LOG4J
Log4Shell is a nickname for a vulnerability in a Java software component called Log4j. Log4j is embedded into numerous applications and is used to log activity such as visitors to a website. The vulnerability can be remotely exploited by adversaries to gain unauthorized access to systems.
On Friday, December 10, a critical software vulnerability known as Log4Shell was broadly publicized. Alarmingly, this vulnerability is widespread, affecting organizations worldwide and putting numerous Stanford systems at risk. The Information Security Office (ISO) has detected related activity targeting our systems and has been working around the clock with IT teams throughout the university to apply fixes as quickly as possible.
Laptops, desktops, and mobile devices may be using this software, but they are not generally at risk. The most vulnerable systems are servers and web-based applications. We are prioritizing internet-facing services, as these are the most susceptible of all.