← Back

CVE-2021-44832

nvd nist
Published: Dec 28, 2021Modified: Jun 17, 2026

JSON object

Loading...
6.6
Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.7 / Impact: 5.9
Source: NVD

Description

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.

Affected (55)

Show all products
1 product
Log4j
18 products
Retail Assortment Planning
Retail Fiscal Management
Siebel Ui Framework
Flexcube Private Banking
Policy Automation
Primavera Gateway
Primavera Unifier
Product Lifecycle Analytics
Retail Order Broker
Retail Xstore Point Of Service
Weblogic Server
1 product
Cloudcenter
1 product
Fedora
1 product
Debian Linux
Configuration A
9 vulnerable
Vulnerable SoftwareAffected Versions
Apache
From 2.0.1 to 2.3.2
From 2.13.0 to 2.17.1
From 2.4 to 2.12.4
Version 2.0
Version 2.0 beta7
Version 2.0 beta8
Version 2.0 beta9
Version 2.0 rc1
Version 2.0 rc2
Configuration B
5 vulnerable
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 4.10.0.16
Configuration D
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 34
Version 35
Configuration E
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 9.0
Configuration F
37 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Before 12.0.0.4.6
Version 12.0.0.5.0
From 8.3.0.0 to 8.5.1.0
Oracle
Version 6.3
Version 6.4
Oracle
Before 12.0.0.4.4
Version 12.0.0.5.0
Version 12.1.0
Oracle
Version 2.5.2.1
Version 3.0.0.0
Version 3.1.0.3
From 12.2.0 to 12.2.24
From 12.2.0 to 12.2.24
Oracle
From 17.12.0 to 17.12.11
From 18.8.0 to 18.8.13
From 19.12.0 to 19.12.12
From 20.12.0 to 20.12.7
Version 21.12.0
Oracle
From 19.12.0.0 to 19.12.18.0
From 20.12.0.0 to 20.12.12.0
Version 21.12.0.0
Oracle
Version 18.8
Version 19.12
Version 20.12
Version 21.12
Version 3.6.1
Oracle
Version 18.0
Version 19.1
Oracle
Version 17.0.4
Version 18.0.3
Version 19.0.2
Version 20.0.1
Version 21.0.1
Up to 21.12
Oracle
Version 12.2.1.3.0
Version 12.2.1.4.0
Version 14.1.1.0.0

References (24)

Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Issue TrackingPatchVendor Advisory
Source: security@apache.org
Mailing ListVendor Advisory
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.