10.0
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 6.0
Source: NVD
Description
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.
Affected (372)
Products: Siemens: 6bk1602 0aa12 0tp0 Firmware, 6bk1602 0aa22 0tp0 Firmware, 6bk1602 0aa32 0tp0 Firmware, 6bk1602 0aa42 0tp0 Firmware, 6bk1602 0aa52 0tp0 Firmware, Sppa T3000 Ses3000 Firmware, Capital, Comos, Desigo Cc Advanced Reports, Desigo Cc Info Center, E Car Operation Center, Energy Engage, Energyip, Energyip Prepay, Gma Manager, Head End System Universal Device Integration System, Industrial Edge Management, Industrial Edge Management Hub, Logo! Soft Comfort, Mendix, Mindsphere, Navigator, Nx, Opcenter Intelligence, Operation Scheduler, Sentron Powermanager, Siguard Dsa, Sipass Integrated, Siveillance Command, Siveillance Control Pro, Siveillance Identity, Siveillance Vantage, Siveillance Viewpoint, Solid Edge Cam Pro, Solid Edge Harness Design, Spectrum Power 4, Spectrum Power 7, Teamcenter, Vesys, Xpedition Enterprise, Xpedition Package Integrator · Apache: Log4j · Intel: Computer Vision Annotation Tool, Datacenter Manager, Genomics Kernel Library, Oneapi Sample Browser, Secure Device Onboard, System Studio · +9 more
Show all products
Siemens: 6bk1602 0aa12 0tp0 Firmware, 6bk1602 0aa22 0tp0 Firmware, 6bk1602 0aa32 0tp0 Firmware, 6bk1602 0aa42 0tp0 Firmware, 6bk1602 0aa52 0tp0 Firmware, Sppa T3000 Ses3000 Firmware, Capital, Comos, Desigo Cc Advanced Reports, Desigo Cc Info Center, E Car Operation Center, Energy Engage, Energyip, Energyip Prepay, Gma Manager, Head End System Universal Device Integration System, Industrial Edge Management, Industrial Edge Management Hub, Logo! Soft Comfort, Mendix, Mindsphere, Navigator, Nx, Opcenter Intelligence, Operation Scheduler, Sentron Powermanager, Siguard Dsa, Sipass Integrated, Siveillance Command, Siveillance Control Pro, Siveillance Identity, Siveillance Vantage, Siveillance Viewpoint, Solid Edge Cam Pro, Solid Edge Harness Design, Spectrum Power 4, Spectrum Power 7, Teamcenter, Vesys, Xpedition Enterprise, Xpedition Package Integrator · Apache: Log4j · Intel: Computer Vision Annotation Tool, Datacenter Manager, Genomics Kernel Library, Oneapi Sample Browser, Secure Device Onboard, System Studio · Debian: Debian Linux · Fedoraproject: Fedora · Sonicwall: Email Security · Netapp: Active Iq Unified Manager, Brocade San Navigator, Cloud Insights, Cloud Manager, Cloud Secure Agent, Oncommand Insight, Ontap Tools, Snapcenter, Solidfire & Hci Storage Node, Solidfire Enterprise Sds · Cisco: Advanced Malware Protection Virtual Private Cloud Appliance, Automated Subsea Tuning, Broadworks, Business Process Automation, Cloud Connect, Cloudcenter, Cloudcenter Cost Optimizer, Cloudcenter Suite Admin, Cloudcenter Workload Manager, Common Services Platform Collector, Connected Mobile Experiences, Contact Center Domain Manager, Contact Center Management Portal, Crosswork Data Gateway, Crosswork Network Controller, Crosswork Optimization Engine, Crosswork Platform Infrastructure, Crosswork Zero Touch Provisioning, Customer Experience Cloud Agent, Cyber Vision Sensor Management Extension, Data Center Network Manager, Dna Center, Dna Spaces, Emergency Responder, Enterprise Chat And Email, Evolved Programmable Network Manager, Finesse, Fog Director, Identity Services Engine, Integrated Management Controller Supervisor, Intersight Virtual Appliance, Iot Operations Dashboard, Network Assurance Engine, Network Services Orchestrator, Nexus Dashboard, Nexus Insights, Optical Network Controller, Packaged Contact Center Enterprise, Paging Server, Prime Service Catalog, Sd Wan Vmanage, Smart Phy, Ucs Central, Ucs Director, Unified Communications Manager, Unified Communications Manager Im And Presence Service, Unified Contact Center Enterprise, Unified Contact Center Express, Unified Customer Voice Portal, Unified Intelligence Center, Unified Sip Proxy, Unified Workforce Optimization, Unity Connection, Video Surveillance Operations Manager, Virtual Topology System, Virtualized Infrastructure Manager, Virtualized Voice Browser, Wan Automation Engine, Webex Meetings Server, Workload Optimization Manager, Fxos, Cloudcenter Suite, Crosswork Network Automation, Cx Cloud Agent, Cyber Vision, Dna Spaces Connector, Firepower Threat Defense, Mobility Services Engine, Network Dashboard Fabric Controller, Network Insights For Data Center, Ucs Central Software, Unified Communications Manager Im & Presence Service, Unified Computing System, Unified Contact Center Management Portal, Video Surveillance Manager · Snowsoftware: Snow Commander, Vm Access Proxy · Bentley: Synchro, Synchro 4d · Percussion: Rhythmyx · Apple: Xcode
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.7.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens 6bk1602 0aa12 0tp0 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.7.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens 6bk1602 0aa22 0tp0 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.7.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens 6bk1602 0aa32 0tp0 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.7.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens 6bk1602 0aa42 0tp0 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.7.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens 6bk1602 0aa52 0tp0 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Sppa T3000 Ses3000 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2019.1 | |
| Before 10.4.2 | |
| Version 3.0 | |
| Version 5.0 | |
| Before 2021-12-13 | |
| Version 3.1 | |
| Version 8.5 | |
| Before 3.8.0.12 | |
| Before 8.6.2j-398 | |
| All versions | |
| All versions | |
| Before 2021-12-13 | |
| All versions | |
| All versions | |
| Before 2021-12-16 | |
| Before 2021-12-13 | |
| All versions | |
| From 3.2 to 3.5 | |
| Up to 1.1.3 | |
| Version 4.1 | |
| From 4.2 to 4.4.1 | |
| Version 2.80 | |
| Up to 4.16.2.1 | |
| All versions | |
| Version 1.5 | |
| All versions | |
| All versions | |
| All versions | |
| Before 2020 | |
| Before 4.70 | |
| Before 2.30 | |
| All versions | |
| Before 2019.1 | |
| All versions | |
| All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| Before 5.1 | |
| All versions | |
| All versions | |
| All versions | |
| All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.0 |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Version 34 |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 10.0.13 |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.5.4 | |
| Before 2.1.0 | |
| Before 2021.11_1.162 | |
| Before 3.0.000.115 | |
| Before 12.6\(1\) | |
| Before 4.10.0.16 | |
| Before 5.5.2 | |
| Before 5.3.1 | |
| Before 5.5.2 | |
| Before 2.9.1.3 | |
| All versions | |
| Before 12.5\(1\) | |
| Before 12.5\(1\) | |
| Before 2.0.2 | |
| Before 2.0.1 | |
| Before 2.0.1 | |
| Before 4.0.1 | |
| Before 2.0.1 | |
| Before 1.12.1 | |
| Before 4.0.3 | |
| Before 11.3\(1\) | |
| Before 2.1.2.8 | |
| Before 2.5 | |
| Before 11.5\(4\) | |
| Before 12.0\(1\) | |
| Up to 4.1.1 | |
| Before 12.6\(1\) | |
| All versions | |
| Before 2.4.0 | |
| Before 2.3.2.1 | |
| Before 1.0.9-361 | |
| All versions | |
| Before 6.0.2 | |
| Before 5.3.5.1 | |
| Before 2.1.2 | |
| Before 6.0.2 | |
| Before 1.1.0 | |
| Before 11.6 | |
| Before 14.4.1 | |
| Before 12.1 | |
| Before 20.3.4.1 | |
| Before 3.2.1 | |
| Before 2.0\(1p\) | |
| Before 6.8.2.0 | |
| Before 11.5\(1\) | |
| Before 11.5\(1\) | |
| Before 11.6\(2\) | |
| Before 12.5\(1\) | |
| Before 11.6 | |
| Before 12.6\(1\) | |
| Before 10.2.1v2 | |
| Before 11.5\(1\) | |
| Before 11.5\(1\) | |
| Before 7.14.4 | |
| Before 2.6.7 | |
| Before 3.2.0 | |
| Before 12.5\(1\) | |
| Before 7.3.0.2 | |
| Before 3.0 | |
| Before 3.2.1 |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.2.3 |
| Running on/with | Platform Versions |
|---|---|
Cisco Firepower 1010 | All versions |
Cisco Firepower 1120 | All versions |
Cisco Firepower 1140 | All versions |
Cisco Firepower 1150 | All versions |
Cisco Firepower 2110 | All versions |
Cisco Firepower 2120 | All versions |
Cisco Firepower 2130 | All versions |
Cisco Firepower 2140 | All versions |
Cisco Firepower 4110 | All versions |
Cisco Firepower 4112 | All versions |
Cisco Firepower 4115 | All versions |
Cisco Firepower 4120 | All versions |
Cisco Firepower 4125 | All versions |
Cisco Firepower 4140 | All versions |
Cisco Firepower 4145 | All versions |
