CVE-2021-44228

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.
Expression Language Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
10 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
apacheCNA
---
---
CVEADP
---
---
CISA-ADPADP
10 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
VendorProductVersion
siemens6bk1602-0aa12-0tp0_firmware
𝑥
< 2.7.0
siemens6bk1602-0aa22-0tp0_firmware
𝑥
< 2.7.0
siemens6bk1602-0aa32-0tp0_firmware
𝑥
< 2.7.0
siemens6bk1602-0aa42-0tp0_firmware
𝑥
< 2.7.0
siemens6bk1602-0aa52-0tp0_firmware
𝑥
< 2.7.0
apachelog4j
2.0.1 ≤
𝑥
< 2.3.1
apachelog4j
2.4.0 ≤
𝑥
< 2.12.2
apachelog4j
2.13.0 ≤
𝑥
< 2.15.0
apachelog4j
2.0
apachelog4j
2.0:beta9
apachelog4j
2.0:rc1
apachelog4j
2.0:rc2
siemenssppa-t3000_ses3000_firmware
*
siemenscapital
𝑥
< 2019.1
siemenscapital
2019.1
siemenscapital
2019.1:sp1912
siemenscomos
𝑥
< 10.4.2
siemensdesigo_cc_advanced_reports
3.0
siemensdesigo_cc_advanced_reports
4.0
siemensdesigo_cc_advanced_reports
4.1
siemensdesigo_cc_advanced_reports
4.2
siemensdesigo_cc_advanced_reports
5.0
siemensdesigo_cc_advanced_reports
5.1
siemensdesigo_cc_info_center
5.0
siemensdesigo_cc_info_center
5.1
siemense-car_operation_center
𝑥
< 2021-12-13
siemensenergy_engage
3.1
siemensenergyip
8.5
siemensenergyip
8.6
siemensenergyip
8.7
siemensenergyip
9.0
siemensenergyip_prepay
𝑥
< 3.8.0.12
siemensgma-manager
𝑥
< 8.6.2j-398
siemenshead-end_system_universal_device_integration_system
*
siemensindustrial_edge_management
*
siemensindustrial_edge_management_hub
𝑥
< 2021-12-13
siemenslogo\!_soft_comfort
*
siemensmendix
*
siemensmindsphere
𝑥
< 2021-12-16
siemensnavigator
𝑥
< 2021-12-13
siemensnx
*
siemensopcenter_intelligence
3.2 ≤
𝑥
< 3.5
siemensoperation_scheduler
𝑥
≤ 1.1.3
siemenssentron_powermanager
4.1
siemenssentron_powermanager
4.2
siemenssiguard_dsa
4.2 ≤
𝑥
< 4.4.1
siemenssipass_integrated
2.80
siemenssipass_integrated
2.85
siemenssiveillance_command
𝑥
≤ 4.16.2.1
siemenssiveillance_control_pro
*
siemenssiveillance_identity
1.5
siemenssiveillance_identity
1.6
siemenssiveillance_vantage
*
siemenssiveillance_viewpoint
*
siemenssolid_edge_cam_pro
*
siemenssolid_edge_harness_design
𝑥
< 2020
siemensspectrum_power_4
𝑥
< 4.70
siemensspectrum_power_4
4.70
siemensspectrum_power_4
4.70:sp7
siemensspectrum_power_4
4.70:sp8
siemensspectrum_power_7
𝑥
< 2.30
siemensspectrum_power_7
2.30
siemensspectrum_power_7
2.30
siemensspectrum_power_7
2.30:sp2
siemensteamcenter
*
siemensvesys
𝑥
< 2019.1
siemensvesys
2019.1
siemensvesys
2019.1
siemensvesys
2019.1:sp1912
siemensvesys
2020.1
siemensvesys
2021.1
siemensxpedition_enterprise
-
siemensxpedition_package_integrator
-
intelcomputer_vision_annotation_tool
-
inteldatacenter_manager
𝑥
< 5.1
intelgenomics_kernel_library
-
inteloneapi_sample_browser
-
intelsecure_device_onboard
-
intelsystem_studio
-
debiandebian_linux
9.0
debiandebian_linux
10.0
debiandebian_linux
11.0
sonicwallemail_security
𝑥
< 10.0.13
netappactive_iq_unified_manager
-
netappactive_iq_unified_manager
-
netappactive_iq_unified_manager
-
netappbrocade_san_navigator
-
netappcloud_insights
-
netappcloud_manager
-
netappcloud_secure_agent
-
netapponcommand_insight
-
netappontap_tools
-
netappsnapcenter
-
netappsolidfire_\&_hci_storage_node
-
netappsolidfire_enterprise_sds
-
ciscoadvanced_malware_protection_virtual_private_cloud_appliance
𝑥
< 3.5.4
ciscoautomated_subsea_tuning
𝑥
< 2.1.0
ciscobroadworks
𝑥
< 2021.11_1.162
ciscobusiness_process_automation
𝑥
< 3.0.000.115
ciscobusiness_process_automation
3.1.000.000 ≤
𝑥
< 3.1.000.044
ciscobusiness_process_automation
3.2.000.000 ≤
𝑥
< 3.2.000.009
ciscocloud_connect
𝑥
< 12.6\(1\)
ciscocloudcenter
𝑥
< 4.10.0.16
ciscocloudcenter_cost_optimizer
𝑥
< 5.5.2
ciscocloudcenter_suite_admin
𝑥
< 5.3.1
ciscocloudcenter_workload_manager
𝑥
< 5.5.2
ciscocommon_services_platform_collector
𝑥
< 2.9.1.3
ciscocommon_services_platform_collector
2.10.0 ≤
𝑥
< 2.10.0.1
ciscoconnected_mobile_experiences
-
ciscocontact_center_domain_manager
𝑥
< 12.5\(1\)
ciscocontact_center_management_portal
𝑥
< 12.5\(1\)
ciscocrosswork_data_gateway
𝑥
< 2.0.2
ciscocrosswork_data_gateway
3.0.0
ciscocrosswork_network_controller
𝑥
< 2.0.1
ciscocrosswork_network_controller
3.0.0
ciscocrosswork_optimization_engine
𝑥
< 2.0.1
ciscocrosswork_optimization_engine
3.0.0
ciscocrosswork_platform_infrastructure
𝑥
< 4.0.1
ciscocrosswork_platform_infrastructure
4.1.0
ciscocrosswork_zero_touch_provisioning
𝑥
< 2.0.1
ciscocrosswork_zero_touch_provisioning
3.0.0
ciscocustomer_experience_cloud_agent
𝑥
< 1.12.1
ciscocyber_vision_sensor_management_extension
𝑥
< 4.0.3
ciscodata_center_network_manager
𝑥
< 11.3\(1\)
ciscodata_center_network_manager
11.3\(1\)
ciscodna_center
𝑥
< 2.1.2.8
ciscodna_center
2.2.2.0 ≤
𝑥
< 2.2.2.8
ciscodna_center
2.2.3.0 ≤
𝑥
< 2.2.3.4
ciscodna_spaces\
𝑥
< 2.5
ciscoemergency_responder
𝑥
< 11.5\(4\)
ciscoenterprise_chat_and_email
𝑥
< 12.0\(1\)
ciscoevolved_programmable_network_manager
𝑥
≤ 4.1.1
ciscofinesse
𝑥
< 12.6\(1\)
ciscofinesse
12.6\(1\)
ciscofog_director
-
ciscoidentity_services_engine
𝑥
< 2.4.0
ciscoidentity_services_engine
2.4.0
ciscointegrated_management_controller_supervisor
𝑥
< 2.3.2.1
ciscointersight_virtual_appliance
𝑥
< 1.0.9-361
ciscoiot_operations_dashboard
-
cisconetwork_assurance_engine
𝑥
< 6.0.2
cisconetwork_services_orchestrator
𝑥
< 5.3.5.1
cisconetwork_services_orchestrator
5.4 ≤
𝑥
< 5.4.5.2
cisconetwork_services_orchestrator
5.5 ≤
𝑥
< 5.5.4.1
cisconetwork_services_orchestrator
5.6 ≤
𝑥
< 5.6.3.1
cisconexus_dashboard
𝑥
< 2.1.2
cisconexus_insights
𝑥
< 6.0.2
ciscooptical_network_controller
𝑥
< 1.1.0
ciscopackaged_contact_center_enterprise
𝑥
< 11.6
ciscopackaged_contact_center_enterprise
11.6\(1\)
ciscopaging_server
𝑥
< 14.4.1
ciscoprime_service_catalog
𝑥
< 12.1
ciscosd-wan_vmanage
𝑥
< 20.3.4.1
ciscosd-wan_vmanage
20.4 ≤
𝑥
< 20.4.2.1
ciscosd-wan_vmanage
20.5 ≤
𝑥
< 20.5.1.1
ciscosd-wan_vmanage
20.6 ≤
𝑥
< 20.6.2.1
ciscosmart_phy
𝑥
< 3.2.1
ciscoucs_central
𝑥
