The Java vulnerability “Log4Shell” (CVE-2021-44228) is currently causing uncertainty. The German Federal Office for Information Security (BSI) has been issuing the highest warning level “4/Red” since the weekend. As far as QPLIX systems are concerned, we can assure our customers that QPLIX is safe. Neither the QPLIX core software (“Q”), nor the web portals and mobile apps are affected by the vulnerability.
The QPLIX systems are protected by a multi-layer security architecture. They are strictly isolated from each other and operated in high-security data centres on our own server infrastructure (i.e. not in the public cloud). Moreover, a web application firewall with two-factor authentication only allows authorised users to pass through. This way, QPLIX ensures maximum security.