CVE-2021-45105
18.12.2021, 12:15
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.Enginsight
Vendor | Product | Version |
---|---|---|
apache | log4j | 2.0 ≤ 𝑥 < 2.3.1 |
apache | log4j | 2.4 ≤ 𝑥 < 2.12.3 |
apache | log4j | 2.13.0 ≤ 𝑥 ≤ 2.16.0 |
netapp | cloud_manager | - |
debian | debian_linux | 10.0 |
debian | debian_linux | 11.0 |
sonicwall | email_security | 𝑥 ≤ 10.0.12 |
sonicwall | network_security_manager | 2.0 ≤ 𝑥 < 3.0 |
sonicwall | network_security_manager | 2.0 ≤ 𝑥 < 3.0 |
sonicwall | web_application_firewall | 3.0.0 ≤ 𝑥 < 3.1.0 |
sonicwall | 6bk1602-0aa12-0tp0_firmware | 𝑥 < 2.7.0 |
sonicwall | 6bk1602-0aa22-0tp0_firmware | 𝑥 < 2.7.0 |
sonicwall | 6bk1602-0aa32-0tp0_firmware | 𝑥 < 2.7.0 |
sonicwall | 6bk1602-0aa42-0tp0_firmware | 𝑥 < 2.7.0 |
sonicwall | 6bk1602-0aa52-0tp0_firmware | 𝑥 < 2.7.0 |
oracle | agile_engineering_data_management | 6.2.1.0 |
oracle | agile_plm | 9.3.6 |
oracle | agile_plm_mcad_connector | 3.6 |
oracle | autovue_for_agile_product_lifecycle_management | 21.0.2 |
oracle | banking_deposits_and_lines_of_credit_servicing | 2.12.0 |
oracle | banking_enterprise_default_management | 2.7.1 |
oracle | banking_enterprise_default_management | 2.12.0 |
oracle | banking_loans_servicing | 2.12.0 |
oracle | banking_party_management | 2.7.0 |
oracle | banking_payments | 14.5 |
oracle | banking_platform | 2.6.2 |
oracle | banking_platform | 2.7.1 |
oracle | banking_platform | 2.12.0 |
oracle | banking_trade_finance | 14.5 |
oracle | banking_treasury_management | 14.5 |
oracle | business_intelligence | 5.5.0.0.0 |
oracle | communications_asap | 7.3 |
oracle | communications_billing_and_revenue_management | 12.0.0.4 |
oracle | communications_billing_and_revenue_management | 12.0.0.5 |
oracle | communications_cloud_native_core_console | 1.9.0 |
oracle | communications_cloud_native_core_network_function_cloud_native_environment | 1.10.0 |
oracle | communications_cloud_native_core_network_repository_function | 1.15.0 |
oracle | communications_cloud_native_core_network_repository_function | 1.15.1 |
oracle | communications_cloud_native_core_network_slice_selection_function | 1.8.0 |
oracle | communications_cloud_native_core_policy | 1.15.0 |
oracle | communications_cloud_native_core_security_edge_protection_proxy | 1.7.0 |
oracle | communications_cloud_native_core_service_communication_proxy | 1.15.0 |
oracle | communications_cloud_native_core_unified_data_repository | 1.15.0 |
oracle | communications_convergence | 3.0.2.2.0 |
oracle | communications_convergence | 3.0.3.0 |
oracle | communications_convergent_charging_controller | 12.0.1.0.0 ≤ 𝑥 ≤ 12.0.4.0.0 |
oracle | communications_convergent_charging_controller | 6.0.1.0.0 |
oracle | communications_diameter_signaling_router | 8.3.0.0 ≤ 𝑥 ≤ 8.5.1.0 |
oracle | communications_eagle_element_management_system | 46.6 |
oracle | communications_eagle_ftp_table_base_retrieval | 4.5 |
oracle | communications_element_manager | 𝑥 < 9.0 |
oracle | communications_evolved_communications_application_server | 7.1 |
oracle | communications_interactive_session_recorder | 6.3 |
oracle | communications_interactive_session_recorder | 6.4 |
oracle | communications_ip_service_activator | 7.4.0 |
oracle | communications_messaging_server | 8.1 |
oracle | communications_network_charging_and_control | 12.0.1.0.0 ≤ 𝑥 ≤ 12.0.4.0.0 |
oracle | communications_network_charging_and_control | 6.0.1.0.0 |
oracle | communications_network_integrity | 7.3.6 |
oracle | communications_performance_intelligence_center | 10.4.0.3 |
oracle | communications_pricing_design_center | 12.0.0.4 |
oracle | communications_pricing_design_center | 12.0.0.5 |
