5.9

CVE-2021-45105

Warning

Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.

Data is provided by the National Vulnerability Database (NVD)
ApacheLog4j Version >= 2.0 < 2.3.1
ApacheLog4j Version >= 2.4 < 2.12.3
ApacheLog4j Version >= 2.13.0 <= 2.16.0
NetappCloud Manager Version-
DebianDebian Linux Version10.0
DebianDebian Linux Version11.0
SonicwallEmail Security Version <= 10.0.12
SonicwallNetwork Security Manager SwEditionon-premises Version >= 2.0 < 3.0
SonicwallNetwork Security Manager SwEditionsaas Version >= 2.0 < 3.0
SonicwallWeb Application Firewall Version >= 3.0.0 < 3.1.0
Sonicwall6bk1602-0aa12-0tp0 Firmware Version < 2.7.0
   Sonicwall6bk1602-0aa12-0tp0 Version-
Sonicwall6bk1602-0aa22-0tp0 Firmware Version < 2.7.0
   Sonicwall6bk1602-0aa22-0tp0 Version-
Sonicwall6bk1602-0aa32-0tp0 Firmware Version < 2.7.0
   Sonicwall6bk1602-0aa32-0tp0 Version-
Sonicwall6bk1602-0aa42-0tp0 Firmware Version < 2.7.0
   Sonicwall6bk1602-0aa42-0tp0 Version-
Sonicwall6bk1602-0aa52-0tp0 Firmware Version < 2.7.0
   Sonicwall6bk1602-0aa52-0tp0 Version-
OracleAgile Plm Version9.3.6
OracleBanking Loans Servicing Version2.12.0
OracleBanking Party Management Version2.7.0
OracleBanking Payments Version14.5
OracleBanking Platform Version2.6.2
OracleBanking Platform Version2.7.1
OracleBanking Platform Version2.12.0
OracleBanking Trade Finance Version14.5
OracleBusiness Intelligence Version5.5.0.0.0 SwEditionenterprise
OracleCommunications Asap Version7.3
OracleCommunications Convergence Version3.0.2.2.0
OracleCommunications Convergence Version3.0.3.0
OracleCommunications Convergent Charging Controller Version >= 12.0.1.0.0 <= 12.0.4.0.0
OracleCommunications Diameter Signaling Router Version >= 8.3.0.0 <= 8.5.1.0
OracleCommunications Network Charging And Control Version >= 12.0.1.0.0 <= 12.0.4.0.0
OracleData Integrator Version12.2.1.3.0
OracleData Integrator Version12.2.1.4.0
OracleE-business Suite Version12.2
OracleFlexcube Universal Banking Version >= 12.1.0 <= 12.4
OracleFlexcube Universal Banking Version >= 14.0.0 <= 14.3.0
OracleFlexcube Universal Banking Version11.83.3
OracleHealth Sciences Inform Version6.2.1.1
OracleHealth Sciences Inform Version6.3.2.1
OracleHealth Sciences Inform Version7.0.0.0
OracleHealth Sciences Information Manager Version >= 3.0.1 <= 3.0.4
OracleHealthcare Foundation Version >= 7.3.0.1 <= 7.3.0.4
OracleHospitality Suite8 Version8.13.0
OracleHospitality Suite8 Version8.14.0
OracleHyperion Bi+ Version < 11.2.8.0
OracleHyperion Planning Version < 11.2.8.0
OracleHyperion Tax Provision Version < 11.2.8.0
OracleIdentity Management Suite Version12.2.1.3.0
OracleIdentity Management Suite Version12.2.1.4.0
OracleInsurance Data Gateway Version1.0.1
OracleJdeveloper Version12.2.1.4.0
OracleManaged File Transfer Version12.2.1.3.0
OracleManaged File Transfer Version12.2.1.4.0
OracleManagement Cloud Engine Version1.5.0
OracleMysql Enterprise Monitor Version <= 8.0.29
OraclePayment Interface Version19.1
OraclePayment Interface Version20.3
OraclePrimavera Gateway Version >= 17.12.0 <= 17.12.11
OraclePrimavera Gateway Version >= 18.8.0 <= 18.8.13
OraclePrimavera Gateway Version >= 19.12.0 <= 19.12.12
OraclePrimavera Gateway Version >= 20.12.0 <= 20.12.7
OraclePrimavera Gateway Version21.12.0
OraclePrimavera P6 Enterprise Project Portfolio Management Version >= 19.12.0.0 <= 19.12.18.0
OraclePrimavera P6 Enterprise Project Portfolio Management Version >= 20.12.0.0 <= 20.12.12.0
OraclePrimavera Unifier Version18.8
OraclePrimavera Unifier Version19.12
OraclePrimavera Unifier Version20.12
OraclePrimavera Unifier Version21.12
OracleRetail Back Office Version14.1
OracleRetail Central Office Version14.1
OracleRetail Customer Insights Version15.0.2
OracleRetail Customer Insights Version16.0.2
OracleRetail Eftlink Version16.0.3
OracleRetail Eftlink Version17.0.2
OracleRetail Eftlink Version18.0.1
OracleRetail Eftlink Version19.0.1
OracleRetail Eftlink Version20.0.1
OracleRetail Eftlink Version21.0.0
OracleRetail Financial Integration Version >= 16.0.1 <= 16.0.3
OracleRetail Financial Integration Version14.1.3.2
OracleRetail Financial Integration Version15.0.3.1
OracleRetail Integration Bus Version >= 16.0.1 <= 16.0.3
OracleRetail Integration Bus Version >= 19.0.0 <= 19.0.1.0
OracleRetail Integration Bus Version14.1.3
OracleRetail Integration Bus Version14.1.3.2
OracleRetail Integration Bus Version15.0.3.1
OracleRetail Integration Bus Version19.0.0
OracleRetail Integration Bus Version19.0.1
OracleRetail Invoice Matching Version15.0.3
OracleRetail Invoice Matching Version16.0.3
OracleRetail Order Broker Version16.0
OracleRetail Order Broker Version18.0
OracleRetail Order Broker Version19.1
OracleRetail Price Management Version14.0.4
OracleRetail Price Management Version14.1.3.0
OracleRetail Price Management Version15.0.3.0
OracleRetail Price Management Version16.0.3.0
OracleRetail Service Backbone Version >= 16.0.1 <= 16.0.3
OracleRetail Service Backbone Version14.1.3
OracleRetail Service Backbone Version14.1.3.2
OracleRetail Service Backbone Version15.0.3.1
OracleRetail Service Backbone Version19.0.0
OracleRetail Service Backbone Version19.0.1
OracleRetail Service Backbone Version19.0.1.0
OracleSiebel Ui Framework Version <= 21.12
OracleSql Developer Version < 21.4.2
OracleTaleo Platform Version < 22.1
OracleUtilities Framework Version >= 4.3.0.1.0 <= 4.3.0.6.0
OracleUtilities Framework Version4.4.0.0.0
OracleUtilities Framework Version4.4.0.2.0
OracleUtilities Framework Version4.4.0.3.0
OracleWebcenter Portal Version12.2.1.3.0
OracleWebcenter Portal Version12.2.1.4.0
OracleWebcenter Sites Version12.2.1.3.0
OracleWebcenter Sites Version12.2.1.4.0
OracleWeblogic Server Version12.2.1.3.0
OracleWeblogic Server Version12.2.1.4.0
OracleWeblogic Server Version14.1.1.0.0
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 65.66% 0.984
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.9 2.2 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

CWE-674 Uncontrolled Recursion

The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.