CVE-2021-44832 is a remote code execution (RCE) vulnerability in Apache Log4j2 versions 2.0-beta7 through 2.17.0, affecting products from vendors like Apache, Cisco, and Oracle. It occurs when a JDBC Appender uses a JNDI LDAP data source URI under attacker control. With a CVSS score of 6.6 (MEDIUM), this vulnerability has high impact on confidentiality, integrity, and availability, but requires high privileges and no user interaction. While not listed in CISA KEV, it has garnered significant community discussion and media coverage, indicating widespread awareness despite no public exploit code being identified.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0.1, < 2.3.2CPE matchmatch criteria | cpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:* | ||
>= 2.4, < 2.12.4CPE matchmatch criteria | cpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:* | ||
>= 2.13.0, < 2.17.1CPE matchmatch criteria | cpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:* | ||
2.0CPE matchmatch criteria | cpe:2.3:a:apache:log4j:2.0:-:*:*:*:*:*:* | ||
2.0CPE matchmatch criteria | cpe:2.3:a:apache:log4j:2.0:beta7:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products
Feb 1, 2022Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products
Feb 1, 2022Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products
Feb 1, 2022Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products
Feb 1, 2022Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products
Feb 1, 2022Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products
Feb 1, 2022Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products
Feb 1, 2022Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products
Feb 1, 2022Improper Input Validation and Injection in Apache Log4j2
Jan 4, 2022log4j-core: remote code execution via JDBC Appender
Dec 28, 2021Apache Log4j Vulnerabilities - Impact on Bosch Rexroth Products
Dec 21, 2021Apache Log4j Vulnerabilities - Impact on Bosch Rexroth Products
Dec 21, 2021Apache Log4j Vulnerabilities - Impact on Bosch Rexroth Products
Dec 21, 2021Apache Log4j Vulnerabilities - Impact on Bosch Rexroth Products
Dec 21, 2021Apache Log4j Vulnerabilities - Impact on Bosch Rexroth Products
Dec 21, 2021Apache Log4j Vulnerabilities - Impact on Bosch Rexroth Products
Dec 21, 2021AS-2021-001: Log4Shell (Log4j 2)
Dec 16, 2021