CVE-2021-44832
6.6
Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.7 / Impact: 5.9
Source: NVD
Description
Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.
Affected (55)
Products: Apache: Log4j · Oracle: Communications Diameter Signaling Router, Primavera P6 Enterprise Project Portfolio Management, Retail Assortment Planning, Retail Fiscal Management, Siebel Ui Framework, Communications Brm Elastic Charging Engine, Communications Interactive Session Recorder, Communications Offline Mediation Controller, Flexcube Private Banking, Health Sciences Data Management Workbench, Policy Automation, Policy Automation For Mobile Devices, Primavera Gateway, Primavera Unifier, Product Lifecycle Analytics, Retail Order Broker, Retail Xstore Point Of Service, Weblogic Server · Cisco: Cloudcenter · +2 more
Show all products
Apache: Log4j · Oracle: Communications Diameter Signaling Router, Primavera P6 Enterprise Project Portfolio Management, Retail Assortment Planning, Retail Fiscal Management, Siebel Ui Framework, Communications Brm Elastic Charging Engine, Communications Interactive Session Recorder, Communications Offline Mediation Controller, Flexcube Private Banking, Health Sciences Data Management Workbench, Policy Automation, Policy Automation For Mobile Devices, Primavera Gateway, Primavera Unifier, Product Lifecycle Analytics, Retail Order Broker, Retail Xstore Point Of Service, Weblogic Server · Cisco: Cloudcenter · Fedoraproject: Fedora · Debian: Debian Linux
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 8.0.0.0 to 8.5.1.0 | |
| From 19.12.0 to 19.12.18.0 | |
| Version 16.0.3 | |
| Version 14.2 | |
| Version 21.12 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.10.0.16 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 34 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 9.0 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 12.0.0.4.6 | |
| From 8.3.0.0 to 8.5.1.0 | |
| Version 6.3 | |
| Before 12.0.0.4.4 | |
| Version 12.1.0 | |
| Version 2.5.2.1 | |
| From 12.2.0 to 12.2.24 | |
| From 12.2.0 to 12.2.24 | |
| From 17.12.0 to 17.12.11 | |
| From 19.12.0.0 to 19.12.18.0 | |
| Version 18.8 | |
| Version 3.6.1 | |
| Version 18.0 | |
| Version 17.0.4 | |
| Up to 21.12 | |
| Version 12.2.1.3.0 |
Related CWEs
CWE-20
Improper Input Validation
The product receives input or data, but it does
not validate or incorrectly validates that the input has the
properties that are required to process the data safely and
correctly.
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
References (24)
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Issue TrackingPatchVendor Advisory
Source: security@apache.org
Mailing ListVendor Advisory
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Third Party Advisory
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Timeline
No history available yet.