IM
IronMonkey Threat Research
‹ Back to ICS Advisories

Apache log4j Vulnerability

CRITICAL
CVSS 10.0
Date 2026-07-28T15:15:04+00:00
Source honeywell
Published by Honeywell

// Description

SN 2021-HBT-12-14-01-V 2 1 www.honeywell.com # Product Security Bulletin Apache log4j Vulnerability Security Bulletin #: 2021-HBT-12-14-01-V2 Publish Date: 12-16-2021 CVSS v3.0 Base Score: 10 Reference: CVE-2021-44228, CVE-2021-45046 ## Summary Honeywell is actively addressing the log4j Remote Code Execution (RCE) vulnerability recently disclosed as CVE-2021-44228 and CVE-2021-45046. Honeywell Commercial Security, part of Honeywell Building Technologies, is actively updating af

// Vulnerabilities (2)

CVE ID CVSS Score Severity Description
CVE-2021-45046 0.0 unknown
CVE-2021-45046. The fix to address CVE-2021-44228 was incomplete in certain non-default configurations, when the logging configuration uses a non-default Pattern Layout with a Context Lookup (for example, ${ctx:loginId}). This could allow attackers with control over Thread Context Map (MDC) input data to craft malicious input data using a JNDI Lookup pattern, resulting in an information leak and remote code execution in some environments and local code execution in all environments.
CVE-2021-44228 10.0 critical
An attacker could enter malicious data into the affected product, causing remote code execution.CVE-2021-44228 has been assigned to this vulnerability. A CVSS v3 base score of 10.0 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).

// Remediations (141)

Patch: Update to V13.3.0.1 or later version
Update to V13.3.0.1 or later version
Patch: Update to V5.1 QU1 or later version
Update to V5.1 QU1 or later version
Patch: Vulnerabilities fixed on central cloud service; no user actions necessary
Vulnerabilities fixed on central cloud service; no user actions necessary
Patch: A hotfix is available; please contact customer support to receive the hotfix
A hotfix is available; please contact customer support to receive the hotfix
Patch: Update Teamcenter to any fix version available for the different version lines of Teamcenter, see ht
Update Teamcenter to any fix version available for the different version lines of Teamcenter, see https://support.sw.siemens.com/en- US/knowledge-base/PL8600700
Patch: Vulnerability CVE-2021-44228 fixed on central cloud service; no user actions necessary
Vulnerability CVE-2021-44228 fixed on central cloud service; no user actions necessary
Patch: Remove the JndiLookup class from the classpath.
Remove the JndiLookup class from the classpath.
Patch: Update to V13.0.1 or later version
Update to V13.0.1 or later version
Patch: Apply the hotfix
Apply the hotfix
Patch: Update to V5.2.6 or later version
Update to V5.2.6 or later version
Patch: Vulnerabilities fixed on central cloud services starting 2021-12-11; no user actions necessary
Vulnerabilities fixed on central cloud services starting 2021-12-11; no user actions necessary
Patch: Update to V12.4.0.12 or later version
Update to V12.4.0.12 or later version
Patch: Download and install the updated TCCS setup from the Siemens Support Center; for details see https:/
Download and install the updated TCCS setup from the Siemens Support Center; for details see https://support.sw.siemens.com/knowledge- base/PL8615527
Patch: Vulnerabilities fixed on central cloud service starting 2021-12-19; no user actions necessary
Vulnerabilities fixed on central cloud service starting 2021-12-19; no user actions necessary
Patch: Update to V10.4.2 or later version
Update to V10.4.2 or later version
Patch: Update to V12.4.1 or later version
Update to V12.4.1 or later version
Patch: Update to V2020.1 SP2202 or later version
Update to V2020.1 SP2202 or later version
Patch: Update to V2000.3400 or later version
Update to V2000.3400 or later version
Patch: Update to VX.2.10 Update 4 or later version
Update to VX.2.10 Update 4 or later version
Patch: Update to V13.2.1.1 or V13.3.0.0 or later version
Update to V13.2.1.1 or V13.3.0.0 or later version
Patch: Simcenter Testlab Data Management team will contact all impacted customer to deploy the mitigation m
Simcenter Testlab Data Management team will contact all impacted customer to deploy the mitigation measures. This action will secure your installation against Log4Shell vulnerability. For further information see: https://support.sw.siemens.com/en-US/knowledge- base/PL8601418
Patch: Remove the JndiLookup class from the classpath. Detailed instructions are available at https://suppo
Remove the JndiLookup class from the classpath. Detailed instructions are available at https://support.industry.siemens.com/cs/ww/en/view/109805562/
Patch: Update to VX.2.7 Update 19 or later version
Update to VX.2.7 Update 19 or later version
Patch: Update to V2008 or later version
Update to V2008 or later version
Patch: Update to V2021.1 SP2202 or later version
Update to V2021.1 SP2202 or later version
Patch: Update to 2022.1-2008 or later version
Update to 2022.1-2008 or later version
Patch: Update to V21Q4 and apply the patch. Please contact your local Siemens representative.
Update to V21Q4 and apply the patch. Please contact your local Siemens representative.
Patch: Update to V4.70 SP9 and apply Security Patch 1. Please contact your local Siemens representative.
Update to V4.70 SP9 and apply Security Patch 1. Please contact your local Siemens representative.
Patch: Update to V4.1.2 or later version
Update to V4.1.2 or later version
Patch: Update to V13.2.0.1 or later version
Update to V13.2.0.1 or later version
Patch: Update to V5.0.11 or later version
Update to V5.0.11 or later version
Patch: Update to V6.3 or later version
Update to V6.3 or later version
Patch: Update to VX.2.10 Update 4 or later version
Update to VX.2.10 Update 4 or later version
Patch: Update to VX.2.8 Update 13 or later version
Update to VX.2.8 Update 13 or later version
Patch: Update to V4.1.1.1 or later version
Update to V4.1.1.1 or later version
Patch: Vulnerabilities fixed with update on 2021-12-16; no user actions necessary
Vulnerabilities fixed with update on 2021-12-16; no user actions necessary
Patch: Update to V13.0.0.2 or later version
Update to V13.0.0.2 or later version
Patch: Update to V2022 SP2202 or later version
Update to V2022 SP2202 or later version
Patch: Update to V13.0.0.9 or later version
Update to V13.0.0.9 or later version
Patch: Apply the patch
Apply the patch
Patch: Update to V2.85.7.5 or later version
Update to V2.85.7.5 or later version
Patch: Vulnerabilities fixed on central cloud services starting 2021-12-10; no user actions necessary
Vulnerabilities fixed on central cloud services starting 2021-12-10; no user actions necessary
