8.5

CVE-2021-44832

Warning

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.

Data is provided by the National Vulnerability Database (NVD)
ApacheLog4j Version >= 2.0.1 < 2.3.2
ApacheLog4j Version >= 2.4 < 2.12.4
ApacheLog4j Version >= 2.13.0 < 2.17.1
ApacheLog4j Version2.0 Update-
ApacheLog4j Version2.0 Updatebeta7
ApacheLog4j Version2.0 Updatebeta8
ApacheLog4j Version2.0 Updatebeta9
ApacheLog4j Version2.0 Updaterc1
ApacheLog4j Version2.0 Updaterc2
OracleCommunications Diameter Signaling Router Version >= 8.0.0.0 <= 8.5.1.0
OraclePrimavera Gateway Version >= 17.12.0 <= 17.12.11
OraclePrimavera Gateway Version >= 18.8.0 <= 18.8.13
OraclePrimavera Gateway Version >= 19.12.0 <= 19.12.12
OraclePrimavera Gateway Version >= 20.12.0 <= 20.12.7
OraclePrimavera Gateway Version21.12.0
OraclePrimavera P6 Enterprise Project Portfolio Management Version >= 19.12.0 <= 19.12.18.0
OraclePrimavera P6 Enterprise Project Portfolio Management Version >= 20.12.0.0 <= 20.12.12.0
OraclePrimavera Unifier Version18.8
OraclePrimavera Unifier Version19.12
OraclePrimavera Unifier Version20.12
OraclePrimavera Unifier Version21.12
OracleSiebel Ui Framework Version21.12
OracleWeblogic Server Version12.2.1.3.0
OracleWeblogic Server Version12.2.1.4.0
OracleWeblogic Server Version14.1.1.0.0
CiscoCloudcenter Version4.10.0.16
FedoraprojectFedora Version34
FedoraprojectFedora Version35
DebianDebian Linux Version9.0
OracleCommunications Diameter Signaling Router Version >= 8.3.0.0 <= 8.5.1.0
OracleFlexcube Private Banking Version12.1.0
OraclePolicy Automation Version >= 12.2.0 <= 12.2.24
OraclePolicy Automation For Mobile Devices Version >= 12.2.0 <= 12.2.24
OraclePrimavera Gateway Version >= 17.12.0 <= 17.12.11
OraclePrimavera Gateway Version >= 18.8.0 <= 18.8.13
OraclePrimavera Gateway Version >= 19.12.0 <= 19.12.12
OraclePrimavera Gateway Version >= 20.12.0 <= 20.12.7
OraclePrimavera Gateway Version21.12.0
OraclePrimavera P6 Enterprise Project Portfolio Management Version >= 19.12.0.0 <= 19.12.18.0
OraclePrimavera P6 Enterprise Project Portfolio Management Version >= 20.12.0.0 <= 20.12.12.0
OraclePrimavera Unifier Version18.8
OraclePrimavera Unifier Version19.12
OraclePrimavera Unifier Version20.12
OraclePrimavera Unifier Version21.12
OracleRetail Order Broker Version18.0
OracleRetail Order Broker Version19.1
OracleSiebel Ui Framework Version <= 21.12
OracleWeblogic Server Version12.2.1.3.0
OracleWeblogic Server Version12.2.1.4.0
OracleWeblogic Server Version14.1.1.0.0
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 53.59% 0.979
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.6 0.7 5.9
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 8.5 6.8 10
AV:N/AC:M/Au:S/C:C/I:C/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.