7.5
CVE-2021-4104
- EPSS 81.15%
- Veröffentlicht 14.12.2021 12:15:12
- Zuletzt bearbeitet 28.05.2026 21:16:28
- Erkennungen
Deserialization of untrusted data in JMSAppender in Apache Log4j 1.2
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-44228. Note this issue only affects Log4j 1.2 when specifically configured to use JMSAppender, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fedoraproject ≫ Fedora Version 35
Redhat ≫ Codeready Studio Version 12.0
Redhat ≫ Integration Camel K Version -
Redhat ≫ Integration Camel Quarkus Version -
Redhat ≫ Jboss A-mq Version 6.0.0
Redhat ≫ Jboss A-mq Version 7
Redhat ≫ Jboss A-mq Streaming Version -
Redhat ≫ Jboss Data Grid Version 7.0.0
Redhat ≫ Jboss Data Virtualization Version 6.0.0
Redhat ≫ Jboss Enterprise Application Platform Version 6.0.0
Redhat ≫ Jboss Enterprise Application Platform Version 7.0
Redhat ≫ Jboss Fuse Version 6.0.0
Redhat ≫ Jboss Fuse Version 7.0.0
Redhat ≫ Jboss Fuse Service Works Version 6.0
Redhat ≫ Jboss Operations Network Version 3.0
Redhat ≫ Jboss Web Server Version 3.0
Redhat ≫ Openshift Application Runtimes Version -
Redhat ≫ Openshift Container Platform Version 4.6
Redhat ≫ Openshift Container Platform Version 4.7
Redhat ≫ Openshift Container Platform Version 4.8
Redhat ≫ Process Automation Version 7.0
Redhat ≫ Single Sign-on Version 7.0
Redhat ≫ Software Collections Version -
Redhat ≫ Enterprise Linux Version 6.0
Redhat ≫ Enterprise Linux Version 7.0
Redhat ≫ Enterprise Linux Version 8.0
Oracle ≫ Advanced Supply Chain Planning Version 12.1
Oracle ≫ Advanced Supply Chain Planning Version 12.2
Oracle ≫ Business Intelligence Version 5.9.0.0.0 SwEdition enterprise
Oracle ≫ Business Intelligence Version 12.2.1.3.0 SwEdition enterprise
Oracle ≫ Business Intelligence Version 12.2.1.4.0 SwEdition enterprise
Oracle ≫ Business Process Management Suite Version 12.2.1.3.0
Oracle ≫ Business Process Management Suite Version 12.2.1.4.0
Oracle ≫ Communications Eagle Ftp Table Base Retrieval Version 4.5
Oracle ≫ Communications Messaging Server Version 8.1
Oracle ≫ Communications Network Integrity Version 7.3.6
Oracle ≫ Communications Offline Mediation Controller Version < 12.0.0.4.0
Oracle ≫ Communications Offline Mediation Controller Version 12.0.0.5.0
Oracle ≫ Communications Unified Inventory Management Version 7.3.4
Oracle ≫ Communications Unified Inventory Management Version 7.3.5
Oracle ≫ Communications Unified Inventory Management Version 7.4.1
Oracle ≫ Communications Unified Inventory Management Version 7.4.2
Oracle ≫ E-business Suite Cloud Manager And Cloud Backup Module Version 2.2.1.1.1
Oracle ≫ Enterprise Manager Base Platform Version 13.4.0.0
Oracle ≫ Enterprise Manager Base Platform Version 13.5.0.0
Oracle ≫ Financial Services Revenue Management And Billing Analytics Version 2.7.0.0
Oracle ≫ Financial Services Revenue Management And Billing Analytics Version 2.7.0.1
Oracle ≫ Financial Services Revenue Management And Billing Analytics Version 2.8.0.0
Oracle ≫ Fusion Middleware Common Libraries And Tools Version 12.2.1.4.0
Oracle ≫ Goldengate Version -
Oracle ≫ Healthcare Data Repository Version 8.1.0
Oracle ≫ Hyperion Data Relationship Management Version < 11.2.8.0
Oracle ≫ Hyperion Infrastructure Technology Version < 11.2.8.0
Oracle ≫ Identity Management Suite Version 12.2.1.3.0
Oracle ≫ Identity Management Suite Version 12.2.1.4.0
Oracle ≫ Jdeveloper Version 12.2.1.3.0
Oracle ≫ Mysql Enterprise Monitor Version <= 8.0.29
Oracle ≫ Retail Allocation Version 14.1.3.2
Oracle ≫ Retail Allocation Version 15.0.3.1
Oracle ≫ Retail Allocation Version 16.0.3
Oracle ≫ Retail Allocation Version 19.0.1
Oracle ≫ Retail Extract Transform And Load Version 13.2.5
Oracle ≫ Stream Analytics Version -
Oracle ≫ Timesten Grid Version -
Oracle ≫ Utilities Testing Accelerator Version 6.0.0.1.1
Oracle ≫ Utilities Testing Accelerator Version 6.0.0.2.2
Oracle ≫ Utilities Testing Accelerator Version 6.0.0.3.1
Oracle ≫ Weblogic Server Version 12.2.1.3.0
Oracle ≫ Weblogic Server Version 12.2.1.4.0
Oracle ≫ Weblogic Server Version 14.1.1.0.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 81.15% | 0.996 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 1.6 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 6 | 6.8 | 6.4 |
AV:N/AC:M/Au:S/C:P/I:P/A:P
|
| CISA-ADP | 7.5 | 1.6 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-502 Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
https://www.oracle.com/security-alerts/cpuapr2022.html
https://www.oracle.com/security-alerts/cpujan2022.html
https://www.oracle.com/security-alerts/cpujul2022.html
https://security.gentoo.org/glsa/202209-02
https://www.kb.cert.org/vuls/id/930724
http://www.openwall.com/lists/oss-security/2022/01/18/3
https://access.redhat.com/security/cve/CVE-2021-4104
https://github.com/apache/logging-log4j2/pull/608#issuecomment-990494126
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0033
https://security.gentoo.org/glsa/202310-16
https://security.gentoo.org/glsa/202312-02
https://security.gentoo.org/glsa/202312-04
https://security.netapp.com/advisory/ntap-20211223-0007/
https://www.cve.org/CVERecord?id=CVE-2021-44228