Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.
CVSS Details
- CVSS 3.1 Base Score: 6.6
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | amazon-linux-ami-2-upgrade-aws-kinesis-agent | Jul 4, 2022 | Dec 28, 2021 | |
| Apache Log4j Core | — | apache-log4j-core-upgrade-2_3_2apache-log4j-core-upgrade-2_12_4apache-log4j-core-upgrade-2_17_1 | Dec 29, 2021 | Dec 28, 2021 |
| Debian | debian-upgrade-apache-log4j2 | Jan 4, 2022 | Dec 28, 2021 | |
| Freebsd | freebsd-upgrade-package-rundeck3 | Feb 20, 2023 | Feb 16, 2023 | |
| Ibm Was | ibm-was-upgrade-latest | Aug 26, 2022 | Dec 28, 2021 | |
| Oracle Weblogic | oracle-weblogic-jan-2022-cpu-12_2_1_3_0oracle-weblogic-jan-2022-cpu-12_2_1_4_0oracle-weblogic-jan-2022-cpu-14_1_1_0_0 | Feb 28, 2022 | Jan 18, 2022 | |
| Red Hat Jboss Eap | red-hat-jboss-eap-upgrade-latest | Sep 19, 2024 | Dec 28, 2021 | |
| Suse | — | suse-upgrade-log4jsuse-upgrade-log4j-javadocsuse-upgrade-log4j-jclsuse-upgrade-log4j-slf4j | Dec 31, 2021 | Dec 28, 2021 |
| Ubuntu | ubuntu-upgrade-liblog4j2-java | Jan 12, 2022 | Dec 28, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub