server to initiate the attack.
Cryoserver v9.5.0 and above is not vulnerable to this attack vector.
As a next step, please email help@cryoserver.com if you have any concerns and/or wish to upgrade to our current 9.6 release.
Read
More
![Cryoserver Partners with DDS Informatica in Andorra](https://cynical-zorilla.transforms.svdcdn.com/production/photo-1551989745-347c28b620e5-cropentropycstinysrgbfitmaxfmjpgixidM3wxMTc3M3wwfDF8c2VhcmNofDE3N3x8aGFuZHNoYWtlfGVufDB8fHx8MTcxMDQxMzUwNnwwixlibrb-4.0.3q80w2000.jpg?w=1024&h=512&q=100&fm=webp&fit=crop&dm=1727093452&s=06487eca2d4c4c7195228cfc161cb65e)
Cryoserver Partners with DDS Informatica in Andorra
Cryoserver (UK) – Manufactures and supports “Advanced enterprise Email Archiving Software”DDS…
![How Can Email Archiving Solve FinTech Compliance Concerns?](https://cynical-zorilla.transforms.svdcdn.com/production/photo-1529400971008-f566de0e6dfc-ixlibrb-1.2.1q80fmjpgcropentropycstinysrgbw2000fitmaxixideyJhcHBfaWQiOjExNzczfQ.jpg?w=1024&h=512&q=100&fm=webp&fit=crop&dm=1727093361&s=b7bdcf6fbb738411ceed63eda28c3c3e)
How Can Email Archiving Solve FinTech Compliance Concerns?
FinTech businesses are innovators who create new approaches and solutions for the challenges facing…
![Know your data purpose.](https://cynical-zorilla.transforms.svdcdn.com/production/photo-1529078155058-5d716f45d604-ixlibrb-1.2.1q80fmjpgcropentropycstinysrgbw2000fitmaxixideyJhcHBfaWQiOjExNzczfQ.jpg?w=1024&h=512&q=100&fm=webp&fit=crop&dm=1727093403&s=2d37528e41b8b243968ed8cb0fd3826b)
Know your data purpose.
Knowing the original purpose for which you obtained personal data is the key to unlocking the…
![How Does Email Archiving Help With Disaster Recovery?](https://cynical-zorilla.transforms.svdcdn.com/production/photo-1485617359743-4dc5d2e53c89-ixlibrb-1.2.1q80fmjpgcropentropycstinysrgbw2000fitmaxixideyJhcHBfaWQiOjExNzczfQ.jpg?w=1024&h=512&q=100&fm=webp&fit=crop&dm=1727093397&s=45f7ceda7719efebee8a3a39dfffe115)
How Does Email Archiving Help With Disaster Recovery?
In the event of a disaster, every business must keep company operations running and recover quickly…
![Where Do Emails Go That Are Archived?](https://cynical-zorilla.transforms.svdcdn.com/production/photo-1560270579-d515a443eb3b-ixlibrb-1.2.1q80fmjpgcropentropycstinysrgbw2000fitmaxixideyJhcHBfaWQiOjExNzczfQ.jpg?w=1024&h=512&q=100&fm=webp&fit=crop&dm=1727093380&s=79f5c8d20a7314d10894a85be15ff4c1)
Where Do Emails Go That Are Archived?
Cleaning up an email inbox is an admin job everyone must do at various times. While for some it may…
![Cohesity buys Veritas: should Enterprise Vault customers worry?](https://cynical-zorilla.transforms.svdcdn.com/production/photo-1573497491208-6b1acb260507-cropentropycstinysrgbfitmaxfmjpgixidM3wxMTc3M3wwfDF8c2VhcmNofDQ5fHxpdHxlbnwwfHx8fDE3MDk1NjYxNTd8MAixlibrb-4.0.3q80w2000.jpg?w=1024&h=512&q=100&fm=webp&fit=crop&dm=1727093448&s=aae5defb079f6d45a08b5fa0a87ff29d)