7.5

CVE-2021-4104

JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-44228. Note this issue only affects Log4j 1.2 when specifically configured to use JMSAppender, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ApacheLog4j Version1.2
FedoraprojectFedora Version35
RedhatCodeready Studio Version12.0
RedhatJboss A-mq Version6.0.0
RedhatJboss A-mq Version7
RedhatJboss Data Grid Version7.0.0
RedhatJboss Fuse Version6.0.0
RedhatJboss Fuse Version7.0.0
RedhatJboss Web Server Version3.0
RedhatProcess Automation Version7.0
RedhatSingle Sign-on Version7.0
RedhatEnterprise Linux Version6.0
RedhatEnterprise Linux Version7.0
RedhatEnterprise Linux Version8.0
OracleBusiness Intelligence Version5.9.0.0.0 SwEditionenterprise
OracleBusiness Intelligence Version12.2.1.3.0 SwEditionenterprise
OracleBusiness Intelligence Version12.2.1.4.0 SwEditionenterprise
OracleGoldengate Version-
OracleIdentity Management Suite Version12.2.1.3.0
OracleIdentity Management Suite Version12.2.1.4.0
OracleJdeveloper Version12.2.1.3.0
OracleMysql Enterprise Monitor Version <= 8.0.29
OracleRetail Allocation Version14.1.3.2
OracleRetail Allocation Version15.0.3.1
OracleRetail Allocation Version16.0.3
OracleRetail Allocation Version19.0.1
OracleStream Analytics Version-
OracleTimesten Grid Version-
OracleTuxedo Version12.2.2.0.0
OracleUtilities Testing Accelerator Version6.0.0.1.1
OracleUtilities Testing Accelerator Version6.0.0.2.2
OracleUtilities Testing Accelerator Version6.0.0.3.1
OracleWeblogic Server Version12.2.1.3.0
OracleWeblogic Server Version12.2.1.4.0
OracleWeblogic Server Version14.1.1.0.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 72.2% 0.987
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 1.6 5.9
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6 6.8 6.4
AV:N/AC:M/Au:S/C:P/I:P/A:P
CWE-502 Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.