FCA Alerts to Apache Log4j Cyber Vulnerability

The UK Financial Conduct Authority (FCA) announced on Wednesday that it has been aware of a remote code execution vulnerability (CVE-2021-44228) that was affecting multiple versions of the Apache Log4j 2 library, a Java-based logging utility.
Furthermore, the National Cyber Security Centre (NCSC) is aware that scanning for this vulnerability has been detected in the UK and exploitation detected elsewhere. It has published guidance for firms to help identify if they may be affected. And the guidance will be updated regularly where more information is available.
The financial regulator recommends that all firms using the Apache Log4j 2 library review the NCSC guidance to ensure the safety of their firm's systems. Besides, it notes that any operational impacts associated with this issue should be escalated via normal supervisory reporting processes.
Shortly before, Fazzaco reported that the UK-based interdealer broker TP ICAP unveiled on Tuesday an update on security vulnerability, which was discovered by the Apache Log4j project on Thursday 9 December, 2021. If exploited, the vulnerability could potentially allow a remote attacker to execute code on the server.
Subscribe Now

