V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2021-44228
DEB
Critical KEVConfirmedExploit available

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log mes…

CVSS
9.8
Critical
EPSS
0.94
p99
Published
2021-01-01
Updated
2021-12-10
Description

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.

Tags · CWE
KEVPre-auth
CWE-20
CAPEC-3
CAPEC-7
CAPEC-8
CAPEC-9
CAPEC-10
CAPEC-13
CAPEC-14
CAPEC-22
CAPEC-23
CAPEC-24
CAPEC-28
CAPEC-31
CAPEC-42
CAPEC-43
CAPEC-45
CAPEC-46
CAPEC-47
CAPEC-52
CAPEC-53
CAPEC-63
CAPEC-64
CAPEC-67
CAPEC-71
CAPEC-72
CAPEC-73
CAPEC-78
CAPEC-79
CAPEC-80
CAPEC-81
CAPEC-83
CAPEC-85
CAPEC-88
CAPEC-101
CAPEC-104
CAPEC-108
CAPEC-109
CAPEC-110
CAPEC-120
CAPEC-135
CAPEC-136
CAPEC-153
CAPEC-182
CAPEC-209
CAPEC-230
CAPEC-231
CAPEC-250
CAPEC-261
CAPEC-267
CAPEC-473
CAPEC-588
CAPEC-664
Affected products
Active_iq_unified_managerBrocade_san_navigatorCloud_insightsCloud_managerCloud_secure_agentOncommand_insightOntap_toolsSnapcenterSolidfire_\&_hci_storage_nodeSolidfire_enterprise_sds
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2021-01-01
Published
2021-12-10
Added to KEV
2021-12-10
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.944 · p99
Known exploited (KEV)
Yes
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-267 · CWE-20
└ via CAPEC-473 · CWE-20
└ via CAPEC-31 · CWE-20
└ via CAPEC-473 · CWE-20
└ via CAPEC-13 · CWE-20
Known exploits — Сканер-ВС
CVE-2021-44228
cisa · https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Enterprise
50590
exploitdb · https://www.exploit-db.com/exploits/50590
Enterprise
50592
exploitdb · https://www.exploit-db.com/exploits/50592
Enterprise
51183
exploitdb · https://www.exploit-db.com/exploits/51183
Enterprise
Affected software
ProductVendorStatus
apache-log4j1.2Exploited
apache-log4j2Exploited
apache-log4j2Exploited
apache-log4j2Exploited
apache-log4j2Exploited
apache-log4j2Exploited
apache-log4j2Exploited
apache-log4j2Exploited
apache-log4j2Exploited
6bk1602-0aa12-0tp0_firmware*Exploited
6bk1602-0aa22-0tp0_firmware*Exploited
6bk1602-0aa32-0tp0_firmware*Exploited
6bk1602-0aa42-0tp0_firmware*Exploited
6bk1602-0aa52-0tp0_firmware*Exploited
active_iq_unified_manager*Exploited
advanced_malware_protection_virtual_private_cloud_appliance*Exploited
automated_subsea_tuning*Exploited
automated_subsea_tuning*Exploited
broadworks*Exploited
broadworks*Exploited
Source databases
DEB
CVE
UBU
Related vulnerabilities