← All CVEs

CVE-2021-45046

critical · 9Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2023-05-01Remediation due 2023-05-22

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in an information leak and remote code execution in some environments and local code execution in all environments. Log4j 2.16.0 (Java 8) and 2.12.2 (Java 7) fix this issue by removing support for message lookup patterns and disabling JNDI functionality by default.

9
CVSS
100.0%
EPSS (exploit prob.)
100th
EPSS percentile
2021-12-14
Published

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-917

Affected products

VendorProductAffected versions
apachelog4j>= 2.0.1, < 2.12.2
apachelog4j>= 2.13.0, < 2.16.0
apachelog4j2.0
apachelog4j2.0
apachelog4j2.0
apachelog4j2.0
cvatcomputer_vision_annotation_toolall versions
intelaudio_development_kitall versions
inteldatacenter_managerall versions
intelgenomics_kernel_libraryall versions
inteloneapiall versions
intelsecure_device_onboardall versions
intelsensor_solution_firmware_development_kitall versions
intelsystem_debuggerall versions
intelsystem_studioall versions
siemenssppa-t3000_ses3000_firmwareall versions
siemenssppa-t3000_ses3000all versions
siemenscaptial< 2019.1
siemenscaptial2019.1
siemenscaptial2019.1
siemenscomosall versions
siemensdesigo_cc_advanced_reports4.0
siemensdesigo_cc_advanced_reports4.1
siemensdesigo_cc_advanced_reports4.2
siemensdesigo_cc_advanced_reports5.0
siemensdesigo_cc_advanced_reports5.1
siemensdesigo_cc_info_center5.0
siemensdesigo_cc_info_center5.1
siemense-car_operation_center< 2021-12-13
siemensenergy_engage3.1
siemensenergyip8.5
siemensenergyip8.6
siemensenergyip8.7
siemensenergyip9.0
siemensenergyip_prepay3.7
siemensenergyip_prepay3.8
siemensgma-manager< 8.6.2j-398
siemenshead-end_system_universal_device_integration_systemall versions
siemensindustrial_edge_managementall versions
siemensindustrial_edge_management_hub< 2021-12-13

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2021-45046