Log4Shell Vulnerability - CVE-2021-44228
Incident Report for 365 Retail Markets - System
Resolved
Dear Valued Customers,

At this time, 365 Retail Markets is not impacted by any log4j vulnerabilities. We will continue to monitor all systems and our inventory to continue to ensure they remain secure and confidential.

Thank you,
365 Support Team
Posted Jan 03, 2022 - 11:37 EST
Update
Dear Valued Customers,

At this time, 365 Retail Markets is not impacted by any log4j vulnerabilities. We will continue to monitor all systems and our inventory to continue to ensure they remain secure and confidential.

Thank you,
365 Support Team
Posted Dec 21, 2021 - 09:00 EST
Monitoring
Dear Valued Customers,

On Friday, a zero-day vulnerability was discovered in the Java logging framework impacting Log4j. It has been labeled CVE-2021-44228 and more details can be found on the NIST National Vulnerability Database webpage: https://nvd.nist.gov/vuln/detail/CVE-2021-44228

Since receiving the notice we have been actively applying patching to all systems in scope and can assure you that all external facing apps and networking devices have been successfully patched.

We are continuing to evaluate all systems in our inventory and will continue to address them as necessary to ensure the security and safety of all devices and information under 365's care.

Please continue to check back for updates as the global situation evolves.

Thank you,
365 Support Team
Posted Dec 21, 2021 - 07:57 EST
Identified
Dear Valued Customers,

On Friday, a zero-day vulnerability was discovered in the Java logging framework impacting Log4j. It has been labeled CVE-2021-44228 and more details can be found on the NIST National Vulnerability Database webpage: https://nvd.nist.gov/vuln/detail/CVE-2021-44228

Since receiving the notice we have been actively applying patching to all systems in scope and can assure you that all external facing apps and networking devices have been successfully patched.

We are continuing to evaluate all systems in our inventory and will continue to address them as necessary to ensure the security and safety of all devices and information under 365's care.

Please continue to check back for updates as the global situation evolves.

Thank you,
365 Support Team
Posted Dec 14, 2021 - 12:23 EST
This incident affected: Legacy (SmartHQ, Credit Card Gateway, VDI Integrations, Global Market Accounts, LightSpeed Integration), V5 Platform (ADM, Credit Card Gateway, VDI Integrations, Global Market Accounts, LightSpeed Integration, MyMarketAccount.net), Stockwell (Ops Tool, Global Market Account), AirVend Vending (AV Live, Payment Gateway), and Company Kitchen (Business Trax, Credit Card Gateway, Mobile App, VDI, Lightspeed).