CVE-2021-45046
Description
It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in an information leak and remote code execution in some environments and local code execution in all environments. Log4j 2.16.0 (Java 8) and 2.12.2 (Java 7) fix this issue by removing support for message lookup patterns and disabling JNDI functionality by default.
Risk Information
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Apache Log4j Vulnerability (CVE-2021-45046) | Windows |
| Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.0.13 | Windows |
| Vulnerabilities CVE-2021-45046 are fixed in Apache - Log4j Core 2.16.0 | Windows |
| Vulnerabilities CVE-2021-45046,CVE-2021-44228 are fixed in Apache - Log4j Core 2.12.2 | Windows |
| Multiple Vulnerabilities are affected in IBM Tivoli Monitoring 6.3.0 | Windows |
| Multiple Vulnerabilities are affected in IBM Security Guardium 10.5 | Windows |
| Multiple Vulnerabilities are affected in IBM Security Guardium 10.6 | Windows |
| Multiple Vulnerabilities are affected in IBM Security Guardium 11.1 | Windows |
| Multiple Vulnerabilities are affected in IBM Security Guardium 11.2 | Windows |
| Multiple Vulnerabilities are affected in IBM Cognos Controller 10.4.2 | Windows |
| Multiple Vulnerabilities are affected in IBM Security Guardium 11.3 | Windows |
| Multiple Vulnerabilities are affected in IBM Security Guardium 11.4 | Windows |
| Vulnerabilities CVE-2021-44228,CVE-2021-45046 are affected in Siemens Mendix 2.3 | Windows |
| Vulnerabilities CVE-2021-44228,CVE-2021-45046 are affected in Siemens Teamcenter 2.3 | Windows |
| Multiple Vulnerabilities are affected in IBM Security Guardium 11.0 | Windows |
| Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.11 | Windows |
| Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.1.1.0 | Windows |
| Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.10.4 | Windows |
| Multiple Vulnerabilities are affected in IBM MQ 9.1 | Windows |
| Multiple Vulnerabilities are affected in IBM MQ 9.2 | Windows |
| Multiple Vulnerabilities are affected in IBM Business Automation Workflow 21.0 | Windows |
| Multiple Vulnerabilities are affected in IBM App Connect Enterprise 11.0.0.15 | Windows |
| Multiple Vulnerabilities are affected in IBM App Connect Enterprise 12.0.3.0 | Windows |
| Vulnerabilities CVE-2021-45105,CVE-2021-44832,CVE-2021-45046,CVE-2021-44228 are fixed in Ops4j - pax-logging-log4j2 1.9.2 | Windows |
| Vulnerabilities CVE-2021-45046,CVE-2021-44228 are fixed in Ops4j - pax-logging-log4j2 1.10.8 | Windows |
| Vulnerabilities CVE-2021-45046 are fixed in Ops4j - pax-logging-log4j2 1.11.11 | Windows |
| Vulnerabilities CVE-2021-45046 are fixed in Ops4j - pax-logging-log4j2 2.0.12 | Windows |
| Vulnerabilities CVE-2021-45046 are fixed in Apache - Log4j Core for Linux 2.16.0 | Linux |
| Vulnerabilities CVE-2021-45046,CVE-2021-44228 are fixed in Apache - Log4j Core for Linux 2.12.2 | Linux |
| Vulnerabilities CVE-2021-45105,CVE-2021-44832,CVE-2021-45046,CVE-2021-44228 are fixed in Ops4j - pax-logging-log4j2 for Linux 1.9.2 | Linux |
| Vulnerabilities CVE-2021-45046,CVE-2021-44228 are fixed in Ops4j - pax-logging-log4j2 for Linux 1.10.8 | Linux |
| Vulnerabilities CVE-2021-45046 are fixed in Ops4j - pax-logging-log4j2 for Linux 1.11.11 | Linux |
| Vulnerabilities CVE-2021-45046 are fixed in Ops4j - pax-logging-log4j2 for Linux 2.0.12 | Linux |
| Improper Neutralization of Special Elements used in an Expression Language Statement (Expression Language Injection) Vulnerability (CVE-2021-45046) | NCM |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234