Last week a new and pervasive vulnerability was announced in a commonly used component of the Java programming framework. Used in millions of programs globally, the “Log4J” vulnerability allows a hacker to easily gain remote access to vulnerable computers. UC San Diego has seen thousands of attacks against networked computers since the announcement, and campus and Health IT professionals have been working since last week to identify and secure vulnerable computers and services.
However, this vulnerability is exceptionally difficult to detect remotely, and thus we need everyone responsible for computing resources, particularly in research environments that maintain their own systems, to apply the appropriate remediations outlined below. The severity of this situation is such that beginning Monday, December 20, when a vulnerable system is identified it will be immediately removed from the network.
Immediate Actions