< 2.0\(1p\)
ciscoucs_director
𝑥
< 6.8.2.0
ciscounified_communications_manager
𝑥
< 11.5\(1\)
ciscounified_communications_manager
𝑥
< 11.5\(1\)
ciscounified_communications_manager
11.5\(1\)
ciscounified_communications_manager
11.5\(1\)
ciscounified_communications_manager
11.5\(1\)
ciscounified_communications_manager
11.5\(1\)su3
ciscounified_communications_manager_im_and_presence_service
𝑥
< 11.5\(1\)
ciscounified_communications_manager_im_and_presence_service
11.5\(1\)
ciscounified_contact_center_enterprise
𝑥
< 11.6\(2\)
ciscounified_contact_center_enterprise
11.6\(2\)
ciscounified_contact_center_express
𝑥
< 12.5\(1\)
ciscounified_customer_voice_portal
𝑥
< 11.6
ciscounified_customer_voice_portal
11.6
ciscounified_customer_voice_portal
12.0
ciscounified_customer_voice_portal
12.5
ciscounity_connection
𝑥
< 11.5\(1\)
ciscovideo_surveillance_operations_manager
𝑥
< 7.14.4
ciscovirtual_topology_system
𝑥
< 2.6.7
ciscovirtualized_infrastructure_manager
𝑥
< 3.2.0
ciscovirtualized_infrastructure_manager
3.4.0 ≤
𝑥
< 3.4.4
ciscovirtualized_voice_browser
𝑥
< 12.5\(1\)
ciscowan_automation_engine
𝑥
< 7.3.0.2
ciscowebex_meetings_server
𝑥
< 3.0
ciscowebex_meetings_server
3.0
ciscowebex_meetings_server
3.0:maintenance_release1
ciscowebex_meetings_server
3.0:maintenance_release2
ciscowebex_meetings_server
3.0:maintenance_release3
ciscowebex_meetings_server
3.0:maintenance_release3
ciscowebex_meetings_server
3.0:maintenance_release3_security_patch4
ciscowebex_meetings_server
3.0:maintenance_release3_security_patch5
ciscowebex_meetings_server
3.0:maintenance_release3_service_pack_2
ciscowebex_meetings_server
3.0:maintenance_release3_service_pack_3
ciscowebex_meetings_server
3.0:maintenance_release4
ciscowebex_meetings_server
4.0
ciscowebex_meetings_server
4.0:maintenance_release1
ciscowebex_meetings_server
4.0:maintenance_release2
ciscowebex_meetings_server
4.0:maintenance_release3
ciscoworkload_optimization_manager
𝑥
< 3.2.1
ciscounified_intelligence_center
𝑥
< 12.6\(1\)
ciscounified_sip_proxy
𝑥
< 10.2.1v2
ciscounified_workforce_optimization
𝑥
< 11.5\(1\)
ciscofxos
6.2.3
ciscofxos
6.3.0
ciscofxos
6.4.0
ciscofxos
6.5.0
ciscofxos
6.6.0
ciscofxos
6.7.0
ciscofxos
7.0.0
ciscofxos
7.1.0
ciscoautomated_subsea_tuning
02.01.00
ciscobroadworks
-
ciscocloudcenter_suite
4.10\(0.15\)
ciscocloudcenter_suite
5.3\(0\)
ciscocloudcenter_suite
5.4\(1\)
ciscocloudcenter_suite
5.5\(0\)
ciscocloudcenter_suite
5.5\(1\)
ciscocommon_services_platform_collector
002.009\(000.000\)
ciscocommon_services_platform_collector
002.009\(000.001\)
ciscocommon_services_platform_collector
002.009\(000.002\)
ciscocommon_services_platform_collector
002.009\(001.000\)
ciscocommon_services_platform_collector
002.009\(001.001\)
ciscocommon_services_platform_collector
002.009\(001.002\)
ciscocommon_services_platform_collector
002.010\(000.000\)
ciscoconnected_analytics_for_network_deployment
006.004.000.003
ciscoconnected_analytics_for_network_deployment
006.005.000.
