Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-45046

98
FAUCET Score

CVE-2021-45046 is an incomplete fix for CVE-2021-44228 in Apache Log4j 2.15.0, allowing attackers to craft malicious input via Thread Context Map (MDC) when specific non-default Pattern Layouts are used, leading to information leakage, remote code execution, or local code execution. This critical vulnerability (CVSS 9.0) affects numerous products including Apache, Debian, and Intel, and has a high FAUCET Risk Score of 100/100. It is actively exploited in the wild, including in known ransomware campaigns, with Metasploit modules and Nuclei templates available, and has garnered significant community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.0.1, < 2.12.2CPE matchmatch criteria
cpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:*
>= 2.13.0, < 2.16.0CPE matchmatch criteria
cpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:*
2.0CPE matchmatch criteria
cpe:2.3:a:apache:log4j:2.0:-:*:*:*:*:*:*
2.0CPE matchmatch criteria
cpe:2.3:a:apache:log4j:2.0:beta9:*:*:*:*:*:*
2.0CPE matchmatch criteria
cpe:2.3:a:apache:log4j:2.0:rc1:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.0CRITICAL

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.2
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
99.98%
Probability of exploitation in next 30 days
EPSS Percentile
100.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Added to KEV · May 1, 2023
Metasploit: Log4Shell HTTP Scanner · Dec 9, 2021
Nuclei: CVE-2021-45046 · Dec 23, 2021
This CVE's current EPSS score of 0.9998 is in the 99th percentile among its peer group of 201 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.4 Reddit, 1.2 Bluesky, 0.9 Mastodon, and 2.3 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.8 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (79)

3cxpatch availablevia llm_extracted
barracudapatch availablevia llm_extracted
boschpatch availablevia llm_extracted
clamavpatch availablevia llm_extracted
consulpatch availablevia llm_extracted
coollabspatch availablevia llm_extracted
freshrsspatch availablevia llm_extracted
githubpatch availablevia llm_extracted
View patch
mavenpatch availablevia ghsa
Product: org.ops4j.pax.logging:pax-logging-log4j2Fixed in: 1.11.11
mavenpatch availablevia ghsa
Product: org.apache.logging.log4j:log4j-coreFixed in: 2.16.0
mavenpatch availablevia ghsa
Product: org.apache.logging.log4j:log4j-coreFixed in: 2.12.2
mavenpatch availablevia ghsa
Product: org.ops4j.pax.logging:pax-logging-log4j2Fixed in: 1.9.2
mavenpatch availablevia ghsa
Product: org.ops4j.pax.logging:pax-logging-log4j2Fixed in: 1.10.8
mavenpatch availablevia ghsa
Product: org.ops4j.pax.logging:pax-logging-log4j2Fixed in: 2.0.12
omronpatch availablevia llm_extracted
View patch
oraclepatch availablevia nvd_reference
View patch
qdrantpatch availablevia llm_extracted
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7Fixed in: eap7-wildfly-0:7.1.9-2.GA_redhat_00002.1.ep7.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7Fixed in: eap7-hal-console-0:3.2.17-1.Final_redhat_00001.1.el7eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7Fixed in: eap7-jackson-annotations-0:2.10.4-2.redhat_00004.1.el7eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7Fixed in: eap7-jackson-core-0:2.10.4-2.redhat_00004.1.el7eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7Fixed in: eap7-jackson-databind-0:2.10.4-4.redhat_00004.1.el7eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7Fixed in: eap7-jackson-jaxrs-providers-0:2.10.4-2.redhat_00004.1.el7eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7Fixed in: eap7-jackson-modules-base-0:2.10.4-4.redhat_00004.1.el7eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7Fixed in: eap7-jackson-modules-java8-0:2.10.4-2.redhat_00004.1.el7eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7Fixed in: eap7-jettison-0:1.5.2-2.redhat_00002.1.el7eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7Fixed in: eap7-netty-0:4.1.63-4.Final_redhat_00002.1.el7eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7Fixed in: eap7-resteasy-0:3.11.6-1.Final_redhat_00001.1.el7eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7Fixed in: eap7-snakeyaml-0:1.33.0-1.SP1_redhat_00001.1.el7eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7Fixed in: eap7-wildfly-0:7.3.12-3.GA_redhat_00002.1.el7eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8Fixed in: eap7-log4j-0:2.17.1-1.redhat_00001.1.el8eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7Fixed in: eap7-log4j-0:2.17.1-1.redhat_00001.1.el7eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: openshift3/ose-logging-elasticsearch5:v3.11.570-2.gd119820
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.6Fixed in: openshift4/ose-logging-elasticsearch6:v4.6.0-202112132021.p0.g2a13a81.assembly.stream
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.6Fixed in: openshift4/ose-metering-hive:v4.6.0-202112140546.p0.g8b9da97.assembly.stream
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.6Fixed in: openshift4/ose-metering-presto:v4.6.0-202112150545.p0.g190688a.assembly.art3595
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.7Fixed in: openshift4/ose-metering-hive:v4.7.0-202112140553.p0.g091bb99.assembly.stream
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.7Fixed in: openshift4/ose-metering-presto:v4.7.0-202112150631.p0.gd502108.assembly.4.7.40
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.8Fixed in: openshift4/ose-metering-hive:v4.8.0-202112132154.p0.g57dd03a.assembly.stream
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.8Fixed in: openshift4/ose-metering-presto:v4.8.0-202112150431.p0.g4b934ae.assembly.art3599
View patch
redhatpatch availablevia redhat_api
Product: Vert.x 4.1.8Fixed in: log4j-core
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7Fixed in: log4j-core
View patch
redhatpatch availablevia redhat_api
Product: OpenShift Logging 5.0Fixed in: openshift-logging/elasticsearch6-rhel8:v5.0.10-1
View patch
redhatpatch availablevia redhat_api
Product: OpenShift Logging 5.1Fixed in: openshift-logging/elasticsearch6-rhel8:v6.8.1-67
View patch
redhatpatch availablevia redhat_api
Product: OpenShift Logging 5.2Fixed in: openshift-logging/elasticsearch6-rhel8:v6.8.1-66
View patch
redhatpatch availablevia redhat_api
Product: OpenShift Logging 5.3Fixed in: openshift-logging/elasticsearch6-rhel8:v6.8.1-65
View patch
redhatpatch availablevia redhat_api
Product: Red Hat AMQ Streams 2.0.0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Data Grid 8.2.3Fixed in: log4j-core
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Fuse 7.8.2, 7.9.1, 7.10.1Fixed in: log4j-core
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Integration Camel Extensions for Quarkus 2.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Integration Camel-K 1.6.3Fixed in: log4j-core
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7Fixed in: eap7-apache-cxf-0:3.1.16-4.redhat_00003.1.ep7.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7Fixed in: eap7-jackson-databind-0:2.8.11.6-2.SP1_redhat_00002.1.ep7.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7Fixed in: eap7-jettison-0:1.3.8-2.redhat_00002.1.ep7.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7Fixed in: eap7-netty-0:4.1.63-1.Final_redhat_00002.1.ep7.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7Fixed in: eap7-resteasy-0:3.0.27-1.Final_redhat_00001.1.ep7.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7Fixed in: eap7-snakeyaml-0:1.33.0-1.SP1_redhat_00001.1.ep7.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7Fixed in: eap7-velocity-0:1.7.0-3.redhat_00006.1.ep7.el7
View patch
samrocketmanpatch availablevia llm_extracted
View patch
symantecpatch availablevia llm_extracted
verbbpatch availablevia llm_extracted
ansiblevendor investigatingvia llm_extracted
capnprotovendor investigatingvia llm_extracted
View patch
cephvendor investigatingvia llm_extracted
ciscovendor investigatingvia llm_extracted
View patch
d-linkvendor investigatingvia llm_extracted
hedgedocvendor investigatingvia llm_extracted
View patch
hpvendor investigatingvia llm_extracted
View patch
humansignalvendor investigatingvia llm_extracted
hyperledgervendor investigatingvia llm_extracted
jenkinsvendor investigatingvia llm_extracted
View patch
lycheeorgvendor investigatingvia llm_extracted
View patch
m2teamvendor investigatingvia llm_extracted
netflixvendor investigatingvia llm_extracted
View patch
ptcvendor investigatingvia llm_extracted
View patch
roundcubevendor investigatingvia llm_extracted
yokogawavendor investigatingvia llm_extracted
View patch
redhatno patchvia redhat_api
Product: Red Hat Integration Camel Quarkus 1Fixed in: log4j-core
redhatno patchvia redhat_api
Product: streams for Apache KafkaFixed in: log4j-core

Vendor Advisories (43)

boschllm-bosch-e97b75ff9f19c1ea

Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products

Feb 1, 2022
clamavllm-clamav-74c1f36ca2a2b103

Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products

Feb 1, 2022
barracudallm-barracuda-af8d79e5d61c6a4f

Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products

Feb 1, 2022
symantecllm-symantec-4371e9c73ac47a0f

Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products

Feb 1, 2022
freshrssllm-freshrss-979b674cecbf7667

Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products

Feb 1, 2022
verbbllm-verbb-543b95d4c401d528

Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products

Feb 1, 2022
consulllm-consul-56727e0e2c5a61f8

Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products

Feb 1, 2022
qdrantllm-qdrant-af0caffba9b2abad

Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products

Feb 1, 2022
ptcllm-ptc-b1e0117182634b21

Okta On-Prem MFA Agent

Jan 26, 2022
ansiblellm-ansible-1784548819af3909

Okta RADIUS Server Agent

Jan 26, 2022
omronllm-omron-88a56391d49f7f9d

Okta On-Prem MFA Agent

Jan 26, 2022
omronllm-omron-8e3137442b1609d2

Okta RADIUS Server Agent

Jan 26, 2022
netflixllm-netflix-fb01ad160bf33618

Okta On-Prem MFA Agent

Jan 26, 2022
netflixllm-netflix-37678e7b06ff08f8

Okta RADIUS Server Agent

Jan 26, 2022
ansiblellm-ansible-bc3839a9c72fa96b

Okta On-Prem MFA Agent

Jan 26, 2022
ptcllm-ptc-976e1796674be3d2

Okta RADIUS Server Agent

Jan 26, 2022
hyperledgerllm-hyperledger-0a534655922d0579CRITICAL

Log4j Vulnerabilities - Impact on PRAESENSA Advanced Public Address Server (PRA-APAS)

Dec 22, 2021
roundcubellm-roundcube-bf2fbc5dc95d4c06CRITICAL

Log4j Vulnerabilities - Impact on PRAESENSA Advanced Public Address Server (PRA-APAS)

Dec 22, 2021
cephllm-ceph-9d9c9e12248affaeCRITICAL

Log4j Vulnerabilities - Impact on PRAESENSA Advanced Public Address Server (PRA-APAS)

Dec 22, 2021
humansignalllm-humansignal-cf93a2c20c745b43CRITICAL

Log4j Vulnerabilities - Impact on PRAESENSA Advanced Public Address Server (PRA-APAS)

Dec 22, 2021
d-linkllm-d-link-2b726676a1308f5fCRITICAL

Log4j Vulnerabilities - Impact on PRAESENSA Advanced Public Address Server (PRA-APAS)

Dec 22, 2021
m2teamllm-m2team-01f5b8b40cc5477cCRITICAL

Log4j Vulnerabilities - Impact on PRAESENSA Advanced Public Address Server (PRA-APAS)

Dec 22, 2021
m2teamllm-m2team-fd218185b07cc095CRITICAL

Apache Log4j Vulnerabilities - Impact on Bosch Rexroth Products

Dec 21, 2021
roundcubellm-roundcube-973d1101d3777753CRITICAL

Apache Log4j Vulnerabilities - Impact on Bosch Rexroth Products

Dec 21, 2021
humansignalllm-humansignal-12e8acb84ccefbc7CRITICAL

Apache Log4j Vulnerabilities - Impact on Bosch Rexroth Products

Dec 21, 2021
d-linkllm-d-link-20f39e25cea76c5fCRITICAL

Apache Log4j Vulnerabilities - Impact on Bosch Rexroth Products

Dec 21, 2021
cephllm-ceph-a2039da5e9b378f4CRITICAL

Apache Log4j Vulnerabilities - Impact on Bosch Rexroth Products

Dec 21, 2021
hyperledgerllm-hyperledger-f29f3d801cb68028CRITICAL

Apache Log4j Vulnerabilities - Impact on Bosch Rexroth Products

Dec 21, 2021
coollabsllm-coollabs-de5dc7fb3cfc06a0CRITICAL

HBT Apache Log4j Vulnerability

Dec 16, 2021
coollabsllm-coollabs-46da79932c430e92CRITICAL

SPS Apache Log4j Vulnerability

Dec 16, 2021
githubllm-github-10c37a0302001c2f

AS-2021-001: Log4Shell (Log4j 2)