oracle | communications_service_broker | 6.2 |
oracle | communications_services_gatekeeper | 7.0 |
oracle | communications_session_report_manager | 𝑥 < 9.0 |
oracle | communications_session_route_manager | 𝑥 < 9.0 |
oracle | communications_unified_inventory_management | 7.3.5 |
oracle | communications_unified_inventory_management | 7.4.1 |
oracle | communications_unified_inventory_management | 7.4.2 |
oracle | communications_user_data_repository | 12.4 |
oracle | communications_webrtc_session_controller | 7.2.0.0 |
oracle | communications_webrtc_session_controller | 7.2.1 |
oracle | data_integrator | 12.2.1.3.0 |
oracle | data_integrator | 12.2.1.4.0 |
oracle | e-business_suite | 12.2 |
oracle | enterprise_manager_base_platform | 13.4.0.0 |
oracle | enterprise_manager_base_platform | 13.5.0.0 |
oracle | enterprise_manager_for_peoplesoft | 13.4.1.1 |
oracle | enterprise_manager_for_peoplesoft | 13.5.1.1 |
oracle | enterprise_manager_ops_center | 12.4.0.0 |
oracle | financial_services_analytical_applications_infrastructure | 8.0.7 ≤ 𝑥 ≤ 8.1.1 |
oracle | financial_services_model_management_and_governance | 8.0.8.0.0 |
oracle | financial_services_model_management_and_governance | 8.1.0.0.0 |
oracle | financial_services_model_management_and_governance | 8.1.1.0.0 |
oracle | flexcube_universal_banking | 12.1.0 ≤ 𝑥 ≤ 12.4 |
oracle | flexcube_universal_banking | 14.0.0 ≤ 𝑥 ≤ 14.3.0 |
oracle | flexcube_universal_banking | 11.83.3 |
oracle | flexcube_universal_banking | 14.5 |
oracle | health_sciences_empirica_signal | 9.1.0.6 |
oracle | health_sciences_empirica_signal | 9.2.0.0 |
oracle | health_sciences_inform | 6.2.1.1 |
oracle | health_sciences_inform | 6.3.2.1 |
oracle | health_sciences_inform | 7.0.0.0 |
oracle | health_sciences_information_manager | 3.0.1 ≤ 𝑥 ≤ 3.0.4 |
oracle | healthcare_data_repository | 8.1.1 |
oracle | healthcare_foundation | 7.3.0.1 ≤ 𝑥 ≤ 7.3.0.4 |
oracle | healthcare_master_person_index | 5.0.1 |
oracle | healthcare_translational_research | 4.1.0 |
oracle | healthcare_translational_research | 4.1.1 |
oracle | hospitality_suite8 | 8.13.0 |
oracle | hospitality_suite8 | 8.14.0 |
oracle | hospitality_token_proxy_service | 19.2 |
oracle | hyperion_bi\+ | 𝑥 < 11.2.8.0 |
oracle | hyperion_data_relationship_management | 𝑥 < 11.2.8.0 |
oracle | hyperion_infrastructure_technology | 𝑥 < 11.2.8.0 |
oracle | hyperion_planning | 𝑥 < 11.2.8.0 |
oracle | hyperion_profitability_and_cost_management | 𝑥 < 11.2.8.0 |
oracle | hyperion_tax_provision | 𝑥 < 11.2.8.0 |
oracle | identity_management_suite | 12.2.1.3.0 |
oracle | identity_management_suite | 12.2.1.4.0 |
oracle | identity_manager_connector | 9.1.0 |
oracle | instantis_enterprisetrack | 17.1 |
oracle | instantis_enterprisetrack | 17.2 |
oracle | instantis_enterprisetrack | 17.3 |
oracle | insurance_data_gateway | 1.0.1 |
oracle | insurance_insbridge_rating_and_underwriting | 5.4 ≤ 𝑥 ≤ 5.6.0.0 |
oracle | insurance_insbridge_rating_and_underwriting | 5.2.0 |
oracle | insurance_insbridge_rating_and_underwriting | 5.6.1.0 |
oracle | jdeveloper | 12.2.1.4.0 |
oracle | managed_file_transfer | 12.2.1.3.0 |
oracle | managed_file_transfer | 12.2.1.4.0 |
oracle | management_cloud_engine | 1.5.0 |
oracle | mysql_enterprise_monitor | 𝑥 ≤ 8.0.29 |
oracle | payment_interface | 19.1 |
oracle | payment_interface | 20.3 |
oracle | peoplesoft_enterprise_peopletools | 8.58 |
oracle | peoplesoft_enterprise_peopletools | 8.59 |
oracle | primavera_gateway | 17.12.0 ≤ 𝑥 ≤ 17.12.11 |
oracle | primavera_gateway | 18.8.0 ≤ 𝑥 ≤ 18.8.13 |
oracle | primavera_gateway | 19.12.0 ≤ 𝑥 ≤ 19.12.12 |
oracle | primavera_gateway | 20.12.0 ≤ 𝑥 ≤ 20.12.7 |
oracle | primavera_gateway | 21.12.0 |
