9

CVE-2021-45046

Warnung

Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack

It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in an information leak and remote code execution in some environments and local code execution in all environments. Log4j 2.16.0 (Java 8) and 2.12.2 (Java 7) fix this issue by removing support for message lookup patterns and disabling JNDI functionality by default.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Log4j Version >= 2.0.1 < 2.12.2
Apache ≫ Log4j Version >= 2.13.0 < 2.16.0
Apache ≫ Log4j Version 2.0 Update -
Apache ≫ Log4j Version 2.0 Update beta9
Apache ≫ Log4j Version 2.0 Update rc1
Apache ≫ Log4j Version 2.0 Update rc2
Intel ≫ Datacenter Manager Version -
Intel ≫ Oneapi Version - SwPlatform eclipse
Intel ≫ System Debugger Version -
Intel ≫ System Studio Version -
Siemens ≫ Captial Version < 2019.1
Siemens ≫ Captial Version 2019.1 Update -
Siemens ≫ Captial Version 2019.1 Update sp1912
Siemens ≫ Desigo Cc Info Center Version 5.0
Siemens ≫ Desigo Cc Info Center Version 5.1
Siemens ≫ E-car Operation Center Version < 2021-12-13
Siemens ≫ Energy Engage Version 3.1
Siemens ≫ Energyip Version 8.5
Siemens ≫ Energyip Version 8.6
Siemens ≫ Energyip Version 8.7
Siemens ≫ Energyip Version 9.0
Siemens ≫ Energyip Prepay Version 3.7
Siemens ≫ Energyip Prepay Version 3.8
Siemens ≫ Gma-manager Version < 8.6.2j-398
Siemens ≫ Industrial Edge Management Hub Version < 2021-12-13
Siemens ≫ Mindsphere Version < 2021-12-11
Siemens ≫ Navigator Version < 2021-12-13
Siemens ≫ Nx
Siemens ≫ Opcenter Intelligence Version <= 3.2
Siemens ≫ Operation Scheduler Version <= 1.1.3
Siemens ≫ Sentron Powermanager Version 4.1
Siemens ≫ Sentron Powermanager Version 4.2
Siemens ≫ Siguard Dsa Version 4.2
Siemens ≫ Siguard Dsa Version 4.3
Siemens ≫ Siguard Dsa Version 4.4
Siemens ≫ Sipass Integrated Version 2.80
Siemens ≫ Sipass Integrated Version 2.85
Siemens ≫ Siveillance Command Version <= 4.16.2.1
Siemens ≫ Siveillance Identity Version 1.5
Siemens ≫ Siveillance Identity Version 1.6
Siemens ≫ Solid Edge Harness Design Version 2020 Update -
Siemens ≫ Solid Edge Harness Design Version 2020 Update sp2002
Siemens ≫ Spectrum Power 4 Version < 4.70
Siemens ≫ Spectrum Power 4 Version 4.70 Update -
Siemens ≫ Spectrum Power 4 Version 4.70 Update sp7
Siemens ≫ Spectrum Power 4 Version 4.70 Update sp8
Siemens ≫ Spectrum Power 7 Version < 2.30
Siemens ≫ Spectrum Power 7 Version 2.30
Siemens ≫ Spectrum Power 7 Version 2.30 Update -
Siemens ≫ Spectrum Power 7 Version 2.30 Update sp2
Siemens ≫ Vesys Version < 2019.1
Siemens ≫ Vesys Version 2019.1
Siemens ≫ Vesys Version 2019.1 Update -
Siemens ≫ Vesys Version 2019.1 Update sp1912
Debian ≫ Debian Linux Version 10.0
Debian ≫ Debian Linux Version 11.0
Sonicwall ≫ Email Security Version < 10.0.12
Fedoraproject ≫ Fedora Version 34
Fedoraproject ≫ Fedora Version 35
Siemens ≫ 6bk1602-0aa12-0tp0 Firmware Version < 2.7.0
   Siemens ≫ 6bk1602-0aa12-0tp0 Version -
Siemens ≫ 6bk1602-0aa22-0tp0 Firmware Version < 2.7.0
   Siemens ≫ 6bk1602-0aa22-0tp0 Version -
Siemens ≫ 6bk1602-0aa32-0tp0 Firmware Version < 2.7.0
   Siemens ≫ 6bk1602-0aa32-0tp0 Version -
Siemens ≫ 6bk1602-0aa42-0tp0 Firmware Version < 2.7.0
   Siemens ≫ 6bk1602-0aa42-0tp0 Version -
Siemens ≫ 6bk1602-0aa52-0tp0 Firmware Version < 2.7.0
   Siemens ≫ 6bk1602-0aa52-0tp0 Version -

01.05.2023: CISA Known Exploited Vulnerabilities (KEV) Catalog

Apache Log4j2 Deserialization of Untrusted Data Vulnerability

Schwachstelle

Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 99.98% 1
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9 2.2 6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
NIST 5.1 4.9 6.4
AV:N/AC:H/Au:N/C:P/I:P/A:P
CISA-ADP 9 2.2 6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE-917 Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')

The product constructs all or part of an expression language (EL) statement in a framework such as a Java Server Page (JSP) using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended EL statement before it is executed.

https://www.oracle.com/security-alerts/cpuapr2022.html
Third Party Advisory
https://www.oracle.com/security-alerts/cpujan2022.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpujul2022.html
Third Party Advisory
http://www.openwall.com/lists/oss-security/2021/12/14/4
Third Party Advisory
Mailing List
Mitigation
http://www.openwall.com/lists/oss-security/2021/12/15/3
Third Party Advisory
Mailing List
https://cert-portal.siemens.com/productcert/pdf/ssa-397453.pdf
Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-479842.pdf
Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-661247.pdf
Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-714170.pdf
Third Party Advisory
https://logging.apache.org/log4j/2.x/security.html
Vendor Advisory
Release Notes
Mitigation
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0032
Third Party Advisory
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd
Third Party Advisory
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00646.html
Third Party Advisory
https://www.kb.cert.org/vuls/id/930724
Third Party Advisory
US Government Resource
https://www.oracle.com/security-alerts/alert-cve-2021-44228.html
Third Party Advisory
https://security.gentoo.org/glsa/202310-16
Third Party Advisory
https://www.cve.org/CVERecord?id=CVE-2021-44228
Not Applicable
http://www.openwall.com/lists/oss-security/2021/12/18/1
Third Party Advisory
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EOKPQGV24RRBBI4TBZUDQMM4MEH7MXCY/
Mailing List
Release Notes
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SIG7FZULMNK2XF6FZRU4VWYDQXNMUGAJ/
Mailing List
Release Notes
https://www.debian.org/security/2021/dsa-5022
Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-45046
US Government Resource