We do not use an Apache web server in our products and are therefore not affected by the hack, which is currently breaking news.
The vulnerability, called Log4shell, allows an attacker to remotely and, without authentication, execute arbitrary code with the privileges of the application. On the unit scale, it has the term critical, the highest possible score.
The Java tool is used, among other things, to record login attempts, but the software is also included in many hundreds, if not thousands, of software products and applications.
Back to news items