CVE-2021-45105
5.9
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 2.2 / Impact: 3.6
Source: NVD
Description
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.
Affected (208)
Show all products
Apache: Log4j · Netapp: Cloud Manager · Debian: Debian Linux · Sonicwall: Email Security, Network Security Manager, Web Application Firewall, 6bk1602 0aa12 0tp0 Firmware, 6bk1602 0aa22 0tp0 Firmware, 6bk1602 0aa32 0tp0 Firmware, 6bk1602 0aa42 0tp0 Firmware, 6bk1602 0aa52 0tp0 Firmware · Oracle: Agile Engineering Data Management, Agile Plm, Agile Plm Mcad Connector, Autovue For Agile Product Lifecycle Management, Banking Deposits And Lines Of Credit Servicing, Banking Enterprise Default Management, Banking Loans Servicing, Banking Party Management, Banking Payments, Banking Platform, Banking Trade Finance, Banking Treasury Management, Business Intelligence, Communications Asap, Communications Billing And Revenue Management, Communications Cloud Native Core Console, Communications Cloud Native Core Network Function Cloud Native Environment, Communications Cloud Native Core Network Repository Function, Communications Cloud Native Core Network Slice Selection Function, Communications Cloud Native Core Policy, Communications Cloud Native Core Security Edge Protection Proxy, Communications Cloud Native Core Service Communication Proxy, Communications Cloud Native Core Unified Data Repository, Communications Convergence, Communications Convergent Charging Controller, Communications Diameter Signaling Router, Communications Eagle Element Management System, Communications Eagle Ftp Table Base Retrieval, Communications Element Manager, Communications Evolved Communications Application Server, Communications Interactive Session Recorder, Communications Ip Service Activator, Communications Messaging Server, Communications Network Charging And Control, Communications Network Integrity, Communications Performance Intelligence Center, Communications Pricing Design Center, Communications Service Broker, Communications Services Gatekeeper, Communications Session Report Manager, Communications Session Route Manager, Communications Unified Inventory Management, Communications User Data Repository, Communications Webrtc Session Controller, Data Integrator, E Business Suite, Enterprise Manager Base Platform, Enterprise Manager For Peoplesoft, Enterprise Manager Ops Center, Financial Services Analytical Applications Infrastructure, Financial Services Model Management And Governance, Flexcube Universal Banking, Health Sciences Empirica Signal, Health Sciences Inform, Health Sciences Information Manager, Healthcare Data Repository, Healthcare Foundation, Healthcare Master Person Index, Healthcare Translational Research, Hospitality Suite8, Hospitality Token Proxy Service, Hyperion Bi+, Hyperion Data Relationship Management, Hyperion Infrastructure Technology, Hyperion Planning, Hyperion Profitability And Cost Management, Hyperion Tax Provision, Identity Management Suite, Identity Manager Connector, Instantis Enterprisetrack, Insurance Data Gateway, Insurance Insbridge Rating And Underwriting, Jdeveloper, Managed File Transfer, Management Cloud Engine, Mysql Enterprise Monitor, Payment Interface, Peoplesoft Enterprise Peopletools, Primavera Gateway, Primavera P6 Enterprise Project Portfolio Management, Primavera Unifier, Retail Back Office, Retail Central Office, Retail Customer Insights, Retail Data Extractor For Merchandising, Retail Eftlink, Retail Financial Integration, Retail Integration Bus, Retail Invoice Matching, Retail Merchandising System, Retail Order Broker, Retail Order Management System, Retail Point Of Service, Retail Predictive Application Server, Retail Price Management, Retail Returns Management, Retail Service Backbone, Retail Store Inventory Management, Siebel Ui Framework, Sql Developer, Taleo Platform, Utilities Framework, Webcenter Portal, Webcenter Sites, Weblogic Server
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.0 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 10.0.12 | |
| From 2.0 to 3.0 | |
| From 3.0.0 to 3.1.0 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.7.0 |
| Running on/with | Platform Versions |
|---|---|
Sonicwall 6bk1602 0aa12 0tp0 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.7.0 |
| Running on/with | Platform Versions |
|---|---|
Sonicwall 6bk1602 0aa22 0tp0 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.7.0 |
| Running on/with | Platform Versions |
|---|---|
Sonicwall 6bk1602 0aa32 0tp0 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.7.0 |
| Running on/with | Platform Versions |
|---|---|
Sonicwall 6bk1602 0aa42 0tp0 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.7.0 |
| Running on/with | Platform Versions |
|---|---|
Sonicwall 6bk1602 0aa52 0tp0 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.2.1.0 | |
| Version 9.3.6 | |
| Version 3.6 | |
| Version 21.0.2 | |
| Version 2.12.0 | |
| Version 2.12.0 | |
| Version 2.12.0 | |
| Version 2.7.0 | |
| Version 14.5 | |
| Version 2.12.0 | |
| Version 14.5 | |
| Version 14.5 | |
| Version 5.5.0.0.0 | |
| Version 7.3 | |
| Version 12.0.0.4 | |
| Version 1.9.0 | |
| Version 1.10.0 | |
| Version 1.15.0 | |
| Version 1.8.0 | |
| Version 1.15.0 | |
| Version 1.7.0 | |
| Version 1.15.0 | |
| Version 1.15.0 | |
| Version 3.0.2.2.0 | |
| From 12.0.1.0.0 to 12.0.4.0.0 | |
| From 8.3.0.0 to 8.5.1.0 | |
| Version 46.6 | |
| Version 4.5 | |
| Before 9.0 | |
| Version 7.1 | |
| Version 6.3 | |
| Version 7.4.0 | |
| Version 8.1 | |
| From 12.0.1.0.0 to 12.0.4.0.0 | |
| Version 7.3.6 | |
| Version 10.4.0.3 | |
| Version 12.0.0.4 | |
| Version 6.2 | |
| Version 7.0 | |
| Before 9.0 | |
| Before 9.0 | |
| Version 7.3.5 | |
| Version 12.4 | |
| Version 7.2.0.0 | |
| Version 12.2.1.3.0 | |
| Version 12.2 | |
| Version 13.4.0.0 | |
| Version 13.4.1.1 | |
| Version 12.4.0.0 | |
| From 8.0.7 to 8.1.1 | |
| Version 8.0.8.0.0 | |
| From 12.1.0 to 12.4 | |
| Version 9.1.0.6 | |
| Version 6.2.1.1 | |
| From 3.0.1 to 3.0.4 | |
| Version 8.1.1 | |
| From 7.3.0.1 to 7.3.0.4 | |
| Version 5.0.1 | |
| Version 4.1.0 | |
| Version 8.13.0 | |
| Version 19.2 | |
| Before 11.2.8.0 | |
| Before 11.2.8.0 | |
| Before 11.2.8.0 | |
| Before 11.2.8.0 | |
| Before 11.2.8.0 | |
| Before 11.2.8.0 | |
| Version 12.2.1.3.0 | |
| Version 9.1.0 | |
| Version 17.1 | |
| Version 1.0.1 | |
| From 5.4 to 5.6.0.0 | |
| Version 12.2.1.4.0 | |
| Version 12.2.1.3.0 | |
| Version 1.5.0 | |
| Up to 8.0.29 | |
| Version 19.1 | |
| Version 8.58 | |
| From 17.12.0 to 17.12.11 | |
| From 19.12.0.0 to 19.12.18.0 | |
| Version 18.8 | |
| Version 14.1 | |
| Version 14.1 | |
| Version 15.0.2 | |
| Version 15.0.2 | |
| Version 16.0.3 | |
| From 16.0.1 to 16.0.3 | |
| From 16.0.1 to 16.0.3 | |
| Version 15.0.3 | |
| Version 16.0.3 | |
| Version 16.0 | |
| Version 19.5 | |
| Version 14.1 | |
| Version 14.1.3.46 | |
| Version 13.2 | |
| Version 14.1 | |
| From 16.0.1 to 16.0.3 | |
| Version 14.0.4.13 | |
| Up to 21.12 | |
| Before 21.4.2 | |
| Before 22.1 | |
| From 4.3.0.1.0 to 4.3.0.6.0 | |
| Version 12.2.1.3.0 | |
| Version 12.2.1.3.0 | |
| Version 12.2.1.3.0 |
Related CWEs
CWE-20
Improper Input Validation
The product receives input or data, but it does
not validate or incorrectly validates that the input has the
properties that are required to process the data safely and
correctly.
CWE-674
Uncontrolled Recursion
The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.
References (26)
Source: security@apache.org
Mailing ListMitigationThird Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Release NotesVendor Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party AdvisoryUS Government Resource
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListMitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Timeline
No history available yet.