CVE-2021-44228
Description
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.
Risk Information
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Apache Log4Shell vulnerability (CVE-2021-44228) | Windows |
| Vulnerabilities CVE-2021-44228 are fixed in Couchbase Server Enterprise Edition 7.0.3 | Windows |
| Vulnerabilities CVE-2021-44228 are fixed in Couchbase Server Enterprise Edition 6.6.4 | Windows |
| Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.0.13 | Windows |
| Vulnerabilities CVE-2021-45105,CVE-2021-44228 are fixed in Apache - Log4j Core 2.3.1 | Windows |
| Vulnerabilities CVE-2021-45046,CVE-2021-44228 are fixed in Apache - Log4j Core 2.12.2 | Windows |
| Vulnerabilities CVE-2021-44228 are fixed in Apache - Log4j Core 2.15.0 | Windows |
| Multiple Vulnerabilities are affected in Netapp Active Iq Unified Manager 2.3 | Windows |
| Multiple Vulnerabilities are affected in Netapp Oncommand Insight 2.3 | Windows |
| Multiple Vulnerabilities are affected in IBM Tivoli Monitoring 6.3.0 | Windows |
| Multiple Vulnerabilities are affected in IBM Security Guardium 10.5 | Windows |
| Multiple Vulnerabilities are affected in IBM Security Guardium 10.6 | Windows |
| Multiple Vulnerabilities are affected in IBM Security Guardium 11.1 | Windows |
| Multiple Vulnerabilities are affected in IBM Security Guardium 11.2 | Windows |
| Multiple Vulnerabilities are affected in IBM Cognos Controller 10.4.2 | Windows |
| Multiple Vulnerabilities are affected in IBM Security Guardium 11.3 | Windows |
| Multiple Vulnerabilities are affected in IBM Security Guardium 11.4 | Windows |
| Vulnerabilities CVE-2021-44228,CVE-2021-45046 are affected in Siemens Mendix 2.3 | Windows |
| Vulnerabilities CVE-2021-44228,CVE-2021-45046 are affected in Siemens Teamcenter 2.3 | Windows |
| Multiple Vulnerabilities are affected in IBM Security Guardium 11.0 | Windows |
| Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.11 | Windows |
| Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.1.1.0 | Windows |
| Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.10.4 | Windows |
| Multiple Vulnerabilities are affected in IBM MQ 9.1 | Windows |
| Multiple Vulnerabilities are affected in IBM MQ 9.2 | Windows |
| Multiple Vulnerabilities are affected in IBM Business Automation Workflow 21.0 | Windows |
| Multiple Vulnerabilities are affected in IBM App Connect Enterprise 11.0.0.15 | Windows |
| Multiple Vulnerabilities are affected in IBM App Connect Enterprise 12.0.3.0 | Windows |
| Vulnerabilities CVE-2021-44228 are affected in Guicedee - log4j-core 1.2.1.2 | Windows |
| Vulnerabilities CVE-2021-45105,CVE-2021-44832,CVE-2021-45046,CVE-2021-44228 are fixed in Ops4j - pax-logging-log4j2 1.9.2 | Windows |
| Vulnerabilities CVE-2021-45046,CVE-2021-44228 are fixed in Ops4j - pax-logging-log4j2 1.10.8 | Windows |
| Vulnerabilities CVE-2021-44228 are fixed in Ops4j - pax-logging-log4j2 1.11.10 | Windows |
| Vulnerabilities CVE-2021-44228 are fixed in Ops4j - pax-logging-log4j2 2.0.11 | Windows |
| Vulnerabilities CVE-2021-44228 are affected in Xbib - log4j 6.3.2.1 | Windows |
| Vulnerabilities CVE-2021-44228 are affected in Co - log4j-core 2.6.3 | Windows |
| Vulnerabilities CVE-2021-44228 are affected in Command Line Tools for XCode for Mac 13.2 | Mac |
| Apache Log4j - Logging Framework for Java (USN-5192-1) liblog4j2-java_2.10.0-2ubuntu0.1_all.deb | Linux |
| Vulnerabilities CVE-2021-44228 are fixed in MySQL Enterprise Monitor 8.0.28 (For Linux) | Linux |
| Vulnerabilities CVE-2021-45105,CVE-2021-44228 are fixed in Apache - Log4j Core for Linux 2.3.1 | Linux |
| Vulnerabilities CVE-2021-45046,CVE-2021-44228 are fixed in Apache - Log4j Core for Linux 2.12.2 | Linux |
| Vulnerabilities CVE-2021-44228 are fixed in Apache - Log4j Core for Linux 2.15.0 | Linux |
| Vulnerabilities CVE-2021-44228 are affected in Guicedee - log4j-core for Linux 1.2.1.2 | Linux |
| Vulnerabilities CVE-2021-45105,CVE-2021-44832,CVE-2021-45046,CVE-2021-44228 are fixed in Ops4j - pax-logging-log4j2 for Linux 1.9.2 | Linux |
| Vulnerabilities CVE-2021-45046,CVE-2021-44228 are fixed in Ops4j - pax-logging-log4j2 for Linux 1.10.8 | Linux |
| Vulnerabilities CVE-2021-44228 are fixed in Ops4j - pax-logging-log4j2 for Linux 1.11.10 | Linux |
| Vulnerabilities CVE-2021-44228 are fixed in Ops4j - pax-logging-log4j2 for Linux 2.0.11 | Linux |
| Vulnerabilities CVE-2021-44228 are affected in Xbib - log4j for Linux 6.3.2.1 | Linux |
| Vulnerabilities CVE-2021-44228 are affected in Co - log4j-core for Linux 2.6.3 | Linux |
| Improper Input Validation Vulnerability (CVE-2021-44228) | NCM |
Patch Details
Click to see the patches provided by ManageEngine for this CVE
| Patch ID | Patch Description |
|---|---|
| PATCH-607901 | Command Line Tools for XCode for Mac 15.3 (Deployment-Only) |
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234