CVE-2021-45105

MEDIUMCVSS 5.9/10EPSS 100.00%

Last modified

CVE-2021-45105 is a medium-severity vulnerability rated 5.9/10 on the CVSS scale. Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. EPSS estimates a 100.00% chance of exploitation in the next 30 days.

Description

Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.

Metrics

CVSS 3.1
5.9/10

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Probability
100.00%

100.0th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
ApacheLog4j>= 2.0, < 2.3.1
ApacheLog4j>= 2.4, < 2.12.3
ApacheLog4j>= 2.13.0, <= 2.16.0
NetappCloud ManagerAll versions
DebianDebian Linux10.0
DebianDebian Linux11.0
SonicwallEmail Security<= 10.0.12
SonicwallNetwork Security Manager>= 2.0, < 3.0
SonicwallWeb Application Firewall>= 3.0.0, < 3.1.0
Sonicwall6bk1602-0aa12-0tp0 Firmware< 2.7.0
Sonicwall6bk1602-0aa22-0tp0 Firmware< 2.7.0
Sonicwall6bk1602-0aa32-0tp0 Firmware< 2.7.0
Sonicwall6bk1602-0aa42-0tp0 Firmware< 2.7.0
Sonicwall6bk1602-0aa52-0tp0 Firmware< 2.7.0
OracleAgile Engineering Data Management6.2.1.0
OracleAgile Plm9.3.6
OracleAgile Plm Mcad Connector3.6
OracleAutovue For Agile Product Lifecycle Management21.0.2
OracleBanking Deposits And Lines Of Credit Servicing2.12.0
OracleBanking Enterprise Default Management2.7.1
OracleBanking Enterprise Default Management2.12.0
OracleBanking Loans Servicing2.12.0
OracleBanking Party Management2.7.0
OracleBanking Payments14.5
OracleBanking Platform2.6.2
OracleBanking Platform2.7.1
OracleBanking Platform2.12.0
OracleBanking Trade Finance14.5
OracleBanking Treasury Management14.5
OracleBusiness Intelligence5.5.0.0.0
OracleCommunications Asap7.3
OracleCommunications Billing And Revenue Management12.0.0.4
OracleCommunications Billing And Revenue Management12.0.0.5
OracleCommunications Cloud Native Core Console1.9.0
OracleCommunications Cloud Native Core Network Function Cloud Native Environment1.10.0
OracleCommunications Cloud Native Core Network Repository Function1.15.0
OracleCommunications Cloud Native Core Network Repository Function1.15.1
OracleCommunications Cloud Native Core Network Slice Selection Function1.8.0
OracleCommunications Cloud Native Core Policy1.15.0
OracleCommunications Cloud Native Core Security Edge Protection Proxy1.7.0
OracleCommunications Cloud Native Core Service Communication Proxy1.15.0
OracleCommunications Cloud Native Core Unified Data Repository1.15.0
OracleCommunications Convergence3.0.2.2.0
OracleCommunications Convergence3.0.3.0
OracleCommunications Convergent Charging Controller>= 12.0.1.0.0, <= 12.0.4.0.0
OracleCommunications Convergent Charging Controller6.0.1.0.0
OracleCommunications Diameter Signaling Router>= 8.3.0.0, <= 8.5.1.0
OracleCommunications Eagle Element Management System46.6
OracleCommunications Eagle Ftp Table Base Retrieval4.5
OracleCommunications Element Manager< 9.0

Showing 50 of 207 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2021-45105?
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.
How severe is CVE-2021-45105?
CVE-2021-45105 has a CVSS score of 5.9/10 (MEDIUM severity). The EPSS model estimates a 100.00% probability of exploitation in the next 30 days.
How do I fix CVE-2021-45105?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-45105?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST