Is Upland affected by the Log4j vulnerability?
Incident Report for Adestra
Resolved
Upland’s environment is not materially impacted by the Log4j vulnerability.

On December 9th, Cybersecurity & Infrastructure Security Agency (CISA) reported a vulnerability in the Apache’sLog4j, versions 2.14.1 and below (CVE-2021-44228).

How did Upland respond to the Log4j vulnerability?

Steps have been taken to mitigate the risk of the vulnerability. Upland deployed the Apache (Log4j 2.15.0) patch to mitigate the vulnerability. Additionally, Upland established detection and prevention measures to monitor against potential attacks.

What’s next?

Upland’s security team continues to monitor the Log4j vulnerability and is assessing information as it’s made available. Additional customer updates will be provided as needed.

Please click below for the complete Upland response:

Upland Corporate Statement Log4J
https://fileservices.uplandsoftware.com/public/file/y5sYhvLZBUaWO3PJzf10AQ/Upland%20Software_Log4J_v2_Final.pdf
Posted Dec 09, 2021 - 17:00 GMT