Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-45105

76
FAUCET Score

CVE-2021-45105 is a denial-of-service vulnerability affecting Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1), impacting products from vendors like Apache, Debian, and Oracle. An attacker can trigger uncontrolled recursion via self-referential lookups with crafted Thread Context Map data, leading to a system crash. This medium-severity vulnerability (CVSS 5.9) has a network attack vector and high attack complexity, resulting in a high impact on availability. While there is no known exploit code in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered significant community discussion and media coverage, indicating high awareness.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.0, < 2.3.1CPE matchmatch criteria
cpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:*
>= 2.4, < 2.12.3CPE matchmatch criteria
cpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:*
>= 2.13.0, <= 2.16.0CPE matchmatch criteria
cpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:netapp:cloud_manager:-:*:*:*:*:*:*:*
10.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.9MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
2.2
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
100.00%
Probability of exploitation in next 30 days
EPSS Percentile
100.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 1.0000 is in the 100th percentile among its peer group of 19,958 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (55)

barracudapatch availablevia llm_extracted
boschpatch availablevia llm_extracted
clamavpatch availablevia llm_extracted
consulpatch availablevia llm_extracted
coollabspatch availablevia llm_extracted
freshrsspatch availablevia llm_extracted
mavenpatch availablevia ghsa
Product: org.apache.logging.log4j:log4j-coreFixed in: 2.17.0
mavenpatch availablevia ghsa
Product: org.apache.logging.log4j:log4j-coreFixed in: 2.3.1
mavenpatch availablevia ghsa
Product: org.ops4j.pax.logging:pax-logging-log4j2Fixed in: 1.9.2
mavenpatch availablevia ghsa
Product: org.ops4j.pax.logging:pax-logging-log4j2Fixed in: 1.10.9
mavenpatch availablevia ghsa
Product: org.ops4j.pax.logging:pax-logging-log4j2Fixed in: 1.11.12
mavenpatch availablevia ghsa
Product: org.ops4j.pax.logging:pax-logging-log4j2Fixed in: 2.0.13
mavenpatch availablevia ghsa
Product: org.apache.logging.log4j:log4j-coreFixed in: 2.12.3
omronpatch availablevia llm_extracted
View patch
oraclepatch availablevia nvd_reference
View patch
qdrantpatch availablevia llm_extracted
redhatpatch availablevia redhat_api
Product: Vert.x 4.1.8Fixed in: log4j-core
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Single Sign-On 7Fixed in: log4j-api
View patch
redhatpatch availablevia redhat_api
Product: OpenShift Logging 5.0Fixed in: openshift-logging/elasticsearch6-rhel8:v5.0.11-2
View patch
redhatpatch availablevia redhat_api
Product: OpenShift Logging 5.1Fixed in: openshift-logging/elasticsearch6-rhel8:v6.8.1-82
View patch
redhatpatch availablevia redhat_api
Product: OpenShift Logging 5.2Fixed in: openshift-logging/elasticsearch6-rhel8:v6.8.1-83
View patch
redhatpatch availablevia redhat_api
Product: OpenShift Logging 5.3Fixed in: openshift-logging/elasticsearch6-rhel8:v6.8.1-84
View patch
redhatpatch availablevia redhat_api
Product: Red Hat AMQ Streams 1.6.6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Data Grid 8.2.3Fixed in: log4j-core
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Fuse 7.8.2, 7.9.1, 7.10.1Fixed in: log4j-core
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Integration Camel Extensions for Quarkus 2.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Integration Camel-K 1.6.3Fixed in: log4j-core
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7Fixed in: log4j-core
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8Fixed in: eap7-log4j-0:2.17.1-1.redhat_00001.1.el8eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7Fixed in: eap7-log4j-0:2.17.1-1.redhat_00001.1.el7eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.6Fixed in: openshift4/ose-logging-elasticsearch6:v4.6.0-202112201736.p0.gce7f68c.assembly.stream
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Single Sign-On 7.5 for RHEL 7Fixed in: rh-sso7-keycloak-0:15.0.6-1.redhat_00001.1.el7sso
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Single Sign-On 7.5 for RHEL 8Fixed in: rh-sso7-keycloak-0:15.0.6-1.redhat_00001.1.el8sso
View patch
symantecpatch availablevia llm_extracted
verbbpatch availablevia llm_extracted
ansiblevendor investigatingvia llm_extracted
capnprotovendor investigatingvia llm_extracted
View patch
cephvendor investigatingvia llm_extracted
ciscovendor investigatingvia llm_extracted
View patch
d-linkvendor investigatingvia llm_extracted
hedgedocvendor investigatingvia llm_extracted
View patch
hpvendor investigatingvia llm_extracted
View patch
humansignalvendor investigatingvia llm_extracted
hyperledgervendor investigatingvia llm_extracted
jenkinsvendor investigatingvia llm_extracted
View patch
lycheeorgvendor investigatingvia llm_extracted
View patch
m2teamvendor investigatingvia llm_extracted
netflixvendor investigatingvia llm_extracted
View patch
ptcvendor investigatingvia llm_extracted
View patch
roundcubevendor investigatingvia llm_extracted
yokogawavendor investigatingvia llm_extracted
View patch
redhatno patchvia redhat_api
Product: Red Hat Integration Camel Quarkus 1Fixed in: log4j-core
redhatno patchvia redhat_api
Product: Red Hat Decision Manager 7Fixed in: log4j-api
redhatno patchvia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: openshift3/ose-logging-elasticsearch5
redhatno patchvia redhat_api
Product: streams for Apache KafkaFixed in: log4j-core

Vendor Advisories (38)

qdrantllm-qdrant-af0caffba9b2abad

Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products

Feb 1, 2022
clamavllm-clamav-74c1f36ca2a2b103

Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products

Feb 1, 2022
verbbllm-verbb-543b95d4c401d528

Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products

Feb 1, 2022
consulllm-consul-56727e0e2c5a61f8

Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products

Feb 1, 2022
freshrssllm-freshrss-979b674cecbf7667

Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products

Feb 1, 2022
boschllm-bosch-e97b75ff9f19c1ea

Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products

Feb 1, 2022
barracudallm-barracuda-af8d79e5d61c6a4f

Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products

Feb 1, 2022
symantecllm-symantec-4371e9c73ac47a0f

Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products

Feb 1, 2022
omronllm-omron-a834047824d8aa55

Okta On-Prem MFA Agent

Jan 26, 2022
omronllm-omron-5733a9c1265b3b6f

Okta RADIUS Server Agent

Jan 26, 2022
netflixllm-netflix-9a34f49505704e71

Okta On-Prem MFA Agent

Jan 26, 2022
ansiblellm-ansible-cdcd8c835d8840ee

Okta RADIUS Server Agent

Jan 26, 2022
ptcllm-ptc-66356be0be995556

Okta On-Prem MFA Agent

Jan 26, 2022
ansiblellm-ansible-e800aaf2959752d9

Okta On-Prem MFA Agent

Jan 26, 2022
ptcllm-ptc-7780b3a5f9c474f1

Okta RADIUS Server Agent

Jan 26, 2022
netflixllm-netflix-378118930ec16beb

Okta RADIUS Server Agent

Jan 26, 2022
d-linkllm-d-link-2b726676a1308f5fCRITICAL

Log4j Vulnerabilities - Impact on PRAESENSA Advanced Public Address Server (PRA-APAS)

Dec 22, 2021
hyperledgerllm-hyperledger-0a534655922d0579CRITICAL

Log4j Vulnerabilities - Impact on PRAESENSA Advanced Public Address Server (PRA-APAS)

Dec 22, 2021
roundcubellm-roundcube-bf2fbc5dc95d4c06CRITICAL

Log4j Vulnerabilities - Impact on PRAESENSA Advanced Public Address Server (PRA-APAS)

Dec 22, 2021
cephllm-ceph-9d9c9e12248affaeCRITICAL

Log4j Vulnerabilities - Impact on PRAESENSA Advanced Public Address Server (PRA-APAS)

Dec 22, 2021
humansignalllm-humansignal-cf93a2c20c745b43CRITICAL

Log4j Vulnerabilities - Impact on PRAESENSA Advanced Public Address Server (PRA-APAS)

Dec 22, 2021
m2teamllm-m2team-01f5b8b40cc5477cCRITICAL

Log4j Vulnerabilities - Impact on PRAESENSA Advanced Public Address Server (PRA-APAS)

