IM
IronMonkey Threat Research

CVE-2021-45046 CRITICAL

Published: 2021-12-14 | Last Modified: 2025-10-27 | Status: Analyzed

Description

It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in an information leak and remote code execution in some environments and local code execution in all environments. Log4j 2.16.0 (Java 8) and 2.12.2 (Java 7) fix this issue by removing support for message lookup patterns and disabling JNDI functionality by default.

Additional Descriptions (1)

Se descubrió que la corrección para abordar CVE-2021-44228 en Apache Log4j versiones 2.15.0 estaba incompleta en ciertas configuraciones no predeterminadas. Esto podría permitir a los atacantes con control sobre los datos de entrada de Thread Context Map (MDC) cuando la configuración de registro utiliza un Pattern Layout no predeterminado con un Context Lookup (por ejemplo, $${ctx:loginId}) o un Thread Context Map pattern (%X, %mdc, o %MDC) para elaborar datos de entrada maliciosos utilizando un patrón JNDI Lookup que resulta en una fuga de información y ejecución de código remoto en algunos entornos y ejecución de código local en todos los entornos. Log4j versiones 2.16.0 (Java 8) y 2.12.2 (Java 7) solucionan este problema eliminando el soporte para los patrones de búsqueda de mensajes y deshabilitando la funcionalidad JNDI por defecto

CVSS Metrics

Base Score: 9.0 (CRITICAL)

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Attack VectorNETWORK
Attack ComplexityHIGH
Privileges RequiredNONE
User InteractionNONE
ScopeCHANGED
Confidentiality ImpactHIGH
Integrity ImpactHIGH
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 2.2

Impact Score: 6.0

Base Score: 5.1 (MEDIUM)

AV:N/AC:H/Au:N/C:P/I:P/A:P

Access VectorNETWORK
Access ComplexityHIGH
AuthenticationNONE
Confidentiality ImpactPARTIAL
Integrity ImpactPARTIAL
Availability ImpactPARTIAL

Source: [email protected]

Type: Primary

Exploitability Score: 4.9

Impact Score: 6.4

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-917
[email protected] Primary
en CWE-917

Affected Products

Vendor Product Version Update Type
apache log4j * <built-in method update of dict object at 0x7763d894ed80> Application
apache log4j * <built-in method update of dict object at 0x7763d894cd40> Application
apache log4j 2.0 <built-in method update of dict object at 0x7763d894ecc0> Application
apache log4j 2.0 <built-in method update of dict object at 0x7763d85a1280> Application
apache log4j 2.0 <built-in method update of dict object at 0x7763d894e3c0> Application
apache log4j 2.0 <built-in method update of dict object at 0x7763d894dc00> Application
cvat computer_vision_annotation_tool - <built-in method update of dict object at 0x7763d85a1900> Application
intel audio_development_kit - <built-in method update of dict object at 0x7763d894d440> Application
intel datacenter_manager - <built-in method update of dict object at 0x7763d894f880> Application
intel genomics_kernel_library - <built-in method update of dict object at 0x7763d894f500> Application
intel oneapi - <built-in method update of dict object at 0x7763d894ee40> Application
intel secure_device_onboard - <built-in method update of dict object at 0x7763d894cc80> Application
intel sensor_solution_firmware_development_kit - <built-in method update of dict object at 0x7763d85a31c0> Application
intel system_debugger - <built-in method update of dict object at 0x7763d85a0c80> Application
intel system_studio - <built-in method update of dict object at 0x7763d894eb80> Application
siemens sppa-t3000_ses3000_firmware * <built-in method update of dict object at 0x7763d894de00> Operating System
siemens captial * <built-in method update of dict object at 0x7763d894f0c0> Application
siemens captial 2019.1 <built-in method update of dict object at 0x7763d85a1fc0> Application
siemens captial 2019.1 <built-in method update of dict object at 0x7763d85a23c0> Application
siemens comos * <built-in method update of dict object at 0x7763a374e280> Application
siemens desigo_cc_advanced_reports 4.0 <built-in method update of dict object at 0x7763d894c1c0> Application
siemens desigo_cc_advanced_reports 4.1 <built-in method update of dict object at 0x7763d894dc80> Application
siemens desigo_cc_advanced_reports 4.2 <built-in method update of dict object at 0x7763d85a1500> Application
siemens desigo_cc_advanced_reports 5.0 <built-in method update of dict object at 0x7763bbbec180> Application
siemens desigo_cc_advanced_reports 5.1 <built-in method update of dict object at 0x7763d85a2d40> Application
siemens desigo_cc_info_center 5.0 <built-in method update of dict object at 0x7763d894fdc0> Application
siemens desigo_cc_info_center 5.1 <built-in method update of dict object at 0x7763d894f480> Application
siemens e-car_operation_center * <built-in method update of dict object at 0x7763d894d680> Application
siemens energy_engage 3.1 <built-in method update of dict object at 0x7763d85a0840> Application
siemens energyip 8.5 <built-in method update of dict object at 0x7763d85a0fc0> Application
siemens energyip 8.6 <built-in method update of dict object at 0x7763d85a0c40> Application
siemens energyip 8.7 <built-in method update of dict object at 0x7763d85a2a40> Application
siemens energyip 9.0 <built-in method update of dict object at 0x7763d85a3040> Application
siemens energyip_prepay 3.7 <built-in method update of dict object at 0x7763d85a3700> Application
siemens energyip_prepay 3.8 <built-in method update of dict object at 0x7763d85a09c0> Application
siemens gma-manager * <built-in method update of dict object at 0x7763d85a22c0> Application
siemens head-end_system_universal_device_integration_system * <built-in method update of dict object at 0x7763d85a1680> Application
siemens industrial_edge_management * <built-in method update of dict object at 0x7763d85a1b40> Application
siemens industrial_edge_management_hub * <built-in method update of dict object at 0x7763d85a1600> Application
siemens logo\!_soft_comfort * <built-in method update of dict object at 0x7763d85a2440> Application
siemens mendix * <built-in method update of dict object at 0x7763d85a1e40> Application
siemens mindsphere * <built-in method update of dict object at 0x7763d85a0b80> Application
siemens navigator * <built-in method update of dict object at 0x7763d85a0700> Application
siemens nx * <built-in method update of dict object at 0x7763d85a2b00> Application
siemens opcenter_intelligence * <built-in method update of dict object at 0x7763d85a0100> Application
siemens operation_scheduler * <built-in method update of dict object at 0x7763bbbed840> Application
siemens sentron_powermanager 4.1 <built-in method update of dict object at 0x7763bbbec340> Application
siemens sentron_powermanager 4.2 <built-in method update of dict object at 0x7763bbbef880> Application
siemens siguard_dsa 4.2 <built-in method update of dict object at 0x7763bbbeff00> Application
siemens siguard_dsa 4.3 <built-in method update of dict object at 0x7763bbbeffc0> Application
siemens siguard_dsa 4.4 <built-in method update of dict object at 0x7763bbbec500> Application
siemens sipass_integrated 2.80 <built-in method update of dict object at 0x7763bbbed880> Application
siemens sipass_integrated 2.85 <built-in method update of dict object at 0x7763bbbec280> Application
siemens siveillance_command * <built-in method update of dict object at 0x7763bbbec5c0> Application
siemens siveillance_control_pro * <built-in method update of dict object at 0x7763bbbed680> Application
siemens siveillance_identity 1.5 <built-in method update of dict object at 0x7763f05c7340> Application
siemens siveillance_identity 1.6 <built-in method update of dict object at 0x7763d8d4c6c0> Application
siemens siveillance_vantage * <built-in method update of dict object at 0x7763a3278b80> Application
siemens siveillance_viewpoint * <built-in method update of dict object at 0x7763a1157140> Application
siemens solid_edge_cam_pro * <built-in method update of dict object at 0x7763f05c5f80> Application
siemens solid_edge_harness_design * <built-in method update of dict object at 0x7763d8b89e80> Application
siemens solid_edge_harness_design 2020 <built-in method update of dict object at 0x7763a327af40> Application
siemens solid_edge_harness_design 2020 <built-in method update of dict object at 0x7763ba74a940> Application
siemens solid_edge_harness_design 2020 <built-in method update of dict object at 0x77636447de00> Application
siemens spectrum_power_4 * <built-in method update of dict object at 0x77635f32cc40> Application
siemens spectrum_power_4 4.70 <built-in method update of dict object at 0x7763f2b645c0> Application
siemens spectrum_power_4 4.70 <built-in method update of dict object at 0x77635f32e900> Application
siemens spectrum_power_4 4.70 <built-in method update of dict object at 0x77635f32efc0> Application
siemens spectrum_power_7 * <built-in method update of dict object at 0x7763d8ee3f80> Application
siemens spectrum_power_7 2.30 <built-in method update of dict object at 0x77635f32dd40> Application
siemens spectrum_power_7 2.30 <built-in method update of dict object at 0x77635f32f100> Application
siemens spectrum_power_7 2.30 <built-in method update of dict object at 0x77635f32fe00> Application
siemens teamcenter * <built-in method update of dict object at 0x77635f32f180> Application
siemens tracealertserverplus * <built-in method update of dict object at 0x77635f32c500> Application
siemens vesys * <built-in method update of dict object at 0x77635f32c440> Application
siemens vesys 2019.1 <built-in method update of dict object at 0x7763ba848f40> Application
siemens vesys 2019.1 <built-in method update of dict object at 0x7763ba84b440> Application
siemens vesys 2019.1 <built-in method update of dict object at 0x7763ba8493c0> Application
siemens xpedition_enterprise - <built-in method update of dict object at 0x7763ba849cc0> Application
