Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-44832

77
FAUCET Score

CVE-2021-44832 is a remote code execution (RCE) vulnerability in Apache Log4j2 versions 2.0-beta7 through 2.17.0, affecting products from vendors like Apache, Cisco, and Oracle. It occurs when a JDBC Appender uses a JNDI LDAP data source URI under attacker control. With a CVSS score of 6.6 (MEDIUM), this vulnerability has high impact on confidentiality, integrity, and availability, but requires high privileges and no user interaction. While not listed in CISA KEV, it has garnered significant community discussion and media coverage, indicating widespread awareness despite no public exploit code being identified.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.0.1, < 2.3.2CPE matchmatch criteria
cpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:*
>= 2.4, < 2.12.4CPE matchmatch criteria
cpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:*
>= 2.13.0, < 2.17.1CPE matchmatch criteria
cpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:*
2.0CPE matchmatch criteria
cpe:2.3:a:apache:log4j:2.0:-:*:*:*:*:*:*
2.0CPE matchmatch criteria
cpe:2.3:a:apache:log4j:2.0:beta7:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.6MEDIUM

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
0.7
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
97.91%
Probability of exploitation in next 30 days
EPSS Percentile
99.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.9791 is in the 100th percentile among its peer group of 687 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (44)

barracudapatch availablevia llm_extracted
boschpatch availablevia llm_extracted
clamavpatch availablevia llm_extracted
consulpatch availablevia llm_extracted
freshrsspatch availablevia llm_extracted
githubpatch availablevia llm_extracted
View patch
mavenpatch availablevia ghsa
Product: org.ops4j.pax.logging:pax-logging-log4j2Fixed in: 1.11.13
mavenpatch availablevia ghsa
Product: org.ops4j.pax.logging:pax-logging-log4j2Fixed in: 2.0.14
mavenpatch availablevia ghsa
Product: org.apache.logging.log4j:log4j-coreFixed in: 2.17.1
mavenpatch availablevia ghsa
Product: org.apache.logging.log4j:log4j-coreFixed in: 2.12.4
mavenpatch availablevia ghsa
Product: org.ops4j.pax.logging:pax-logging-log4j2Fixed in: 1.9.2
mavenpatch availablevia ghsa
Product: org.apache.logging.log4j:log4j-coreFixed in: 2.3.2
mavenpatch availablevia ghsa
Product: org.ops4j.pax.logging:pax-logging-log4j2Fixed in: 1.10.9
oraclepatch availablevia nvd_reference
View patch
qdrantpatch availablevia llm_extracted
redhatpatch availablevia redhat_api
Product: Red Hat Fuse 7.8.2, 7.9.1, 7.10.1Fixed in: log4j-core
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Integration Camel Extensions for Quarkus 2.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Integration Camel-K 1.6.3Fixed in: log4j-core
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7Fixed in: log4j-core
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8Fixed in: eap7-log4j-0:2.17.1-1.redhat_00001.1.el8eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7Fixed in: eap7-log4j-0:2.17.1-1.redhat_00001.1.el7eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: openshift3/ose-logging-elasticsearch5:v3.11.570-2.ge84e80c
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.6Fixed in: openshift4/ose-logging-elasticsearch6:v4.6.0-202201181437.p0.g181b827.assembly.stream
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.7Fixed in: openshift4/ose-metering-hive:v4.7.0-202201271626.p0.g12e974d.assembly.stream
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.7Fixed in: openshift4/ose-metering-presto:v4.7.0-202201271626.p0.g2155d34.assembly.stream
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.8Fixed in: openshift4/ose-metering-hive:v4.8.0-202201271626.p0.g8fb24af.assembly.stream
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.8Fixed in: openshift4/ose-metering-presto:v4.8.0-202201271626.p0.gf1abc62.assembly.stream
View patch
redhatpatch availablevia redhat_api
Product: Vert.x 4.1.8Fixed in: log4j-core
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Data Grid 8.2.3Fixed in: log4j-core
View patch
redhatpatch availablevia redhat_api
Product: Red Hat AMQ Streams 2.0.0Fixed in: log4j-core
View patch
redhatpatch availablevia redhat_api
Product: Red Hat AMQ Streams 1.6.7
View patch
redhatpatch availablevia redhat_api
Product: OpenShift Logging 5.3Fixed in: openshift-logging/elasticsearch6-rhel8:v6.8.1-99
View patch
redhatpatch availablevia redhat_api
Product: OpenShift Logging 5.2Fixed in: openshift-logging/elasticsearch6-rhel8:v6.8.1-100
View patch
redhatpatch availablevia redhat_api
Product: OpenShift Logging 5.1Fixed in: openshift-logging/elasticsearch6-rhel8:v6.8.1-98
View patch
redhatpatch availablevia redhat_api
Product: OpenShift Logging 5.0Fixed in: openshift-logging/elasticsearch6-rhel8:v5.0.12-1
View patch
symantecpatch availablevia llm_extracted
verbbpatch availablevia llm_extracted
cephvendor investigatingvia llm_extracted
d-linkvendor investigatingvia llm_extracted
humansignalvendor investigatingvia llm_extracted
hyperledgervendor investigatingvia llm_extracted
m2teamvendor investigatingvia llm_extracted
roundcubevendor investigatingvia llm_extracted
redhatno patchvia redhat_api
Product: Red Hat Integration Camel Quarkus 1Fixed in: log4j-core

