[Lo4Net] Cyber Vulnerability Vendor Impact Assessment for Lo4Net
Milind Wankhede <[email protected]> Fri, 17 Dec 2021 14:08:40 +0000
| Newsgroups | gmane.comp.apache.logging.log4net.devel,gmane.comp.apache.commons.general |
|---|---|
| Message-ID | <MN2PR05MB6525ECF77DCB55D292E669A9FB789@MN2PR05MB6525.namprd05.prod.outlook.com> |
--_000_MN2PR05MB6525ECF77DCB55D292E669A9FB789MN2PR05MB6525namp_ Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Good Morning/Afternoon, As you may know, a cyber-vulnerability impacting Java Library: log4j was re= cently identified. DHS warns of critical flaw in widely used software - CNNPolitics<https://ww= w.cnn.com/2021/12/11/politics/dhs-log4j-software-flaw-warning/index.html> As a result and to provide our regulators confidence in our management of t= he impact, we are engaging our vendors to determine both if they were impac= ted (Yes/No) and if "Yes" what "Actions were taken?" We ask you consider in your response any 3rd party vendors which your busin= ess may share SMBC data with as well. We are looking for impact on Log4Net project/Library. Vendor Reported Impact (Yes or No) Actions Taken (If Any or N/A) Impact to SMBC (Yes/No) Please reply to all on this mail. To ensure we are in compliance with regulatory obligations we ask that you = please respond within 48 hours of this mail. Thank you, Thanks & Regards! Milind Wankhede SMBC Capital Markets, Inc. 277 Park Ave New York NY 10172 Phone: (212) 224-5221 | Email: [email protected]<mailto:mwankhede@smbc= -cm.com> This message, including any attachments, may contain information that is pr= ivileged, confidential and/or protected by copyright, and is subject to the= terms available at https://www.smbcgroup.com/americas/disclaimers/emaildi= sclaimer.html/ = If you are not the intended recipient, or have received this message in err= or, please notify the sender immediately and delete this message. --_000_MN2PR05MB6525ECF77DCB55D292E669A9FB789MN2PR05MB6525namp_--