


As Minecraft did, many organizations will need to develop their own patches or will be unable to patch immediately because they are running legacy software, like older versions of Java. The situation underscores the challenges of managing risk within interdependent enterprise software.

The organization says that Chen Zhaojun of Alibaba Cloud Security Team first disclosed the vulnerability. There are some mitigating factors, but this being the real world there will be many companies that are not on current releases that are scrambling to fix this.”Īpache rates the vulnerability at “critical” severity and published patches and mitigations on Friday. “So many people are vulnerable, and this is so easy to exploit.
