[Lo4Net] Cyber Vulnerability Vendor Impact Assessment for Lo4Net

Milind Wankhede <[email protected]> Fri, 17 Dec 2021 14:08:40 +0000
Newsgroups gmane.comp.apache.logging.log4net.devel,gmane.comp.apache.commons.general
Message-ID <MN2PR05MB6525ECF77DCB55D292E669A9FB789@MN2PR05MB6525.namprd05.prod.outlook.com>
--_000_MN2PR05MB6525ECF77DCB55D292E669A9FB789MN2PR05MB6525namp_
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable

Good Morning/Afternoon,
As you may know, a cyber-vulnerability impacting Java Library: log4j was re=
cently identified.
DHS warns of critical flaw in widely used software - CNNPolitics<https://ww=
w.cnn.com/2021/12/11/politics/dhs-log4j-software-flaw-warning/index.html>

As a result and to provide our regulators confidence in our management of t=
he impact, we are engaging our vendors to determine both if they were impac=
ted (Yes/No) and if "Yes" what "Actions were taken?"

We ask you consider in your response any 3rd party vendors which your busin=
ess may share SMBC data with as well.

We are looking for impact on Log4Net project/Library.

Vendor Reported Impact (Yes or No)
Actions Taken (If Any or N/A)
Impact to SMBC (Yes/No)


Please reply to all on this mail.

To ensure we are in compliance with regulatory obligations we ask that you =
please respond within 48 hours of this mail.

Thank you,


Thanks & Regards!
Milind Wankhede
SMBC Capital Markets, Inc.
277 Park Ave New York NY 10172
Phone: (212) 224-5221 | Email:  [email protected]<mailto:mwankhede@smbc=
-cm.com>

This message, including any attachments, may contain information that is pr=
ivileged, confidential and/or protected by copyright, and is subject to the=
 terms available at  https://www.smbcgroup.com/americas/disclaimers/emaildi=
sclaimer.html/ =

If you are not the intended recipient, or have received this message in err=
or, please notify the sender immediately and delete this message.

--_000_MN2PR05MB6525ECF77DCB55D292E669A9FB789MN2PR05MB6525namp_--