8.5

CVE-2021-44832

Warnung

Apache Log4j2 vulnerable to RCE via JDBC Appender when attacker controls configuration

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Log4j Version >= 2.0.1 < 2.3.2
Apache ≫ Log4j Version >= 2.4 < 2.12.4
Apache ≫ Log4j Version >= 2.13.0 < 2.17.1
Apache ≫ Log4j Version 2.0 Update -
Apache ≫ Log4j Version 2.0 Update beta7
Apache ≫ Log4j Version 2.0 Update beta8
Apache ≫ Log4j Version 2.0 Update beta9
Apache ≫ Log4j Version 2.0 Update rc1
Apache ≫ Log4j Version 2.0 Update rc2
Oracle ≫ Communications Diameter Signaling Router Version >= 8.0.0.0 <= 8.5.1.0
Oracle ≫ Primavera Gateway Version >= 17.12.0 <= 17.12.11
Oracle ≫ Primavera Gateway Version >= 18.8.0 <= 18.8.13
Oracle ≫ Primavera Gateway Version >= 19.12.0 <= 19.12.12
Oracle ≫ Primavera Gateway Version >= 20.12.0 <= 20.12.7
Oracle ≫ Primavera Gateway Version 21.12.0
Oracle ≫ Primavera P6 Enterprise Project Portfolio Management Version >= 19.12.0 <= 19.12.18.0
Oracle ≫ Primavera P6 Enterprise Project Portfolio Management Version >= 20.12.0.0 <= 20.12.12.0
Oracle ≫ Primavera Unifier Version 18.8
Oracle ≫ Primavera Unifier Version 19.12
Oracle ≫ Primavera Unifier Version 20.12
Oracle ≫ Primavera Unifier Version 21.12
Oracle ≫ Retail Assortment Planning Version 16.0.3
Oracle ≫ Retail Fiscal Management Version 14.2
Oracle ≫ Siebel Ui Framework Version 21.12
Oracle ≫ Weblogic Server Version 12.2.1.3.0
Oracle ≫ Weblogic Server Version 12.2.1.4.0
Oracle ≫ Weblogic Server Version 14.1.1.0.0
Cisco ≫ Cloudcenter Version 4.10.0.16
Fedoraproject ≫ Fedora Version 34
Fedoraproject ≫ Fedora Version 35
Debian ≫ Debian Linux Version 9.0
Oracle ≫ Communications Diameter Signaling Router Version >= 8.3.0.0 <= 8.5.1.0
Oracle ≫ Flexcube Private Banking Version 12.1.0
Oracle ≫ Policy Automation Version >= 12.2.0 <= 12.2.24
Oracle ≫ Policy Automation For Mobile Devices Version >= 12.2.0 <= 12.2.24
Oracle ≫ Primavera Gateway Version >= 17.12.0 <= 17.12.11
Oracle ≫ Primavera Gateway Version >= 18.8.0 <= 18.8.13
Oracle ≫ Primavera Gateway Version >= 19.12.0 <= 19.12.12
Oracle ≫ Primavera Gateway Version >= 20.12.0 <= 20.12.7
Oracle ≫ Primavera Gateway Version 21.12.0
Oracle ≫ Primavera P6 Enterprise Project Portfolio Management Version >= 19.12.0.0 <= 19.12.18.0
Oracle ≫ Primavera P6 Enterprise Project Portfolio Management Version >= 20.12.0.0 <= 20.12.12.0
Oracle ≫ Primavera Unifier Version 18.8
Oracle ≫ Primavera Unifier Version 19.12
Oracle ≫ Primavera Unifier Version 20.12
Oracle ≫ Primavera Unifier Version 21.12
Oracle ≫ Retail Order Broker Version 18.0
Oracle ≫ Retail Order Broker Version 19.1
Oracle ≫ Siebel Ui Framework Version <= 21.12
Oracle ≫ Weblogic Server Version 12.2.1.3.0
Oracle ≫ Weblogic Server Version 12.2.1.4.0
Oracle ≫ Weblogic Server Version 14.1.1.0.0
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 97.91% 0.999
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.6 0.7 5.9
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
NIST 8.5 6.8 10
AV:N/AC:M/Au:S/C:C/I:C/A:C
CISA-ADP 6.6 0.7 5.9
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

https://www.oracle.com/security-alerts/cpuapr2022.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpujan2022.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpujul2022.html
Patch
Third Party Advisory
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd
Third Party Advisory
http://www.openwall.com/lists/oss-security/2021/12/28/1
Third Party Advisory
Mailing List
https://cert-portal.siemens.com/productcert/pdf/ssa-784507.pdf
Third Party Advisory
https://issues.apache.org/jira/browse/LOG4J2-3293
Patch
Vendor Advisory
Issue Tracking
https://lists.apache.org/thread/s1o5vlo78ypqxnzn6p8zf6t9shtq5143
Vendor Advisory
Mailing List
https://lists.debian.org/debian-lts-announce/2021/12/msg00036.html
Third Party Advisory
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EVV25FXL4FU5X6X5BSL7RLQ7T6F65MRA/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T57MPJUW3MA6QGWZRTMCHHMMPQNVKGFC/
https://security.netapp.com/advisory/ntap-20220104-0001/
Third Party Advisory