Vendor Advisories (17)

clamavllm-clamav-74c1f36ca2a2b103

Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products

Feb 1, 2022
qdrantllm-qdrant-af0caffba9b2abad

Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products

Feb 1, 2022
barracudallm-barracuda-af8d79e5d61c6a4f

Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products

Feb 1, 2022
symantecllm-symantec-4371e9c73ac47a0f

Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products

Feb 1, 2022
freshrssllm-freshrss-979b674cecbf7667

Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products

Feb 1, 2022
verbbllm-verbb-543b95d4c401d528

Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products

Feb 1, 2022
consulllm-consul-56727e0e2c5a61f8

Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products

Feb 1, 2022
boschllm-bosch-e97b75ff9f19c1ea

Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products

Feb 1, 2022
mavenGHSA-8489-44mv-ggj8medium

Improper Input Validation and Injection in Apache Log4j2

Jan 4, 2022
redhatCVE-2021-44832Moderate

log4j-core: remote code execution via JDBC Appender

Dec 28, 2021
humansignalllm-humansignal-12e8acb84ccefbc7CRITICAL

Apache Log4j Vulnerabilities - Impact on Bosch Rexroth Products

Dec 21, 2021
d-linkllm-d-link-20f39e25cea76c5fCRITICAL

Apache Log4j Vulnerabilities - Impact on Bosch Rexroth Products

Dec 21, 2021
cephllm-ceph-a2039da5e9b378f4CRITICAL

Apache Log4j Vulnerabilities - Impact on Bosch Rexroth Products

Dec 21, 2021
hyperledgerllm-hyperledger-f29f3d801cb68028CRITICAL

Apache Log4j Vulnerabilities - Impact on Bosch Rexroth Products

Dec 21, 2021
m2teamllm-m2team-fd218185b07cc095CRITICAL

Apache Log4j Vulnerabilities - Impact on Bosch Rexroth Products

Dec 21, 2021
roundcubellm-roundcube-973d1101d3777753CRITICAL

Apache Log4j Vulnerabilities - Impact on Bosch Rexroth Products

Dec 21, 2021
githubllm-github-10c37a0302001c2f

AS-2021-001: Log4Shell (Log4j 2)

Dec 16, 2021

References

cert-portal.siemens.com / productcert/pdf/ssa-784507.pdf
Third Party Advisory
issues.apache.org / jira/browse/LOG4J2-3293
Issue TrackingPatchVendor Advisory
lists.apache.org / thread/s1o5vlo78ypqxnzn6p8zf6t9shtq5143
Mailing ListVendor Advisory
lists.debian.org / debian-lts-announce/2021/12/msg00036.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/EVV25FXL4FU5X6X5BSL7RLQ7T6F65MRA
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/T57MPJUW3MA6QGWZRTMCHHMMPQNVKGFC
security.netapp.com / advisory/ntap-20220104-0001
Third Party Advisory
tools.cisco.com / security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd
Third Party Advisory
oracle.com / security-alerts/cpuapr2022.html
PatchThird Party Advisory
oracle.com / security-alerts/cpujan2022.html
PatchThird Party Advisory
oracle.com / security-alerts/cpujul2022.html
PatchThird Party Advisory
openwall.com / lists/oss-security/2021/12/28/1
Mailing ListThird Party Advisory