Cisco Firepower 4150 | All versions |
Cisco Firepower 9300 | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Version 02.01.00 | |
| All versions | |
| Version 4.10.0.15 | |
| Version 002.009(000.000) | |
| All versions | |
| Version 001.012 | |
| Version 4.0.2 | |
| Version 4.0.2 | |
| Version 2.2.2.8 | |
| All versions | |
| All versions | |
| Version 11.5 | |
| Version 12.0(1) | |
| Version 3.0 | |
| Version 12.5(1) su1 | |
| Version 6.2.3 | |
| Version 002.004(000.914) | |
| Version 002.003(002.000) | |
| Version 1.0.9-343 | |
| All versions | |
| Version 6.0(2.1912) | |
| Version 11.0(1) | |
| Version 6.0(2.1914) | |
| All versions | |
| Version 1.1 | |
| Version 12.5(2) | |
| Version 12.1 | |
| Version 20.3 | |
| Version 21.3 | |
| Version 2.0 | |
| Version 11.5(1.17900.52) | |
| Version 11.5(1.22900.6) | |
| Version 006.008(001.000) | |
| Version 11.6(2) | |
| Version 12.5(1) | |
| Version 12.6(1) | |
| Version 11.6(1) | |
| Version 12.6(1) | |
| Version 010.000(000) | |
| Version 11.5(1) sr7 | |
| Version 11.5 | |
| Version 7.14(1.26) | |
| Version 2.6.6 | |
| Version 7.1.3 | |
| Version 3.0 |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.10.0 | |
| Before 3.6 |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| From 6.1 to 6.2.4.2 | |
| Before 6.4.3.2 |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 7.3.2 |
Related CWEs
CWE-20
Improper Input Validation
The product receives input or data, but it does
not validate or incorrectly validates that the input has the
properties that are required to process the data safely and
correctly.
CWE-400
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CWE-502
Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.
CWE-917
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
The product constructs all or part of an expression language (EL) statement in a framework such as a Java Server Page (JSP) using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended EL statement before it is executed.
References (103)
Source: security@apache.org
Third Party AdvisoryVDB Entry
Source: security@apache.org
Third Party AdvisoryVDB Entry
Source: security@apache.org
ExploitThird Party AdvisoryVDB Entry
Source: security@apache.org
ExploitThird Party AdvisoryVDB Entry
Source: security@apache.org
Third Party AdvisoryVDB Entry
Source: security@apache.org
Third Party AdvisoryVDB Entry
Source: security@apache.org
Third Party AdvisoryVDB Entry
Source: security@apache.org
Third Party AdvisoryVDB Entry
Source: security@apache.org
Broken LinkThird Party AdvisoryVDB Entry
Source: security@apache.org
ExploitThird Party AdvisoryVDB Entry
Source: security@apache.org
ExploitThird Party AdvisoryVDB Entry
Source: security@apache.org
ExploitThird Party AdvisoryVDB Entry
Source: security@apache.org
ExploitThird Party AdvisoryVDB Entry
Source: security@apache.org
Third Party AdvisoryVDB Entry
Source: security@apache.org
ExploitThird Party AdvisoryVDB Entry
Source: security@apache.org
Third Party AdvisoryVDB Entry
Source: security@apache.org
ExploitMailing ListThird Party Advisory
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Mailing ListMitigationThird Party Advisory
Source: security@apache.org
Mailing ListMitigationThird Party Advisory
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Broken LinkProductUS Government Resource
Source: security@apache.org
ExploitThird Party Advisory
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Release Notes
Source: security@apache.org
Release Notes
Source: security@apache.org
Release NotesVendor Advisory
Source: security@apache.org
PatchThird Party AdvisoryVendor Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Broken LinkExploitThird Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party AdvisoryUS Government Resource
Source: security@apache.org
ExploitThird Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListMitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListMitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkProductUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party AdvisoryVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Third Party AdvisoryUS Government Resource
Timeline
No history available yet.