CVE-2021-45105
medium · 5.9Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.
5.9
CVSS
100.0%
EPSS (exploit prob.)
100th
EPSS percentile
2021-12-18
Published
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses
CWE-20CWE-674
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apache | log4j | >= 2.0, < 2.3.1 |
| apache | log4j | >= 2.4, < 2.12.3 |
| apache | log4j | >= 2.13.0, <= 2.16.0 |
| netapp | cloud_manager | all versions |
| debian | debian_linux | 10.0 |
| debian | debian_linux | 11.0 |
| sonicwall | email_security | <= 10.0.12 |
| sonicwall | network_security_manager | >= 2.0, < 3.0 |
| sonicwall | network_security_manager | >= 2.0, < 3.0 |
| sonicwall | web_application_firewall | >= 3.0.0, < 3.1.0 |
| sonicwall | 6bk1602-0aa12-0tp0_firmware | < 2.7.0 |
| sonicwall | 6bk1602-0aa12-0tp0 | all versions |
| sonicwall | 6bk1602-0aa22-0tp0_firmware | < 2.7.0 |
| sonicwall | 6bk1602-0aa22-0tp0 | all versions |
| sonicwall | 6bk1602-0aa32-0tp0_firmware | < 2.7.0 |
| sonicwall | 6bk1602-0aa32-0tp0 | all versions |
| sonicwall | 6bk1602-0aa42-0tp0_firmware | < 2.7.0 |
| sonicwall | 6bk1602-0aa42-0tp0 | all versions |
| sonicwall | 6bk1602-0aa52-0tp0_firmware | < 2.7.0 |
| sonicwall | 6bk1602-0aa52-0tp0 | all versions |
| oracle | agile_engineering_data_management | 6.2.1.0 |
| oracle | agile_plm_mcad_connector | 3.6 |
| oracle | agile_product_lifecycle_management | 9.3.6 |
| oracle | autovue_for_agile_product_lifecycle_management | 21.0.2 |
| oracle | banking_deposits_and_lines_of_credit_servicing | 2.12.0 |
| oracle | banking_enterprise_default_management | 2.7.1 |
| oracle | banking_enterprise_default_management | 2.12.0 |
| oracle | banking_loans_servicing | 2.12.0 |
| oracle | banking_party_management | 2.7.0 |
| oracle | banking_payments | 14.5 |
| oracle | banking_platform | 2.6.2 |
| oracle | banking_platform | 2.7.1 |
| oracle | banking_platform | 2.12.0 |
| oracle | banking_trade_finance | 14.5 |
| oracle | banking_treasury_management | 14.5 |
| oracle | business_intelligence | 5.5.0.0.0 |
| oracle | communications_asap | 7.3 |
| oracle | communications_billing_and_revenue_management | 12.0.0.4 |
| oracle | communications_billing_and_revenue_management | 12.0.0.5 |
| oracle | communications_cloud_native_core_console | 1.9.0 |
Check a specific version with /api/v1/cve/match.
References
- http://www.openwall.com/lists/oss-security/2021/12/19/1
- https://cert-portal.siemens.com/productcert/pdf/ssa-479842.pdf
- https://cert-portal.siemens.com/productcert/pdf/ssa-501673.pdf
- https://logging.apache.org/log4j/2.x/security.html
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0032
- https://security.netapp.com/advisory/ntap-20211218-0001/
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd
- https://www.debian.org/security/2021/dsa-5024
- https://www.kb.cert.org/vuls/id/930724
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpujan2022.html
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://www.zerodayinitiative.com/advisories/ZDI-21-1541/
- http://www.openwall.com/lists/oss-security/2021/12/19/1
- https://cert-portal.siemens.com/productcert/pdf/ssa-479842.pdf
- https://cert-portal.siemens.com/productcert/pdf/ssa-501673.pdf
- https://logging.apache.org/log4j/2.x/security.html
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0032
- https://security.netapp.com/advisory/ntap-20211218-0001/
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd
- https://www.debian.org/security/2021/dsa-5024
- https://www.kb.cert.org/vuls/id/930724
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpujan2022.html
- https://www.oracle.com/security-alerts/cpujul2022.html
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2021-45105