← Back

CVE-2021-4104

nvd nist
Published: Dec 14, 2021Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.6 / Impact: 5.9
Source: NVD

Description

JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-44228. Note this issue only affects Log4j 1.2 when specifically configured to use JMSAppender, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.

Affected (72)

Show all products
1 product
Log4j
1 product
Fedora
18 products
Codeready Studio
Enterprise Linux
Integration Camel K
Integration Camel Quarkus
Jboss A Mq
Jboss A Mq Streaming
Jboss Data Grid
Jboss Data Virtualization
Jboss Fuse
Jboss Fuse Service Works
Jboss Operations Network
Jboss Web Server
Openshift Application Runtimes
Openshift Container Platform
Process Automation
Single Sign On
Software Collections
26 products
Advanced Supply Chain Planning
Business Intelligence
Business Process Management Suite
Communications Messaging Server
Communications Network Integrity
Enterprise Manager Base Platform
Goldengate
Healthcare Data Repository
Identity Management Suite
Jdeveloper
Mysql Enterprise Monitor
Retail Allocation
Retail Extract Transform And Load
Stream Analytics
Timesten Grid
Tuxedo
Utilities Testing Accelerator
Weblogic Server
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 1.2
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 35
Configuration C
25 vulnerable
Configuration D
45 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 12.1
Version 12.2
Oracle
Version 12.2.1.3.0
Version 12.2.1.4.0
Version 5.9.0.0.0
Oracle
Version 12.2.1.3.0
Version 12.2.1.4.0
Version 4.5
Version 8.1
Version 7.3.6
Oracle
Before 12.0.0.4.0
Version 12.0.0.5.0
Oracle
Version 7.3.4
Version 7.3.5
Version 7.4.1
Version 7.4.2
Version 2.2.1.1.1
Oracle
Version 13.4.0.0
Version 13.5.0.0
Oracle
Version 2.7.0.0
Version 2.7.0.1
Version 2.8.0.0
Version 12.2.1.4.0
All versions
Version 8.1.0
Before 11.2.8.0
Before 11.2.8.0
Oracle
Version 12.2.1.3.0
Version 12.2.1.4.0
Version 12.2.1.3.0
Up to 8.0.29
Oracle
Version 14.1.3.2
Version 15.0.3.1
Version 16.0.3
Version 19.0.1
Version 13.2.5
All versions
All versions
Version 12.2.2.0.0
Oracle
Version 6.0.0.1.1
Version 6.0.0.2.2
Version 6.0.0.3.1
Oracle
Version 12.2.1.3.0
Version 12.2.1.4.0
Version 14.1.1.0.0

References (28)

Source: security@apache.org
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.