ciscoconnected_analytics_for_network_deployment
006.005.000.000
ciscoconnected_analytics_for_network_deployment
007.000.001
ciscoconnected_analytics_for_network_deployment
007.001.000
ciscoconnected_analytics_for_network_deployment
007.002.000
ciscoconnected_analytics_for_network_deployment
7.3
ciscoconnected_analytics_for_network_deployment
007.003.000
ciscoconnected_analytics_for_network_deployment
007.003.001.001
ciscoconnected_analytics_for_network_deployment
007.003.003
ciscoconnected_analytics_for_network_deployment
008.000.000
ciscoconnected_analytics_for_network_deployment
008.000.000.000.004
ciscocrosswork_network_automation
-
ciscocrosswork_network_automation
2.0.0
ciscocrosswork_network_automation
3.0.0
ciscocrosswork_network_automation
4.1.0
ciscocrosswork_network_automation
4.1.1
ciscocx_cloud_agent
001.012
ciscocyber_vision
4.0.2
ciscocyber_vision_sensor_management_extension
4.0.2
ciscodna_center
2.2.2.8
ciscodna_spaces
-
ciscodna_spaces_connector
-
ciscoemergency_responder
11.5
ciscoemergency_responder
11.5\(4.65000.14\)
ciscoemergency_responder
11.5\(4.66000.14\)
ciscoenterprise_chat_and_email
12.0\(1\)
ciscoenterprise_chat_and_email
12.5\(1\)
ciscoenterprise_chat_and_email
12.6\(1\)
ciscoevolved_programmable_network_manager
3.0
ciscoevolved_programmable_network_manager
3.1
ciscoevolved_programmable_network_manager
4.0
ciscoevolved_programmable_network_manager
4.1
ciscoevolved_programmable_network_manager
5.0
ciscoevolved_programmable_network_manager
5.1
ciscofinesse
12.5\(1\):su1
ciscofinesse
12.5\(1\):su2
ciscofinesse
12.6\(1\)
ciscofinesse
12.6\(1\):es01
ciscofinesse
12.6\(1\):es02
ciscofinesse
12.6\(1\):es03
ciscofirepower_threat_defense
6.2.3
ciscofirepower_threat_defense
6.3.0
ciscofirepower_threat_defense
6.4.0
ciscofirepower_threat_defense
6.5.0
ciscofirepower_threat_defense
6.6.0
ciscofirepower_threat_defense
6.7.0
ciscofirepower_threat_defense
7.0.0
ciscofirepower_threat_defense
7.1.0
ciscoidentity_services_engine
002.004\(000.914\)
ciscoidentity_services_engine
002.006\(000.156\)
ciscoidentity_services_engine
002.007\(000.356\)
ciscoidentity_services_engine
003.000\(000.458\)
ciscoidentity_services_engine
003.001\(000.518\)
ciscoidentity_services_engine
003.002\(000.116\)
ciscointegrated_management_controller_supervisor
002.003\(002.000\)
ciscointegrated_management_controller_supervisor
2.3.2.0
ciscointersight_virtual_appliance
1.0.9-343
ciscomobility_services_engine
-
cisconetwork_assurance_engine
6.0\(2.1912\)
cisconetwork_dashboard_fabric_controller
11.0\(1\)
cisconetwork_dashboard_fabric_controller
11.1\(1\)
cisconetwork_dashboard_fabric_controller
11.2\(1\)
cisconetwork_dashboard_fabric_controller
11.3\(1\)
cisconetwork_dashboard_fabric_controller
11.4\(1\)
cisconetwork_dashboard_fabric_controller
11.5\(1\)
cisconetwork_dashboard_fabric_controller
11.5\(2\)
cisconetwork_dashboard_fabric_controller
11.5\(3\)
cisconetwork_insights_for_data_center
6.0\(2.1914\)
cisconetwork_services_orchestrator
-
ciscooptical_network_controller
1.1
ciscopaging_server
8.3\(1\)
ciscopaging_server
8.4\(1\)
ciscopaging_server
8.5\(1\)
ciscopaging_server
9.0\(1\)
ciscopaging_server
9.0\(2\)
ciscopaging_server
9.1\(1\)
ciscopaging_server
12.5\(2\)
ciscopaging_server
14.0\(1\)
ciscoprime_service_catalog
12.1
ciscosd-wan_vmanage
20.3
ciscosd-wan_vmanage
20.4
ciscosd-wan_vmanage
20.5
ciscosd-wan_vmanage
20.6
ciscosd-wan_vmanage
20.6.1
ciscosd-wan_vmanage
20.7
ciscosd-wan_vmanage
20.8
