CVE-2021-44228
Last modified
CVE-2021-44228 is a critical-severity vulnerability rated 10/10 on the CVSS scale. Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. CISA has confirmed active exploitation in the wild. EPSS estimates a 100.00% chance of exploitation in the next 30 days.
Description
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
100.0th percentile
Probability of exploitation in the next 30 days. Learn more
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Siemens | 6bk1602-0aa12-0tp0 Firmware | < 2.7.0 | — |
| Siemens | 6bk1602-0aa22-0tp0 Firmware | < 2.7.0 | — |
| Siemens | 6bk1602-0aa32-0tp0 Firmware | < 2.7.0 | — |
| Siemens | 6bk1602-0aa42-0tp0 Firmware | < 2.7.0 | — |
| Siemens | 6bk1602-0aa52-0tp0 Firmware | < 2.7.0 | — |
| Apache | Log4j | >= 2.0.1, < 2.3.1 | — |
| Apache | Log4j | >= 2.4.0, < 2.12.2 | — |
| Apache | Log4j | >= 2.13.0, < 2.15.0 | — |
| Apache | Log4j | 2.0 | — |
| Siemens | Sppa-T3000 Ses3000 Firmware | All versions | — |
| Siemens | Capital | < 2019.1 | — |
| Siemens | Capital | 2019.1 | — |
| Siemens | Comos | < 10.4.2 | — |
| Siemens | Desigo Cc Advanced Reports | 3.0 | — |
| Siemens | Desigo Cc Advanced Reports | 4.0 | — |
| Siemens | Desigo Cc Advanced Reports | 4.1 | — |
| Siemens | Desigo Cc Advanced Reports | 4.2 | — |
| Siemens | Desigo Cc Advanced Reports | 5.0 | — |
| Siemens | Desigo Cc Advanced Reports | 5.1 | — |
| Siemens | Desigo Cc Info Center | 5.0 | — |
| Siemens | Desigo Cc Info Center | 5.1 | — |
| Siemens | E-Car Operation Center | < 2021-12-13 | — |
| Siemens | Energy Engage | 3.1 | — |
| Siemens | Energyip | 8.5 | — |
| Siemens | Energyip | 8.6 | — |
| Siemens | Energyip | 8.7 | — |
| Siemens | Energyip | 9.0 | — |
| Siemens | Energyip Prepay | < 3.8.0.12 | — |
| Siemens | Gma-Manager | < 8.6.2j-398 | — |
| Siemens | Head-End System Universal Device Integration System | All versions | — |
| Siemens | Industrial Edge Management | All versions | — |
| Siemens | Industrial Edge Management Hub | < 2021-12-13 | — |
| Siemens | Logo\! Soft Comfort | All versions | — |
| Siemens | Mendix | All versions | — |
| Siemens | Mindsphere | < 2021-12-16 | — |
| Siemens | Navigator | < 2021-12-13 | — |
| Siemens | Nx | All versions | — |
| Siemens | Opcenter Intelligence | >= 3.2, < 3.5 | — |
| Siemens | Operation Scheduler | <= 1.1.3 | — |
| Siemens | Sentron Powermanager | 4.1 | — |
| Siemens | Sentron Powermanager | 4.2 | — |
| Siemens | Siguard Dsa | >= 4.2, < 4.4.1 | — |
| Siemens | Sipass Integrated | 2.80 | — |
| Siemens | Sipass Integrated | 2.85 | — |
| Siemens | Siveillance Command | <= 4.16.2.1 | — |
| Siemens | Siveillance Control Pro | All versions | — |
| Siemens | Siveillance Identity | 1.5 | — |
| Siemens | Siveillance Identity | 1.6 | — |
| Siemens | Siveillance Vantage | All versions | — |
| Siemens | Siveillance Viewpoint | All versions | — |
Showing 50 of 333 affected configurations. See NVD for the full list.