siemens xpedition_package_integrator - <built-in method update of dict object at 0x7763ba84ad80> Application
debian debian_linux 10.0 <built-in method update of dict object at 0x7763ba848cc0> Operating System
debian debian_linux 11.0 <built-in method update of dict object at 0x7763ba849100> Operating System
sonicwall email_security * <built-in method update of dict object at 0x7763ba849140> Application
fedoraproject fedora 34 <built-in method update of dict object at 0x7763ba84a080> Operating System
fedoraproject fedora 35 <built-in method update of dict object at 0x7763ba8480c0> Operating System
siemens 6bk1602-0aa12-0tp0_firmware * <built-in method update of dict object at 0x7763ba84a300> Operating System
siemens 6bk1602-0aa22-0tp0_firmware * <built-in method update of dict object at 0x7763ba84bac0> Operating System
siemens 6bk1602-0aa32-0tp0_firmware * <built-in method update of dict object at 0x7763ba849580> Operating System
siemens 6bk1602-0aa42-0tp0_firmware * <built-in method update of dict object at 0x7763ba84a480> Operating System
siemens 6bk1602-0aa52-0tp0_firmware * <built-in method update of dict object at 0x7763ba84bb80> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:apache:log4j:2.0:-:*:*:*:*:*:*
Yes cpe:2.3:a:apache:log4j:2.0:beta9:*:*:*:*:*:*
Yes cpe:2.3:a:apache:log4j:2.0:rc1:*:*:*:*:*:*
Yes cpe:2.3:a:apache:log4j:2.0:rc2:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:cvat:computer_vision_annotation_tool:-:*:*:*:*:*:*:*
Yes cpe:2.3:a:intel:audio_development_kit:-:*:*:*:*:*:*:*
Yes cpe:2.3:a:intel:datacenter_manager:-:*:*:*:*:*:*:*
Yes cpe:2.3:a:intel:genomics_kernel_library:-:*:*:*:*:*:*:*
Yes cpe:2.3:a:intel:oneapi:-:*:*:*:*:eclipse:*:*
Yes cpe:2.3:a:intel:secure_device_onboard:-:*:*:*:*:*:*:*
Yes cpe:2.3:a:intel:sensor_solution_firmware_development_kit:-:*:*:*:*:*:*:*
Yes cpe:2.3:a:intel:system_debugger:-:*:*:*:*:*:*:*
Yes cpe:2.3:a:intel:system_studio:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:sppa-t3000_ses3000_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:sppa-t3000_ses3000:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:siemens:captial:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:captial:2019.1:-:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:captial:2019.1:sp1912:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:comos:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:desigo_cc_advanced_reports:4.0:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:desigo_cc_advanced_reports:4.1:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:desigo_cc_advanced_reports:4.2:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:desigo_cc_advanced_reports:5.0:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:desigo_cc_advanced_reports:5.1:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:desigo_cc_info_center:5.0:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:desigo_cc_info_center:5.1:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:e-car_operation_center:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:energy_engage:3.1:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:energyip:8.5:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:energyip:8.6:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:energyip:8.7:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:energyip:9.0:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:energyip_prepay:3.7:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:energyip_prepay:3.8:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:gma-manager:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:head-end_system_universal_device_integration_system:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:industrial_edge_management:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:industrial_edge_management_hub:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:logo\!_soft_comfort:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:mendix:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:mindsphere:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:navigator:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:nx:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:opcenter_intelligence:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:operation_scheduler:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:sentron_powermanager:4.1:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:sentron_powermanager:4.2:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:siguard_dsa:4.2:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:siguard_dsa:4.3:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:siguard_dsa:4.4:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:sipass_integrated:2.80:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:sipass_integrated:2.85:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:siveillance_command:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:siveillance_control_pro:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:siveillance_identity:1.5:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:siveillance_identity:1.6:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:siveillance_vantage:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:siveillance_viewpoint:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:solid_edge_cam_pro:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:solid_edge_harness_design:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:solid_edge_harness_design:2020:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:solid_edge_harness_design:2020:-:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:solid_edge_harness_design:2020:sp2002:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:spectrum_power_4:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:spectrum_power_4:4.70:-:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:spectrum_power_4:4.70:sp7:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:spectrum_power_4:4.70:sp8:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:spectrum_power_7:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:spectrum_power_7:2.30:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:spectrum_power_7:2.30:-:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:spectrum_power_7:2.30:sp2:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:teamcenter:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:tracealertserverplus:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:vesys:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:vesys:2019.1:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:vesys:2019.1:-:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:vesys:2019.1:sp1912:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:xpedition_enterprise:-:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:xpedition_package_integrator:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
Yes cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:sonicwall:email_security:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
Yes cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:6bk1602-0aa12-0tp0:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:6bk1602-0aa12-0tp0_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:6bk1602-0aa22-0tp0:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:6bk1602-0aa22-0tp0_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:6bk1602-0aa32-0tp0:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:6bk1602-0aa32-0tp0_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:6bk1602-0aa42-0tp0:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:6bk1602-0aa42-0tp0_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:6bk1602-0aa52-0tp0:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:6bk1602-0aa52-0tp0_firmware:*:*:*:*:*:*:*:*

References

Notification
Message here