Metrics
No CVSS v4.0
Attack Vector Network
Attack Complexity High
Privileges Required None
Scope Unchanged
Confidentiality Impact None
Integrity Impact None
Availability Impact High
User Interaction None
No CVSS v3.0
Access Vector Network
Access Complexity Medium
Authentication None
Confidentiality Impact None
Integrity Impact None
Availability Impact Partial
This CVE is not in the KEV list.
The EPSS score is 0.72106.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
| Vendors | Products |
|---|---|
|
Apache
Subscribe
|
Log4j
Subscribe
|
|
Debian
Subscribe
|
Debian Linux
Subscribe
|
|
Netapp
Subscribe
|
Cloud Manager
Subscribe
|
|
Oracle
Subscribe
|
Agile Engineering Data Management
Subscribe
Agile Plm
Subscribe
Agile Plm Mcad Connector
Subscribe
Autovue For Agile Product Lifecycle Management
Subscribe
Banking Deposits And Lines Of Credit Servicing
Subscribe
Banking Enterprise Default Management
Subscribe
Banking Loans Servicing
Subscribe
Banking Party Management
Subscribe
Banking Payments
Subscribe
Banking Platform
Subscribe
Banking Trade Finance
Subscribe
Banking Treasury Management
Subscribe
Business Intelligence
Subscribe
Communications Asap
Subscribe
Communications Billing And Revenue Management
Subscribe
Communications Cloud Native Core Console
Subscribe
Communications Cloud Native Core Network Function Cloud Native Environment
Subscribe
Communications Cloud Native Core Network Repository Function
Subscribe
Communications Cloud Native Core Network Slice Selection Function
Subscribe
Communications Cloud Native Core Policy
Subscribe
Communications Cloud Native Core Security Edge Protection Proxy
Subscribe
Communications Cloud Native Core Service Communication Proxy
Subscribe
Communications Cloud Native Core Unified Data Repository
Subscribe
Communications Convergence
Subscribe
Communications Convergent Charging Controller
Subscribe
Communications Diameter Signaling Router
Subscribe
Communications Eagle Element Management System
Subscribe
Communications Eagle Ftp Table Base Retrieval
Subscribe
Communications Element Manager
Subscribe
Communications Evolved Communications Application Server
Subscribe
Communications Interactive Session Recorder
Subscribe
Communications Ip Service Activator
Subscribe
Communications Messaging Server
Subscribe
Communications Network Charging And Control
Subscribe
Communications Network Integrity
Subscribe
Communications Performance Intelligence Center
Subscribe
Communications Pricing Design Center
Subscribe
Communications Service Broker
Subscribe
Communications Services Gatekeeper
Subscribe
Communications Session Report Manager
Subscribe
Communications Session Route Manager
Subscribe
Communications Unified Inventory Management
Subscribe
Communications User Data Repository
Subscribe
Communications Webrtc Session Controller
Subscribe
Data Integrator
Subscribe
E-business Suite
Subscribe
Enterprise Manager Base Platform
Subscribe
Enterprise Manager For Peoplesoft
Subscribe
Enterprise Manager Ops Center
Subscribe
Financial Services Analytical Applications Infrastructure
Subscribe
Financial Services Model Management And Governance
Subscribe
Flexcube Universal Banking
Subscribe
Health Sciences Empirica Signal
Subscribe
Health Sciences Inform
Subscribe
Health Sciences Information Manager
Subscribe
Healthcare Data Repository
Subscribe
Healthcare Foundation
Subscribe
Healthcare Master Person Index
Subscribe
Healthcare Translational Research
Subscribe
Hospitality Suite8
Subscribe
Hospitality Token Proxy Service
Subscribe
Hyperion Bi\+
Subscribe
Hyperion Data Relationship Management
Subscribe
Hyperion Infrastructure Technology
Subscribe
Hyperion Planning
Subscribe
Hyperion Profitability And Cost Management
Subscribe
Hyperion Tax Provision
Subscribe
Identity Management Suite
Subscribe
Identity Manager Connector
Subscribe
Instantis Enterprisetrack
Subscribe
Insurance Data Gateway
Subscribe
Insurance Insbridge Rating And Underwriting
Subscribe
Jdeveloper
Subscribe
Managed File Transfer
Subscribe
Management Cloud Engine
Subscribe
Mysql Enterprise Monitor
Subscribe
Payment Interface
Subscribe
Peoplesoft Enterprise Peopletools
Subscribe
Primavera Gateway
Subscribe
Primavera P6 Enterprise Project Portfolio Management
Subscribe
Primavera Unifier
Subscribe
Retail Back Office
Subscribe
Retail Central Office
Subscribe
Retail Customer Insights
Subscribe
Retail Data Extractor For Merchandising
Subscribe
Retail Eftlink
Subscribe
Retail Financial Integration
Subscribe
Retail Integration Bus
Subscribe
Retail Invoice Matching
Subscribe
Retail Merchandising System
Subscribe
Retail Order Broker
Subscribe
Retail Order Management System
Subscribe
Retail Point-of-service
Subscribe
Retail Predictive Application Server
Subscribe
Retail Price Management
Subscribe
Retail Returns Management
Subscribe
Retail Service Backbone
Subscribe
Retail Store Inventory Management
Subscribe
Siebel Ui Framework
Subscribe
Sql Developer
Subscribe
Taleo Platform
Subscribe
Utilities Framework
Subscribe
Webcenter Portal
Subscribe
Webcenter Sites
Subscribe
Weblogic Server
Subscribe
|
|
Redhat
Subscribe
|
|
|
Sonicwall
Subscribe
|
6bk1602-0aa12-0tp0
Subscribe
6bk1602-0aa12-0tp0 Firmware
Subscribe
6bk1602-0aa22-0tp0
Subscribe
6bk1602-0aa22-0tp0 Firmware
Subscribe
6bk1602-0aa32-0tp0
Subscribe
6bk1602-0aa32-0tp0 Firmware
Subscribe
6bk1602-0aa42-0tp0
Subscribe
6bk1602-0aa42-0tp0 Firmware
Subscribe
6bk1602-0aa52-0tp0
Subscribe
6bk1602-0aa52-0tp0 Firmware
Subscribe
Email Security
Subscribe
Network Security Manager
Subscribe
Web Application Firewall
Subscribe
|
Configuration 1 [-]
|
Configuration 2 [-]
|
Configuration 3 [-]
|
Configuration 4 [-]
|
Configuration 5 [-]
| AND |
|
Configuration 6 [-]
| AND |
|
Configuration 7 [-]
| AND |
|
Configuration 8 [-]
| AND |
|
Configuration 9 [-]
| AND |
|
Configuration 10 [-]
|
| Package | CPE | Advisory | Released Date |
|---|---|---|---|
| EAP 7.4.4 release | |||
| log4j-core | cpe:/a:redhat:jboss_enterprise_application_platform:7.4 | RHSA-2022:1299 | 2022-04-11T00:00:00Z |
| EAP 7.4 log4j async | |||
| log4j-core | cpe:/a:redhat:jboss_enterprise_application_platform:7.4 | RHSA-2022:0216 | 2022-01-20T00:00:00Z |
| OpenShift Logging 5.0 | |||
| openshift-logging/elasticsearch6-rhel8:v5.0.11-2 | cpe:/a:redhat:logging:5.0::el8 | RHSA-2022:0047 | 2022-01-10T00:00:00Z |
| OpenShift Logging 5.1 | |||
| openshift-logging/elasticsearch6-rhel8:v6.8.1-82 | cpe:/a:redhat:logging:5.1::el8 | RHSA-2022:0042 | 2022-01-10T00:00:00Z |
| OpenShift Logging 5.2 | |||
| openshift-logging/elasticsearch6-rhel8:v6.8.1-83 | cpe:/a:redhat:logging:5.2::el8 | RHSA-2022:0043 | 2022-01-10T00:00:00Z |
| OpenShift Logging 5.3 | |||