oracle | primavera_p6_enterprise_project_portfolio_management | 19.12.0.0 ≤ 𝑥 ≤ 19.12.18.0 |
oracle | primavera_p6_enterprise_project_portfolio_management | 20.12.0.0 ≤ 𝑥 ≤ 20.12.12.0 |
oracle | primavera_p6_enterprise_project_portfolio_management | 21.12.0.0 |
oracle | primavera_unifier | 18.8 |
oracle | primavera_unifier | 19.12 |
oracle | primavera_unifier | 20.12 |
oracle | primavera_unifier | 21.12 |
oracle | retail_back_office | 14.1 |
oracle | retail_central_office | 14.1 |
oracle | retail_customer_insights | 15.0.2 |
oracle | retail_customer_insights | 16.0.2 |
oracle | retail_data_extractor_for_merchandising | 15.0.2 |
oracle | retail_data_extractor_for_merchandising | 16.0.2 |
oracle | retail_eftlink | 16.0.3 |
oracle | retail_eftlink | 17.0.2 |
oracle | retail_eftlink | 18.0.1 |
oracle | retail_eftlink | 19.0.1 |
oracle | retail_eftlink | 20.0.1 |
oracle | retail_eftlink | 21.0.0 |
oracle | retail_financial_integration | 16.0.1 ≤ 𝑥 ≤ 16.0.3 |
oracle | retail_financial_integration | 14.1.3.2 |
oracle | retail_financial_integration | 15.0.3.1 |
oracle | retail_financial_integration | 19.0.0 |
oracle | retail_financial_integration | 19.0.1 |
oracle | retail_integration_bus | 16.0.1 ≤ 𝑥 ≤ 16.0.3 |
oracle | retail_integration_bus | 19.0.0 ≤ 𝑥 ≤ 19.0.1.0 |
oracle | retail_integration_bus | 14.1.3 |
oracle | retail_integration_bus | 14.1.3.2 |
oracle | retail_integration_bus | 15.0.3.1 |
oracle | retail_integration_bus | 19.0.0 |
oracle | retail_integration_bus | 19.0.1 |
oracle | retail_invoice_matching | 15.0.3 |
oracle | retail_invoice_matching | 16.0.3 |
oracle | retail_merchandising_system | 16.0.3 |
oracle | retail_merchandising_system | 19.0.1 |
oracle | retail_order_broker | 16.0 |
oracle | retail_order_broker | 18.0 |
oracle | retail_order_broker | 19.1 |
oracle | retail_order_management_system | 19.5 |
oracle | retail_point-of-service | 14.1 |
oracle | retail_predictive_application_server | 14.1.3.46 |
oracle | retail_predictive_application_server | 15.0.3.115 |
oracle | retail_predictive_application_server | 16.0.3.240 |
oracle | retail_price_management | 13.2 |
oracle | retail_price_management | 14.0.4 |
oracle | retail_price_management | 14.1.3.0 |
oracle | retail_price_management | 15.0.3.0 |
oracle | retail_price_management | 16.0.3.0 |
oracle | retail_returns_management | 14.1 |
oracle | retail_service_backbone | 16.0.1 ≤ 𝑥 ≤ 16.0.3 |
oracle | retail_service_backbone | 14.1.3 |
oracle | retail_service_backbone | 14.1.3.2 |
oracle | retail_service_backbone | 15.0.3.1 |
oracle | retail_service_backbone | 19.0.0 |
oracle | retail_service_backbone | 19.0.1 |
oracle | retail_service_backbone | 19.0.1.0 |
oracle | retail_store_inventory_management | 14.0.4.13 |
oracle | retail_store_inventory_management | 14.1.3.5 |
oracle | retail_store_inventory_management | 14.1.3.14 |
oracle | retail_store_inventory_management | 15.0.3.3 |
oracle | retail_store_inventory_management | 15.0.3.8 |
oracle | retail_store_inventory_management | 16.0.3.7 |
oracle | siebel_ui_framework | 𝑥 ≤ 21.12 |
oracle | sql_developer | 𝑥 < 21.4.2 |
oracle | taleo_platform | 𝑥 < 22.1 |
oracle | utilities_framework | 4.3.0.1.0 ≤ 𝑥 ≤ 4.3.0.6.0 |
oracle | utilities_framework | 4.4.0.0.0 |
oracle | utilities_framework | 4.4.0.2.0 |
oracle | utilities_framework | 4.4.0.3.0 |
oracle | webcenter_portal | 12.2.1.3.0 |
oracle | webcenter_portal | 12.2.1.4.0 |
oracle | webcenter_sites | 12.2.1.3.0 |
oracle | webcenter_sites | 12.2.1.4.0 |
oracle | weblogic_server | 12.2.1.3.0 |
oracle | weblogic_server | 12.2.1.4.0 |
oracle | weblogic_server | 14.1.1.0.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration