9.0
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 6.0
Source: NVD
Description
It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in an information leak and remote code execution in some environments and local code execution in all environments. Log4j 2.16.0 (Java 8) and 2.12.2 (Java 7) fix this issue by removing support for message lookup patterns and disabling JNDI functionality by default.
Affected (90)
Products: Apache: Log4j · Cvat: Computer Vision Annotation Tool · Intel: Audio Development Kit, Datacenter Manager, Genomics Kernel Library, Oneapi, Secure Device Onboard, Sensor Solution Firmware Development Kit, System Debugger, System Studio · +4 more
Show all products
Apache: Log4j · Cvat: Computer Vision Annotation Tool · Intel: Audio Development Kit, Datacenter Manager, Genomics Kernel Library, Oneapi, Secure Device Onboard, Sensor Solution Firmware Development Kit, System Debugger, System Studio · Siemens: Sppa T3000 Ses3000 Firmware, Captial, Comos, Desigo Cc Advanced Reports, Desigo Cc Info Center, E Car Operation Center, Energy Engage, Energyip, Energyip Prepay, Gma Manager, Head End System Universal Device Integration System, Industrial Edge Management, Industrial Edge Management Hub, Logo! Soft Comfort, Mendix, Mindsphere, Navigator, Nx, Opcenter Intelligence, Operation Scheduler, Sentron Powermanager, Siguard Dsa, Sipass Integrated, Siveillance Command, Siveillance Control Pro, Siveillance Identity, Siveillance Vantage, Siveillance Viewpoint, Solid Edge Cam Pro, Solid Edge Harness Design, Spectrum Power 4, Spectrum Power 7, Teamcenter, Tracealertserverplus, Vesys, Xpedition Enterprise, Xpedition Package Integrator, 6bk1602 0aa12 0tp0 Firmware, 6bk1602 0aa22 0tp0 Firmware, 6bk1602 0aa32 0tp0 Firmware, 6bk1602 0aa42 0tp0 Firmware, 6bk1602 0aa52 0tp0 Firmware · Debian: Debian Linux · Sonicwall: Email Security · Fedoraproject: Fedora
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Sppa T3000 Ses3000 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2019.1 | |
| All versions | |
| Version 4.0 | |
| Version 5.0 | |
| Before 2021-12-13 | |
| Version 3.1 | |
| Version 8.5 | |
| Version 3.7 | |
| Before 8.6.2j-398 | |
| All versions | |
| All versions | |
| Before 2021-12-13 | |
| All versions | |
| All versions | |
| Before 2021-12-11 | |
| Before 2021-12-13 | |
| All versions | |
| Up to 3.2 | |
| Up to 1.1.3 | |
| Version 4.1 | |
| Version 4.2 | |
| Version 2.80 | |
| Up to 4.16.2.1 | |
| All versions | |
| Version 1.5 | |
| All versions | |
| All versions | |
| All versions | |
| Before 2020 | |
| Before 4.70 | |
| Before 2.30 | |
| All versions | |
| All versions | |
| Before 2019.1 | |
| All versions | |
| All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.0 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 10.0.12 |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version 34 |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.7.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens 6bk1602 0aa12 0tp0 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.7.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens 6bk1602 0aa22 0tp0 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.7.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens 6bk1602 0aa32 0tp0 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.7.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens 6bk1602 0aa42 0tp0 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.7.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens 6bk1602 0aa52 0tp0 | All versions |
References (43)
Source: security@apache.org
Mailing ListMitigationThird Party Advisory
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Mailing ListRelease Notes
Source: security@apache.org
Mailing ListRelease Notes
Source: security@apache.org
MitigationRelease NotesVendor Advisory
Source: security@apache.org
Third Party Advisory
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party AdvisoryUS Government Resource
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListMitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListRelease Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListRelease Notes
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationRelease NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Not Applicable
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource
Timeline
No history available yet.