ciscosmart_phy
3.1.2
ciscosmart_phy
3.1.3
ciscosmart_phy
3.1.4
ciscosmart_phy
3.1.5
ciscosmart_phy
3.2.1
ciscosmart_phy
21.3
ciscoucs_central_software
2.0
ciscoucs_central_software
2.0\(1a\)
ciscoucs_central_software
2.0\(1b\)
ciscoucs_central_software
2.0\(1c\)
ciscoucs_central_software
2.0\(1d\)
ciscoucs_central_software
2.0\(1e\)
ciscoucs_central_software
2.0\(1f\)
ciscoucs_central_software
2.0\(1g\)
ciscoucs_central_software
2.0\(1h\)
ciscoucs_central_software
2.0\(1k\)
ciscoucs_central_software
2.0\(1l\)
ciscounified_communications_manager
11.5\(1.17900.52\)
ciscounified_communications_manager
11.5\(1.18119.2\)
ciscounified_communications_manager
11.5\(1.18900.97\)
ciscounified_communications_manager
11.5\(1.21900.40\)
ciscounified_communications_manager
11.5\(1.22900.28\)
ciscounified_communications_manager_im_\&_presence_service
11.5\(1\)
ciscounified_communications_manager_im_\&_presence_service
11.5\(1.22900.6\)
ciscounified_computing_system
006.008\(001.000\)
ciscounified_contact_center_enterprise
11.6\(2\)
ciscounified_contact_center_enterprise
12.0\(1\)
ciscounified_contact_center_enterprise
12.5\(1\)
ciscounified_contact_center_enterprise
12.6\(1\)
ciscounified_contact_center_enterprise
12.6\(2\)
ciscounified_contact_center_express
12.5\(1\)
ciscounified_contact_center_express
12.5\(1\):su1
ciscounified_contact_center_express
12.6\(1\)
ciscounified_contact_center_express
12.6\(2\)
ciscounified_contact_center_management_portal
12.6\(1\)
ciscounified_customer_voice_portal
11.6\(1\)
ciscounified_customer_voice_portal
12.0\(1\)
ciscounified_customer_voice_portal
12.5\(1\)
ciscounified_customer_voice_portal
12.6\(1\)
ciscounified_intelligence_center
12.6\(1\)
ciscounified_intelligence_center
12.6\(1\):es01
ciscounified_intelligence_center
12.6\(1\):es02
ciscounified_intelligence_center
12.6\(2\)
ciscounified_sip_proxy
010.000\(000\)
ciscounified_sip_proxy
010.000\(001\)
ciscounified_sip_proxy
010.002\(000\)
ciscounified_sip_proxy
010.002\(001\)
ciscounified_workforce_optimization
11.5\(1\):sr7
ciscounity_connection
11.5
ciscounity_connection
11.5\(1.10000.6\)
ciscovideo_surveillance_manager
7.14\(1.26\)
ciscovideo_surveillance_manager
7.14\(2.26\)
ciscovideo_surveillance_manager
7.14\(3.025\)
ciscovideo_surveillance_manager
7.14\(4.018\)
ciscovirtual_topology_system
2.6.6
ciscowan_automation_engine
7.1.3
ciscowan_automation_engine
7.2.1
ciscowan_automation_engine
7.2.2
ciscowan_automation_engine
7.2.3
ciscowan_automation_engine
7.3
ciscowan_automation_engine
7.4
ciscowan_automation_engine
7.5
ciscowan_automation_engine
7.6
ciscowebex_meetings_server
3.0
ciscowebex_meetings_server
4.0
snowsoftwaresnow_commander
𝑥
< 8.10.0
snowsoftwarevm_access_proxy
𝑥
< 3.6
bentleysynchro
6.1 ≤
𝑥
< 6.2.4.2
bentleysynchro_4d
𝑥
< 6.4.3.2
percussionrhythmyx
𝑥
≤ 7.3.2
applexcode
𝑥
< 13.3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
apache-log4j1.2
bullseye
1.2.17-10+deb11u1
fixed
bookworm
1.2.17-11
fixed
sid
1.2.17-11
fixed
trixie
1.2.17-11
fixed
apache-log4j2
bullseye
2.17.1-1~deb11u1
fixed
bullseye (security)
2.17.0-1~deb11u1
fixed
bookworm
2.19.0-2
fixed
sid
2.19.0-2
fixed
trixie
2.19.0-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
apache-log4j2
jammy
not-affected
impish
Fixed 2.15.0-0.21.10.1
released
hirsute
Fixed 2.15.0-0.21.04.1
released
focal
Fixed 2.15.0-0.20.04.1
released
bionic
Fixed 2.10.0-2ubuntu0.1
released
xenial
Fixed 2.4-2ubuntu0.1~esm1
released
trusty
dne
References