Patch: Specific fix versions based on V6.0.2 and V6.0.3 were released and deployed for all affected project
Specific fix versions based on V6.0.2 and V6.0.3 were released and deployed for all affected projects
Patch: Update the driver for the SmartRAID controller to V2.6.6 or later version, available at https://stor
Update the driver for the SmartRAID controller to V2.6.6 or later version, available at https://storage.microsemi.com/en- us/support/raid/sas_raid/asr-3151-4i/
Patch: Update to V3.3.0.7 or later version
Update to V3.3.0.7 or later version
Patch: Update to V4.3.13 or later version
Update to V4.3.13 or later version
Patch: Update to V5.1.5 or later version
Update to V5.1.5 or later version
Patch: Update to V1.7.18 or later version, as provided via cRSP V13.17.2 or later version
Update to V1.7.18 or later version, as provided via cRSP V13.17.2 or later version
Patch: Update to V2008 or later version
Update to V2008 or later version
Patch: Update to V5.1.8 or later version
Update to V5.1.8 or later version
Patch: Update to V1973.4340 or later version
Update to V1973.4340 or later version
Patch: Update to V8.6.2.472 or later version
Update to V8.6.2.472 or later version
Patch: Update the UAA component to V75.8.3
Update the UAA component to V75.8.3
Patch: Update to V2.3.2 or later version; please contact customer support to receive the latest version
Update to V2.3.2 or later version; please contact customer support to receive the latest version
Patch: Update to V13.0.1.2 or later version
Update to V13.0.1.2 or later version
Patch: Update to V4.2.0.2 or later version
Update to V4.2.0.2 or later version
Patch: Update to V2021.2.2 or later version
Update to V2021.2.2 or later version
Patch: Update to V1.5 SP4 and apply the patch
Update to V1.5 SP4 and apply the patch
Patch: Update to V5.0.6 or later version
Update to V5.0.6 or later version
Patch: Update to V13.2.0.6 or later version
Update to V13.2.0.6 or later version
Patch: Update to V2020.1 SP2202 or later version
Update to V2020.1 SP2202 or later version
Patch: Update to V12.3.11 or later version
Update to V12.3.11 or later version
Patch: Remove the JndiLookup class from the classpath. Detailed instructions are available at https://suppo
Remove the JndiLookup class from the classpath. Detailed instructions are available at https://support.industry.siemens.com/cs/ww/en/view/109805602/
Patch: Update to V18.1 or later version to fix CVE-2021-44228
Update to V18.1 or later version to fix CVE-2021-44228
Patch: Update to V13.1.0.1 or later version
Update to V13.1.0.1 or later version
Patch: Update to V12.2.0.18 or later version
Update to V12.2.0.18 or later version
Patch: Update to V13.1.0.8 or later version
Update to V13.1.0.8 or later version
Patch: Update to V5.2.3 or later version
Update to V5.2.3 or later version
Patch: Apply the hotfix
Apply the hotfix
Patch: Update to V2.2.7 or later version; please contact customer support to receive the latest version
Update to V2.2.7 or later version; please contact customer support to receive the latest version
Patch: Update to V12.3.0.15 or later version
Update to V12.3.0.15 or later version
Patch: Find detailed remediation and mitigation information on the EnergyIP docs portal at: https://docs.em
Find detailed remediation and mitigation information on the EnergyIP docs portal at: https://docs.emeter.com/display/public/WELCOME/Energy IP+Security+Advisory+for+Log4Shell+Vulnerability
Patch: HEEDS Connect team will contact all impacted customers to deploy a new log4j version. This action wi
HEEDS Connect team will contact all impacted customers to deploy a new log4j version. This action will secure your installation against Log4Shell vulnerability. For further information see: https://support.sw.siemens.com/en-US/knowledge-base/PL8601661
Patch: Update to V4.0.0.2 or later version
Update to V4.0.0.2 or later version
Patch: Although the Cloud Foundry environment itself is not vulnerable to this exploit, we nevertheless rec
Although the Cloud Foundry environment itself is not vulnerable to this exploit, we nevertheless recommend to upgrade log4j-core to the latest available version if log4j-core is part of your project. https://support.sw.siemens.com/en-US/product/268530510/knowledge- base/PL8600797
Patch: Update to V4.0.3 or later version
Update to V4.0.3 or later version
Patch: Update Teamcenter to any fix version available for the different version lines of Teamcenter, see ht
Update Teamcenter to any fix version available for the different version lines of Teamcenter, see https://support.sw.siemens.com/en- US/knowledge-base/PL8600700
Patch: Update to VX.2.10 Update 4 or later version
Update to VX.2.10 Update 4 or later version
Patch: Update to V1.6 SP1 and apply the patch
Update to V1.6 SP1 and apply the patch
Patch: Update to V3.5 or later version
Update to V3.5 or later version
Patch: Follow the remediation steps documented at https://ask.adaptec.com/app/answers/detail/a_id/17527/
Follow the remediation steps documented at https://ask.adaptec.com/app/answers/detail/a_id/17527/
Patch: Update to V4.3.3 or later version
Update to V4.3.3 or later version
Patch: Apply the hotfix, available for versions V14.1, V15.0, V15.1, V15.1.2, V16.0, V16.0.1, V16.0.2, V16.
Apply the hotfix, available for versions V14.1, V15.0, V15.1, V15.1.2, V16.0, V16.0.1, V16.0.2, V16.1, V16.1.1, V16.1.2
Patch: Update to VX.2.7 Update 19 or later version
Update to VX.2.7 Update 19 or later version
Patch: Update to V12.2.8 or later version
Update to V12.2.8 or later version
Patch: Update to V2019.1 SP2204 or later version
Update to V2019.1 SP2204 or later version
Patch: Vulnerabilities fixed with update on 2021-12-23; no user actions necessary
Vulnerabilities fixed with update on 2021-12-23; no user actions necessary
Patch: Update to VX.2.10 Update 4 or later version
Update to VX.2.10 Update 4 or later version
Mitigation: Specific mitigations and how to apply are described in the SE Controls Security Announcement Inciden
Specific mitigations and how to apply are described in the SE Controls Security Announcement Incident 2021-01, available in the customer portal. https://cep.siemens-energy.com/cep/
Mitigation: Ensure that SPPA-T3000 is set up according to the security concept defined in the SPPA-T3000 securit
Ensure that SPPA-T3000 is set up according to the security concept defined in the SPPA-T3000 security manual
Mitigation: Restrict physical access to the local networks of the solution
Restrict physical access to the local networks of the solution
Mitigation: Open TraceAlertServerPLUS.exe with Zip tool to remove file JndiLookup.class in directory org/apache/
Open TraceAlertServerPLUS.exe with Zip tool to remove file JndiLookup.class in directory org/apache/logging/log4j/core/lookup/. This measure mitigates both CVE-2021-44228 and CVE-2021-45046.
Mitigation: Check file system permissions
Check file system permissions
Mitigation: Review the status of the defense in depth recommendations that apply to your specific deployment and
Review the status of the defense in depth recommendations that apply to your specific deployment and align as needed. Especially the measures on the network layer to prevent accessibility from other network segments
Mitigation: Ensure that TraceAlertServerPLUS does not run with elevated privileges
Ensure that TraceAlertServerPLUS does not run with elevated privileges
Patch: Vulnerabilities fixed on central cloud service between 2021-12-10 (CVE-2021-44228) and 2021-12-21 (C
Vulnerabilities fixed on central cloud service between 2021-12-10 (CVE-2021-44228) and 2021-12-21 (CVE-2021-45105); no user actions necessary
Mitigation: Note: EnergyIP V8.5 and V8.6 applications are not directly affected, but CAS is.
Note: EnergyIP V8.5 and V8.6 applications are not directly affected, but CAS is.
Patch: Vulnerabilities fixed for Command installations on a project basis; no user actions necessary
Vulnerabilities fixed for Command installations on a project basis; no user actions necessary
Mitigation: Note: Earlier versions of the product contained a vulnerable version of log4j, but no risk for explo
Note: Earlier versions of the product contained a vulnerable version of log4j, but no risk for exploitation could be identified.
Patch: Vulnerabilities fixed on central cloud service starting 2021-12-13; no user actions necessary
Vulnerabilities fixed on central cloud service starting 2021-12-13; no user actions necessary
Mitigation: Stop and disable autostart for maxView Storage Manager WebServer. Note: This software is not require
Stop and disable autostart for maxView Storage Manager WebServer. Note: This software is not required for the underlying RAID to work
Mitigation: Find detailed mitigation steps for both server and client installations at: https://support.sw.sieme
Find detailed mitigation steps for both server and client installations at: https://support.sw.siemens.com/en-US/knowledge- base/PL8602538
Mitigation: If, for a particular product listed in the table above, no remediation or specific mitigation is giv
If, for a particular product listed in the table above, no remediation or specific mitigation is given: Block both incoming and outgoing connections between the system and the Internet.
Mitigation: Find detailed mitigation steps at: https://support.sw.siemens.com/en- US/knowledge-base/MG618363
Find detailed mitigation steps at: https://support.sw.siemens.com/en- US/knowledge-base/MG618363
Patch: Update to V1.4.0-42 or later version
Update to V1.4.0-42 or later version
Patch: Although the Mendix runtime itself is not vulnerable to this exploit, we nevertheless recommend to u
Although the Mendix runtime itself is not vulnerable to this exploit, we nevertheless recommend to upgrade log4j-core to the latest available version if log4j-core is part of your project. This advice is regardless of the JRE/JDK version the app runs on.
Mitigation: Additional information is available at https://support.sw.siemens.com/en-US/product/1644094854/knowl
Additional information is available at https://support.sw.siemens.com/en-US/product/1644094854/knowledge- base/MG618343
Patch: Update to V1.4.11 or later version
Update to V1.4.11 or later version
Patch: Update to V4.4.1 or later version
Update to V4.4.1 or later version
