Security News
10 Technology Vendors Affected By The Log4j Vulnerability
Michael Novinson
Vulnerable Log4j code can be found in products from some of the most prominent technology vendors like Cisco, IBM, and VMware, and as well as one serving the MSP community like ConnectWise and N-able.

IBM
The Apache Log4j open-source library with the vulnerability has been used by both IBM Watson Explorer as well as the WebSphere Application Server, with the WebSphere Application Server Admin Console and the UDDI Registry Application directly impacted. Certain versions of seven different products in the IBM Watson Explorer cognitive exploration family were susceptible to the vulnerability.
IBM Watson Explorer customers are directed to upgrade to Version 12.0.3.8 or Version 11.0.2.12 depending on the product. If IBM Watson Explorer Content Analytics Studio was upgraded after the customer updated IBM Java Runtime, the customer’s changes are lost and they must repeat the steps.
WebSphere Application Server customers are directed by IBM to apply the interim fix as soon as possible.