References
- http://packetstormsecurity.com/files/165225/Apache-Log4j2-2.14.1-Remote-Code-Execution.htmlThird Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/165260/VMware-Security-Advisory-2021-0028.htmlThird Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/165261/Apache-Log4j2-2.14.1-Information-Disclosure.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/165270/Apache-Log4j2-2.14.1-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/165281/Log4j2-Log4Shell-Regexes.htmlThird Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/165282/Log4j-Payload-Generator.htmlThird Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/165306/L4sh-Log4j-Remote-Code-Execution.htmlThird Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/165307/Log4j-Remote-Code-Execution-Word-Bypassing.htmlThird Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/165311/log4j-scan-Extensive-Scanner.htmlBroken Link, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/165371/VMware-Security-Advisory-2021-0028.4.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/165532/Log4Shell-HTTP-Header-Injection.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/165642/VMware-vCenter-Server-Unauthenticated-Log4Shell-JNDI-Injection-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/165673/UniFi-Network-Application-Unauthenticated-Log4Shell-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/167794/Open-Xchange-App-Suite-7.10.x-Cross-Site-Scripting-Command-Injection.htmlThird Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/167917/MobileIron-Log4Shell-Remote-Command-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/171626/AD-Manager-Plus-7122-Remote-Code-Execution.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2022/Dec/2Exploit, Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2022/Jul/11Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2022/Mar/23Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2021/12/10/1Mailing List, Mitigation, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2021/12/10/2Mailing List, Mitigation, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2021/12/10/3Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2021/12/13/1Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2021/12/13/2Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2021/12/14/4Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2021/12/15/3Mailing List, Third Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-397453.pdfThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-479842.pdfThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-661247.pdfThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-714170.pdfThird Party Advisory
- https://github.com/cisagov/log4j-affected-dbThird Party Advisory
- https://github.com/cisagov/log4j-affected-db/blob/develop/SOFTWARE-LIST.mdBroken Link, Product, US Government Resource
- https://github.com/nu11secur1ty/CVE-mitre/tree/main/CVE-2021-44228Exploit, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/12/msg00007.htmlMailing List, Third Party Advisory
- https://logging.apache.org/log4j/2.x/security.htmlRelease Notes, Vendor Advisory
- https://msrc-blog.microsoft.com/2021/12/11/microsofts-response-to-cve-2021-44228-apache-log4j2/Patch, Third Party Advisory, Vendor Advisory
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0032Third Party Advisory
- https://security.netapp.com/advisory/ntap-20211210-0007/Third Party Advisory
- https://support.apple.com/kb/HT213189Third Party Advisory
- https://twitter.com/kurtseifried/status/1469345530182455296Broken Link, Exploit, Third Party Advisory
- https://www.bentley.com/en/common-vulnerability-exposure/be-2022-0001Third Party Advisory
- https://www.debian.org/security/2021/dsa-5020Mailing List, Third Party Advisory
- https://www.kb.cert.org/vuls/id/930724Third Party Advisory, US Government Resource
- https://www.nu11secur1ty.com/2021/12/cve-2021-44228.htmlExploit, Third Party Advisory
- https://www.oracle.com/security-alerts/alert-cve-2021-44228.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.htmlPatch, Third Party Advisory
- http://packetstormsecurity.com/files/165225/Apache-Log4j2-2.14.1-Remote-Code-Execution.htmlThird Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/165260/VMware-Security-Advisory-2021-0028.htmlThird Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/165261/Apache-Log4j2-2.14.1-Information-Disclosure.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/165270/Apache-Log4j2-2.14.1-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/165281/Log4j2-Log4Shell-Regexes.htmlThird Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/165282/Log4j-Payload-Generator.htmlThird Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/165306/L4sh-Log4j-Remote-Code-Execution.htmlThird Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/165307/Log4j-Remote-Code-Execution-Word-Bypassing.htmlThird Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/165311/log4j-scan-Extensive-Scanner.htmlBroken Link, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/165371/VMware-Security-Advisory-2021-0028.4.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/165532/Log4Shell-HTTP-Header-Injection.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/165642/VMware-vCenter-Server-Unauthenticated-Log4Shell-JNDI-Injection-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/165673/UniFi-Network-Application-Unauthenticated-Log4Shell-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/167794/Open-Xchange-App-Suite-7.10.x-Cross-Site-Scripting-Command-Injection.htmlThird Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/167917/MobileIron-Log4Shell-Remote-Command-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/171626/AD-Manager-Plus-7122-Remote-Code-Execution.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2022/Dec/2Exploit, Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2022/Jul/11Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2022/Mar/23Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2021/12/10/1Mailing List, Mitigation, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2021/12/10/2Mailing List, Mitigation, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2021/12/10/3Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2021/12/13/1Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2021/12/13/2Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2021/12/14/4Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2021/12/15/3Mailing List, Third Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-397453.pdfThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-479842.pdfThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-661247.pdfThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-714170.pdfThird Party Advisory
- https://github.com/cisagov/log4j-affected-dbThird Party Advisory
- https://github.com/cisagov/log4j-affected-db/blob/develop/SOFTWARE-LIST.mdBroken Link, Product, US Government Resource
- https://github.com/nu11secur1ty/CVE-mitre/tree/main/CVE-2021-44228Exploit, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/12/msg00007.htmlMailing List, Third Party Advisory
- https://logging.apache.org/log4j/2.x/security.htmlRelease Notes, Vendor Advisory
- https://msrc-blog.microsoft.com/2021/12/11/microsofts-response-to-cve-2021-44228-apache-log4j2/Patch, Third Party Advisory, Vendor Advisory
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0032Third Party Advisory
- https://security.netapp.com/advisory/ntap-20211210-0007/Third Party Advisory
- https://support.apple.com/kb/HT213189Third Party Advisory
- https://twitter.com/kurtseifried/status/1469345530182455296Broken Link, Exploit, Third Party Advisory
- https://www.bentley.com/en/common-vulnerability-exposure/be-2022-0001Third Party Advisory
- https://www.debian.org/security/2021/dsa-5020Mailing List, Third Party Advisory
- https://www.kb.cert.org/vuls/id/930724Third Party Advisory, US Government Resource
- https://www.nu11secur1ty.com/2021/12/cve-2021-44228.htmlExploit, Third Party Advisory
- https://www.oracle.com/security-alerts/alert-cve-2021-44228.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.htmlPatch, Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-44228Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2021-44228?
How severe is CVE-2021-44228?
How do I fix CVE-2021-44228?
Are you affected by CVE-2021-44228?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