Dec 16, 2021
mavenGHSA-7rjr-3q55-vv33critical

Incomplete fix for Apache Log4j vulnerability

Dec 14, 2021
ciscollm-cisco-387b577d83f9ed2b

Log4Shell Vulnerability (CVE-2021-4104 / CVE-2021-44228 / CVE-2021-45046 / CVE-2021-45105 )

Dec 14, 2021
redhatCVE-2021-45046Moderate

log4j-core: DoS in log4j 2.x with thread context message pattern and context lookup pattern (incomplete fix for CVE-2021-44228)

Dec 14, 2021
hpllm-hp-2055d4c7f54b1803

Log4Shell Vulnerability (CVE-2021-4104 / CVE-2021-44228 / CVE-2021-45046 / CVE-2021-45105 )

Dec 14, 2021
jenkinsllm-jenkins-7d91794cc1b2006b

Log4Shell Vulnerability (CVE-2021-4104 / CVE-2021-44228 / CVE-2021-45046 / CVE-2021-45105 )

Dec 14, 2021
hedgedocllm-hedgedoc-4a615bf87a47e5e3

Log4Shell Vulnerability (CVE-2021-4104 / CVE-2021-44228 / CVE-2021-45046 / CVE-2021-45105 )

Dec 14, 2021
yokogawallm-yokogawa-37145bd015de806f

Log4Shell Vulnerability (CVE-2021-4104 / CVE-2021-44228 / CVE-2021-45046 / CVE-2021-45105 )

Dec 14, 2021
lycheeorgllm-lycheeorg-09b89315da092fa0

Log4Shell Vulnerability (CVE-2021-4104 / CVE-2021-44228 / CVE-2021-45046 / CVE-2021-45105 )

Dec 14, 2021
capnprotollm-capnproto-b08e57af0276a29b

Log4Shell Vulnerability (CVE-2021-4104 / CVE-2021-44228 / CVE-2021-45046 / CVE-2021-45105 )

Dec 14, 2021
samrocketmanllm-samrocketman-06cde3e9dcf8da99CRITICAL

NR21-04

Dec 13, 2021
3cxllm-3cx-b78bae857f56c8d1CRITICAL

NR21-03

Dec 10, 2021
samrocketmanllm-samrocketman-c1e5366fd9a505f5CRITICAL

NR21-03

Dec 10, 2021

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
cert-portal.siemens.com / productcert/pdf/ssa-397453.pdf
Third Party Advisory
cert-portal.siemens.com / productcert/pdf/ssa-479842.pdf
Third Party Advisory
cert-portal.siemens.com / productcert/pdf/ssa-661247.pdf
Third Party Advisory
cert-portal.siemens.com / productcert/pdf/ssa-714170.pdf
Third Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/EOKPQGV24RRBBI4TBZUDQMM4MEH7MXCY
Mailing ListRelease Notes
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/SIG7FZULMNK2XF6FZRU4VWYDQXNMUGAJ
Mailing ListRelease Notes
logging.apache.org / log4j/2.x/security.html
MitigationRelease NotesVendor Advisory
psirt.global.sonicwall.com / vuln-detail/SNWLID-2021-0032
Third Party Advisory
security.gentoo.org / glsa/202310-16
Third Party Advisory
tools.cisco.com / security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd
Third Party Advisory
cve.org / CVERecord
Not Applicable
debian.org / security/2021/dsa-5022
Third Party Advisory
intel.com / content/www/us/en/security-center/advisory/intel-sa-00646.html
Third Party Advisory
kb.cert.org / vuls/id/930724
Third Party AdvisoryUS Government Resource
oracle.com / security-alerts/alert-cve-2021-44228.html
Third Party Advisory
oracle.com / security-alerts/cpuapr2022.html
Third Party Advisory
oracle.com / security-alerts/cpujan2022.html
PatchThird Party Advisory
oracle.com / security-alerts/cpujul2022.html
Third Party Advisory
openwall.com / lists/oss-security/2021/12/14/4
Mailing ListMitigationThird Party Advisory
openwall.com / lists/oss-security/2021/12/15/3
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2021/12/18/1
Mailing ListThird Party Advisory