Dec 22, 2021
d-linkllm-d-link-20f39e25cea76c5fCRITICAL

Apache Log4j Vulnerabilities - Impact on Bosch Rexroth Products

Dec 21, 2021
m2teamllm-m2team-fd218185b07cc095CRITICAL

Apache Log4j Vulnerabilities - Impact on Bosch Rexroth Products

Dec 21, 2021
humansignalllm-humansignal-12e8acb84ccefbc7CRITICAL

Apache Log4j Vulnerabilities - Impact on Bosch Rexroth Products

Dec 21, 2021
cephllm-ceph-a2039da5e9b378f4CRITICAL

Apache Log4j Vulnerabilities - Impact on Bosch Rexroth Products

Dec 21, 2021
roundcubellm-roundcube-973d1101d3777753CRITICAL

Apache Log4j Vulnerabilities - Impact on Bosch Rexroth Products

Dec 21, 2021
hyperledgerllm-hyperledger-f29f3d801cb68028CRITICAL

Apache Log4j Vulnerabilities - Impact on Bosch Rexroth Products

Dec 21, 2021
mavenGHSA-p6xc-xr62-6r2ghigh

Apache Log4j2 vulnerable to Improper Input Validation and Uncontrolled Recursion

Dec 18, 2021
redhatCVE-2021-45105Moderate

log4j-core: DoS in log4j 2.x with Thread Context Map (MDC) input data contains a recursive lookup and context lookup pattern

Dec 18, 2021
coollabsllm-coollabs-46da79932c430e92CRITICAL

SPS Apache Log4j Vulnerability

Dec 16, 2021
lycheeorgllm-lycheeorg-09b89315da092fa0

Log4Shell Vulnerability (CVE-2021-4104 / CVE-2021-44228 / CVE-2021-45046 / CVE-2021-45105 )

Dec 14, 2021
ciscollm-cisco-387b577d83f9ed2b

Log4Shell Vulnerability (CVE-2021-4104 / CVE-2021-44228 / CVE-2021-45046 / CVE-2021-45105 )

Dec 14, 2021
hedgedocllm-hedgedoc-4a615bf87a47e5e3

Log4Shell Vulnerability (CVE-2021-4104 / CVE-2021-44228 / CVE-2021-45046 / CVE-2021-45105 )

Dec 14, 2021
capnprotollm-capnproto-b08e57af0276a29b

Log4Shell Vulnerability (CVE-2021-4104 / CVE-2021-44228 / CVE-2021-45046 / CVE-2021-45105 )

Dec 14, 2021
hpllm-hp-2055d4c7f54b1803

Log4Shell Vulnerability (CVE-2021-4104 / CVE-2021-44228 / CVE-2021-45046 / CVE-2021-45105 )

Dec 14, 2021
yokogawallm-yokogawa-37145bd015de806f

Log4Shell Vulnerability (CVE-2021-4104 / CVE-2021-44228 / CVE-2021-45046 / CVE-2021-45105 )

Dec 14, 2021
jenkinsllm-jenkins-7d91794cc1b2006b

Log4Shell Vulnerability (CVE-2021-4104 / CVE-2021-44228 / CVE-2021-45046 / CVE-2021-45105 )

Dec 14, 2021

References

cert-portal.siemens.com / productcert/pdf/ssa-479842.pdf
Third Party Advisory
cert-portal.siemens.com / productcert/pdf/ssa-501673.pdf
Third Party Advisory
logging.apache.org / log4j/2.x/security.html
Release NotesVendor Advisory
psirt.global.sonicwall.com / vuln-detail/SNWLID-2021-0032
Third Party Advisory
security.netapp.com / advisory/ntap-20211218-0001
Third Party Advisory
tools.cisco.com / security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd
Third Party Advisory
debian.org / security/2021/dsa-5024
Third Party Advisory
kb.cert.org / vuls/id/930724
Third Party AdvisoryUS Government Resource
oracle.com / security-alerts/cpuapr2022.html
PatchThird Party Advisory
oracle.com / security-alerts/cpujan2022.html
PatchThird Party Advisory
oracle.com / security-alerts/cpujul2022.html
Third Party Advisory
zerodayinitiative.com / advisories/ZDI-21-1541
Third Party AdvisoryVDB Entry
openwall.com / lists/oss-security/2021/12/19/1
Mailing ListMitigationThird Party Advisory