← Back

CVE-2021-45046

Published: Dec 14, 2021Modified: Jun 17, 2026CISA KEV

JSON object

Loading...
9.0
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 6.0
Source: NVD

Description

It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in an information leak and remote code execution in some environments and local code execution in all environments. Log4j 2.16.0 (Java 8) and 2.12.2 (Java 7) fix this issue by removing support for message lookup patterns and disabling JNDI functionality by default.

Affected (90)

Show all products
1 product
Log4j
1 product
Computer Vision Annotation Tool
8 products
Audio Development Kit
Datacenter Manager
Genomics Kernel Library
Oneapi
Secure Device Onboard
System Debugger
System Studio
42 products
Sppa T3000 Ses3000 Firmware
Captial
Comos
Desigo Cc Advanced Reports
Desigo Cc Info Center
E Car Operation Center
Energy Engage
Energyip
Energyip Prepay
Gma Manager
Industrial Edge Management
Industrial Edge Management Hub
Logo! Soft Comfort
Mendix
Mindsphere
Navigator
Nx
Opcenter Intelligence
Operation Scheduler
Sentron Powermanager
Siguard Dsa
Sipass Integrated
Siveillance Command
Siveillance Control Pro
Siveillance Identity
Siveillance Vantage
Siveillance Viewpoint
Solid Edge Cam Pro
Solid Edge Harness Design
Spectrum Power 4
Spectrum Power 7
Teamcenter
Tracealertserverplus
Vesys
Xpedition Enterprise
Xpedition Package Integrator
6bk1602 0aa12 0tp0 Firmware
6bk1602 0aa22 0tp0 Firmware
6bk1602 0aa32 0tp0 Firmware
6bk1602 0aa42 0tp0 Firmware
6bk1602 0aa52 0tp0 Firmware
1 product
Debian Linux
1 product
Email Security
1 product
Fedora
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Apache
From 2.0.1 to 2.12.2
From 2.13.0 to 2.16.0
Version 2.0
Version 2.0 beta9
Version 2.0 rc1
Version 2.0 rc2
Configuration B
9 vulnerable
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Siemens
Sppa T3000 Ses3000
All versions
Configuration D
64 vulnerable
Vulnerable SoftwareAffected Versions
Siemens
Before 2019.1
Version 2019.1
Version 2019.1 sp1912
All versions
Siemens
Version 4.0
Version 4.1
Version 4.2
Version 5.0
Version 5.1
Siemens
Version 5.0
Version 5.1
Before 2021-12-13
Version 3.1
Siemens
Version 8.5
Version 8.6
Version 8.7
Version 9.0
Siemens
Version 3.7
Version 3.8
Before 8.6.2j-398
All versions
All versions
Before 2021-12-13
All versions
All versions
Before 2021-12-11
Before 2021-12-13
All versions
Up to 3.2
Up to 1.1.3
Siemens
Version 4.1
Version 4.2
Siemens
Version 4.2
Version 4.3
Version 4.4
Siemens
Version 2.80
Version 2.85
Up to 4.16.2.1
All versions
Siemens
Version 1.5
Version 1.6
All versions
All versions
All versions
Siemens
Before 2020
Version 2020
Version 2020
Version 2020 sp2002
Siemens
Before 4.70
Version 4.70
Version 4.70 sp7
Version 4.70 sp8
Siemens
Before 2.30
Version 2.30
Version 2.30
Version 2.30 sp2
All versions
All versions
Siemens
Before 2019.1
Version 2019.1
Version 2019.1
Version 2019.1 sp1912
All versions
All versions
Configuration E
2 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 10.0
Version 11.0
Configuration F
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 10.0.12
Configuration G
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 34
Version 35
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.7.0
Running on/withPlatform Versions
Siemens
6bk1602 0aa12 0tp0
All versions
Configuration I
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.7.0
Running on/withPlatform Versions
Siemens
6bk1602 0aa22 0tp0
All versions
Configuration J
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.7.0
Running on/withPlatform Versions
Siemens
6bk1602 0aa32 0tp0
All versions
Configuration K
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.7.0
Running on/withPlatform Versions
Siemens
6bk1602 0aa42 0tp0
All versions
Configuration L
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.7.0
Running on/withPlatform Versions
Siemens
6bk1602 0aa52 0tp0
All versions

References (43)

Source: security@apache.org
Mailing ListMitigationThird Party Advisory
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
MitigationRelease NotesVendor Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Not Applicable
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party AdvisoryUS Government Resource
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListMitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationRelease NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Not Applicable
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.