Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
Configuration 9 (hide)
AND |
|
Configuration 10 (hide)
|
History
21 Nov 2024, 06:31
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.openwall.com/lists/oss-security/2021/12/19/1Â - Mailing List, Mitigation, Third Party Advisory | |
References | () https://cert-portal.siemens.com/productcert/pdf/ssa-479842.pdf - Third Party Advisory | |
References | () https://cert-portal.siemens.com/productcert/pdf/ssa-501673.pdf - Third Party Advisory | |
References | () https://logging.apache.org/log4j/2.x/security.html - Release Notes, Vendor Advisory | |
References | () https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0032Â - Third Party Advisory | |
References | () https://security.netapp.com/advisory/ntap-20211218-0001/Â - Third Party Advisory | |
References | () https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd - Third Party Advisory | |
References | () https://www.debian.org/security/2021/dsa-5024Â - Third Party Advisory | |
References | () https://www.kb.cert.org/vuls/id/930724Â - Third Party Advisory, US Government Resource | |
References | () https://www.oracle.com/security-alerts/cpuapr2022.html - Patch, Third Party Advisory | |
References | () https://www.oracle.com/security-alerts/cpujan2022.html - Patch, Third Party Advisory | |
References | () https://www.oracle.com/security-alerts/cpujul2022.html - Third Party Advisory | |
References | () https://www.zerodayinitiative.com/advisories/ZDI-21-1541/Â - Third Party Advisory, VDB Entry |
Information
Published : 2021-12-18 12:15
Updated : 2024-11-21 06:31
NVD link : CVE-2021-45105
Mitre link : CVE-2021-45105
CVE.ORG link : CVE-2021-45105
JSON object : View
Products Affected
debian
- debian_linux
oracle
- health_sciences_empirica_signal
- business_intelligence
- banking_enterprise_default_management
- communications_cloud_native_core_security_edge_protection_proxy
- instantis_enterprisetrack
- communications_services_gatekeeper
- e-business_suite
- financial_services_model_management_and_governance
- communications_cloud_native_core_network_repository_function
- managed_file_transfer
- communications_convergence
- autovue_for_agile_product_lifecycle_management
- banking_party_management
- webcenter_portal
- retail_store_inventory_management
- communications_pricing_design_center
- data_integrator
- peoplesoft_enterprise_peopletools
- taleo_platform
- communications_eagle_element_management_system
- retail_point-of-service
- hyperion_infrastructure_technology
- communications_cloud_native_core_network_function_cloud_native_environment
- insurance_data_gateway
- healthcare_master_person_index
- communications_asap
- communications_network_charging_and_control
- retail_order_broker
- primavera_p6_enterprise_project_portfolio_management
- communications_webrtc_session_controller
- financial_services_analytical_applications_infrastructure
- communications_evolved_communications_application_server
- healthcare_foundation
- communications_cloud_native_core_console
- hospitality_suite8
- health_sciences_inform
- retail_invoice_matching
- communications_diameter_signaling_router
- utilities_framework
- identity_manager_connector
- retail_central_office
- hyperion_planning
- retail_financial_integration
- enterprise_manager_ops_center
- flexcube_universal_banking
- communications_cloud_native_core_unified_data_repository
- communications_element_manager
- banking_treasury_management
- hyperion_data_relationship_management
- weblogic_server
- communications_cloud_native_core_policy
- primavera_unifier
- webcenter_sites
- retail_customer_insights
- siebel_ui_framework
- banking_trade_finance
- retail_back_office
- health_sciences_information_manager
- communications_cloud_native_core_service_communication_proxy
- enterprise_manager_base_platform
- management_cloud_engine
- banking_deposits_and_lines_of_credit_servicing
- retail_returns_management
- communications_network_integrity
- retail_price_management
- jdeveloper
- banking_platform
- banking_loans_servicing
- retail_merchandising_system
- agile_plm
- retail_integration_bus
- retail_order_management_system
- sql_developer
- communications_session_route_manager
- communications_unified_inventory_management
- retail_predictive_application_server
- retail_data_extractor_for_merchandising
- mysql_enterprise_monitor
- insurance_insbridge_rating_and_underwriting
- communications_cloud_native_core_network_slice_selection_function
- communications_eagle_ftp_table_base_retrieval
- communications_ip_service_activator
- enterprise_manager_for_peoplesoft
- healthcare_translational_research
- payment_interface
- banking_payments
- communications_service_broker
- communications_user_data_repository
- communications_session_report_manager
- communications_interactive_session_recorder
- communications_performance_intelligence_center
- healthcare_data_repository
- hyperion_bi\+
- retail_service_backbone
- retail_eftlink
- hyperion_profitability_and_cost_management
- hospitality_token_proxy_service
- hyperion_tax_provision
- agile_plm_mcad_connector
- communications_convergent_charging_controller
- identity_management_suite
- communications_messaging_server
- communications_billing_and_revenue_management
- agile_engineering_data_management
- primavera_gateway
sonicwall
- 6bk1602-0aa42-0tp0
- 6bk1602-0aa12-0tp0_firmware
- 6bk1602-0aa52-0tp0_firmware
- 6bk1602-0aa52-0tp0
- 6bk1602-0aa32-0tp0_firmware
- email_security
- 6bk1602-0aa22-0tp0_firmware
- network_security_manager
- 6bk1602-0aa32-0tp0
- web_application_firewall
- 6bk1602-0aa22-0tp0
- 6bk1602-0aa12-0tp0
- 6bk1602-0aa42-0tp0_firmware
netapp
- cloud_manager
apache
- log4j