ARTICLE
7 January 2022

FTC Warns Companies To Remediate Log4j Security Vulnerability

M
Mintz
Contributor
Mintz is a general practice, full-service Am Law 100 law firm with more than 600 attorneys. We are headquartered in Boston and have additional US offices in Los Angeles, Miami, New York City, San Diego, San Francisco, and Washington, DC, as well as an office in Toronto, Canada.
Before the holidays, we warned of a critical vulnerability in a widely-used Java logging utility that could affect tens of thousands of companies.
United States Technology
To print this article, all you need is to be registered or login on Mondaq.com.

Before the holidays, we warned of a critical vulnerability in a widely-used Java logging utility that could affect tens of thousands of companies. Since that original alert, multiple US and foreign government cybersecurity agencies published a joint advisory and guidance for affected organizations recommending that patches or workarounds be applied immediately to mitigate the vulnerabilities and exposure. The US Cybersecurity and Infrastructure Security Agency also ordered US federal civilian executive branch agencies to patch within days of the order.

The Federal Trade Commission has now issued a release warning all companies utilizing the Java-based Log4j to identify and remedy the reported vulnerabilities. The FTC warns that companies are obligated to "take reasonable steps to mitigate known software vulnerabililties" under various laws, including the FTC Act and the Gramm-Leach-Bliley Act, and that the Commission "intends to use its full legal authority to pursue companies that fail to take reasonable steps to protect consumer data from exposure."

If your company has not analyzed its exposure to Log4j, it is time to do so and to deploy patches or workarounds if patches are not possible. Apache has created a full site with patches and more information. Breaches resulting from a failure to address this critical vulnerability can exposure your company to regulatory actions in addition to potential litigation.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

We operate a free-to-view policy, asking only that you register in order to read all of our content. Please login or register to view the rest of this article.

ARTICLE
7 January 2022

FTC Warns Companies To Remediate Log4j Security Vulnerability

United States Technology
Contributor
Mintz is a general practice, full-service Am Law 100 law firm with more than 600 attorneys. We are headquartered in Boston and have additional US offices in Los Angeles, Miami, New York City, San Diego, San Francisco, and Washington, DC, as well as an office in Toronto, Canada.
See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More