Mitigation: Find detailed remediation and mitigation information at: https://support.sw.siemens.com/knowledge-ba
Find detailed remediation and mitigation information at: https://support.sw.siemens.com/knowledge-base/MG618362
Patch: Vulnerabilities fixed for Vantage installations on a project basis; no user actions necessary
Vulnerabilities fixed for Vantage installations on a project basis; no user actions necessary
Mitigation: Find detailed remediation and mitigation information at: https://support.sw.siemens.com/en-US/knowle
Find detailed remediation and mitigation information at: https://support.sw.siemens.com/en-US/knowledge-base/PL8601468
Mitigation: For Comfy and Enlighted, see also chapter Additional Information below
For Comfy and Enlighted, see also chapter Additional Information below
Mitigation: Disable ports 8080/tcp and 8443/tcp in the firewall configuration of the IPC
Disable ports 8080/tcp and 8443/tcp in the firewall configuration of the IPC
Mitigation: Find detailed remediation and mitigation information at: https://support.sw.siemens.com/en-US/knowle
Find detailed remediation and mitigation information at: https://support.sw.siemens.com/en-US/knowledge-base/PL8600700
Patch: Vulnerability CVE-2021-44228 fixed on central cloud service starting 2021-12-13; no user actions nec
Vulnerability CVE-2021-44228 fixed on central cloud service starting 2021-12-13; no user actions necessary
Mitigation: Find detailed remediation and mitigation information at: https://support.sw.siemens.com/en-US/knowle
Find detailed remediation and mitigation information at: https://support.sw.siemens.com/en-US/knowledge-base/PL8601203
Patch: Vulnerabilities fixed on central cloud service starting 2021-12-11; no user actions necessary
Vulnerabilities fixed on central cloud service starting 2021-12-11; no user actions necessary
Patch: Update to V3.0.29 or later version
Update to V3.0.29 or later version
Patch: Update to V4.70 SP9 Security Patch 1 or later version. Please contact your local Siemens representa
Update to V4.70 SP9 Security Patch 1 or later version. Please contact your local Siemens representative.
Patch: Apply the patch. Please contact your local Siemens representative.
Apply the patch. Please contact your local Siemens representative.
Patch: Update to V12.1.0.14 or later version
Update to V12.1.0.14 or later version
Patch: Vulnerabilities fixed with update on 2021-12-21; no user actions necessary
Vulnerabilities fixed with update on 2021-12-21; no user actions necessary
Patch: Update to V3.0.30 or later version
Update to V3.0.30 or later version
Patch: Update to V13.17.2 was deployed on all cRSP services on 2021-12-21; no user actions necessary
Update to V13.17.2 was deployed on all cRSP services on 2021-12-21; no user actions necessary
Patch: Follow the remediation steps documented at: https://support.sw.siemens.com/en-US/knowledge-base/PL86
Follow the remediation steps documented at: https://support.sw.siemens.com/en-US/knowledge-base/PL8602466
Patch: Vulnerabilities fixed on remote VPL server; no user actions necessary
Vulnerabilities fixed on remote VPL server; no user actions necessary
Patch: Update to V4.2.3 or later version
Update to V4.2.3 or later version
Patch: Update to V2021.1 SP2202 or later version
Update to V2021.1 SP2202 or later version
Patch: Update to VX.2.8 Update 13 or later version
Update to VX.2.8 Update 13 or later version
Patch: Update to V5.2.4 or later version
Update to V5.2.4 or later version
Patch: Upgrade PowerManage to Version 4.10
Upgrade PowerManage to Version 4.10
Patch: Remove the JndiLookup class from the classpath. Detailed instructions are available at https://suppo
Remove the JndiLookup class from the classpath. Detailed instructions are available at https://support.industry.siemens.com/cs/ww/en/view/109805562/
Patch: Update to V5.1 QU1 or later version
Update to V5.1 QU1 or later version
Patch: Update to V5.2.4 or later version
Update to V5.2.4 or later version
Mitigation: Note: EnergyIP V8.5 and V8.6 applications are not directly affected, but CAS is.
Note: EnergyIP V8.5 and V8.6 applications are not directly affected, but CAS is.
Mitigation: Johnson Controls recommends upgrading exacq Enterprise Manager to Version 21.12.1 or apply manual mi
Johnson Controls recommends upgrading exacq Enterprise Manager to Version 21.12.1 or apply manual mitigation steps (available upon request).
Mitigation: Further ICS security notices and product security guidance are located at Johnson Controls product s
Further ICS security notices and product security guidance are located at Johnson Controls product security website.
Mitigation: Refer to the exacq Hardening Guide for guidance on isolating exacqVision NVRs and Enterprise Manager
Refer to the exacq Hardening Guide for guidance on isolating exacqVision NVRs and Enterprise Manager from public facing networks to reduce network exposure to attacks.
Mitigation: For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI
For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI-PSA-2021-24 v1
Mitigation: For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI
For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI-PSA-2022-01 v1

// References