| openshift-logging/elasticsearch6-rhel8:v6.8.1-84 | cpe:/a:redhat:logging:5.3::el8 | RHSA-2022:0044 | 2022-01-10T00:00:00Z |
| Red Hat AMQ Streams 1.6.6 | |||
| log4j-core | cpe:/a:redhat:amq_streams:1 | RHSA-2022:0219 | 2022-01-20T00:00:00Z |
| Red Hat Data Grid 8.2.3 | |||
| log4j-core | cpe:/a:redhat:jboss_data_grid:8.2 | RHSA-2022:0205 | 2022-01-20T00:00:00Z |
| Red Hat Fuse 7.8.2, 7.9.1, 7.10.1 | |||
| log4j-core | cpe:/a:redhat:jboss_fuse:7 | RHSA-2022:0203 | 2022-01-20T00:00:00Z |
| Red Hat Integration Camel Extensions for Quarkus 2.2 | |||
| log4j-core | cpe:/a:redhat:camel_quarkus:2.2 | RHSA-2022:0222 | 2022-01-20T00:00:00Z |
| Red Hat Integration Camel-K 1.6.3 | |||
| log4j-core | cpe:/a:redhat:integration:1 | RHSA-2022:0223 | 2022-01-20T00:00:00Z |
| Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 | |||
| eap7-log4j-0:2.17.1-1.redhat_00001.1.el8eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el8 | RHSA-2022:1297 | 2022-04-11T00:00:00Z |
| Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 | |||
| eap7-log4j-0:2.17.1-1.redhat_00001.1.el7eap | cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el7 | RHSA-2022:1296 | 2022-04-11T00:00:00Z |
| Red Hat OpenShift Container Platform 4.6 | |||
| openshift4/ose-logging-elasticsearch6:v4.6.0-202112201736.p0.gce7f68c.assembly.stream | cpe:/a:redhat:openshift:4.6::el8 | RHSA-2022:0026 | 2022-01-12T00:00:00Z |
| Red Hat Single Sign-On 7 | |||
| log4j-api | cpe:/a:redhat:red_hat_single_sign_on:7 | RHSA-2022:1469 | 2022-04-20T00:00:00Z |
| Red Hat Single Sign-On 7.5 for RHEL 7 | |||
| rh-sso7-keycloak-0:15.0.6-1.redhat_00001.1.el7sso | cpe:/a:redhat:red_hat_single_sign_on:7.5::el7 | RHSA-2022:1462 | 2022-04-20T00:00:00Z |
| Red Hat Single Sign-On 7.5 for RHEL 8 | |||
| rh-sso7-keycloak-0:15.0.6-1.redhat_00001.1.el8sso | cpe:/a:redhat:red_hat_single_sign_on:7.5::el8 | RHSA-2022:1463 | 2022-04-20T00:00:00Z |
| Vert.x 4.1.8 | |||
| log4j-core | cpe:/a:redhat:openshift_application_runtimes:1.0 | RHSA-2022:0083 | 2022-01-20T00:00:00Z |
No data.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2852-1 | apache-log4j2 security update |
Debian DSA |
DSA-5024-1 | apache-log4j2 security update |
Github GHSA |
GHSA-p6xc-xr62-6r2g | Apache Log4j2 vulnerable to Improper Input Validation and Uncontrolled Recursion |
Ubuntu USN |
USN-5203-1 | Apache Log4j 2 vulnerability |
Ubuntu USN |
USN-5222-1 | Apache Log4j 2 vulnerabilities |
Solution
No solution given by the vendor.
Workaround
Implement one of the following mitigation techniques: * Java 8 (or later) users should upgrade to release 2.17.0. Alternatively, this can be mitigated in configuration: * In PatternLayout in the logging configuration, replace Context Lookups like `${ctx:loginId}` or `$${ctx:loginId}` with Thread Context Map patterns (%X, %mdc, or %MDC). * Otherwise, in the configuration, remove references to Context Lookups like `${ctx:loginId}` or `$${ctx:loginId}` where they originate from sources external to the application such as HTTP headers or user input.
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-04T04:39:20.295Z
Reserved: 2021-12-16T00:00:00
Link: CVE-2021-45105
No data.
Status : Modified
Published: 2021-12-18T12:15:07.433
Modified: 2024-11-21T06:31:58.170
Link: CVE-2021-45105
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
Github GHSA
Ubuntu USN