Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.
CVSS Details
- CVSS 3.1 Base Score: 6.6
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade aws-kinesis-agent | Jul 4, 2022 | Dec 28, 2021 |
| Apache Log4j Core | — | apache-log4j-core-upgrade-2_3_2apache-log4j-core-upgrade-2_12_4apache-log4j-core-upgrade-2_17_1 | Dec 29, 2021 | Dec 28, 2021 |
| Debian | — | Upgrade apache-log4j2 | Jan 4, 2022 | Dec 28, 2021 |
| Freebsd | — | Upgrade rundeck3 | Feb 20, 2023 | Feb 16, 2023 |
| Ibm Was | — | Upgrade to minimal fix pack levels as required by interim fixes and then apply latest Interim Fix. | Aug 26, 2022 | Dec 28, 2021 |
| Oracle Weblogic | — | Apply the Patch Set Update (PSU) 33699205 for version 12.2.1.3.0.Apply the Patch Set Update (PSU) 33727616 for version 12.2.1.4.0.Apply the Patch Set Update (PSU) 33727619 for version 14.1.1.0.0. | Feb 28, 2022 | Jan 18, 2022 |
| Red Hat Jboss Eap | — | Upgrade Red Hat JBoss EAP to the latest version | Sep 19, 2024 | Dec 28, 2021 |
| Red_hat Jboss_eap | — | — | Apr 10, 2023 | Dec 28, 2021 |
| Suse | — | suse-upgrade-log4jsuse-upgrade-log4j-javadocsuse-upgrade-log4j-jclsuse-upgrade-log4j-slf4j | Dec 31, 2021 | Dec 28, 2021 |
| Ubuntu | ubuntu-upgrade-liblog4j2-java | Jan 12, 2022 | Dec 28, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub