Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.
CVSS Details
- CVSS 3.1 Base Score: 10
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade java-1.7.0-openjdk-srcUpgrade java-11-openjdk-static-libs-debugUpgrade java-1.8.0-openjdk-src-debugUpgrade java-1.8.0-amazon-corretto-develUpgrade java-1.8.0-openjdk-javadoc-zip-debugUpgrade java-1.8.0-openjdk-headlessUpgrade java-1.8.0-openjdk-accessibility-debugUpgrade java-1.8.0-openjdk-headless-debugUpgrade java-11-amazon-correttoUpgrade java-17-amazon-corretto-jmodsUpgrade java-1.8.0-openjdk-demo-debugUpgrade java-11-openjdk-debuginfoUpgrade java-1.8.0-openjdk-debugUpgrade aws-kinesis-agentUpgrade java-1.8.0-openjdk-debuginfoUpgrade java-17-amazon-corretto-headlessUpgrade java-1.8.0-openjdk-srcUpgrade java-17-amazon-correttoUpgrade java-1.7.0-openjdkUpgrade java-11-openjdk-headlessUpgrade java-11-openjdk-devel-debugUpgrade java-1.7.0-openjdk-debuginfoUpgrade java-11-amazon-corretto-javadocUpgrade java-11-openjdk-headless-debugUpgrade java-1.8.0-openjdk-demoUpgrade java-11-openjdk-debugUpgrade java-1.8.0-openjdk-javadoc-zipUpgrade java-11-openjdk-javadoc-zip-debugUpgrade java-17-amazon-corretto-develUpgrade java-1.7.0-openjdk-demoUpgrade java-1.7.0-openjdk-develUpgrade java-11-openjdk-javadocUpgrade java-1.8.0-openjdkUpgrade java-11-openjdk-javadoc-debugUpgrade java-1.8.0-openjdk-devel-debugUpgrade java-1.8.0-openjdk-accessibilityUpgrade java-1.7.0-openjdk-accessibilityUpgrade java-1.8.0-openjdk-javadocUpgrade java-11-openjdk-jmods-debugUpgrade java-1.8.0-openjdk-develUpgrade java-11-openjdk-demoUpgrade java-11-amazon-corretto-headlessUpgrade java-1.8.0-amazon-correttoUpgrade java-1.7.0-openjdk-headlessUpgrade java-11-openjdk-develUpgrade java-17-amazon-corretto-javadocUpgrade java-1.7.0-openjdk-javadocUpgrade java-11-openjdk-srcUpgrade java-11-openjdk-javadoc-zipUpgrade java-1.8.0-openjdk-javadoc-debugUpgrade java-11-openjdk-demo-debugUpgrade java-11-openjdk-jmodsUpgrade java-11-openjdk-static-libsUpgrade java-11-openjdk-src-debugUpgrade java-11-openjdk | Jul 4, 2022 | Dec 10, 2021 |
| Amazon_linux | — | Upgrade java-1.6.0-openjdkUpgrade java-1.8.0-openjdkUpgrade java-1.7.0-openjdk | Dec 18, 2021 | Dec 10, 2021 |
| Apache Log4j Core | — | Upgrade Apache Log4j Core to 2.12.2Upgrade Apache Log4j Core to 2.16Upgrade Apache Log4j Core to 2.3.1 | Dec 12, 2021 | Dec 9, 2021 |
| Apache Ofbiz | — | Upgrade Apache OFBiz to the latest version | Dec 23, 2024 | Dec 10, 2021 |
| Apache Solr | — | Upgrade Apache Solr to the latest version | Nov 27, 2023 | Dec 10, 2021 |
| Debian | — | Upgrade apache-log4j2 | Dec 13, 2021 | Dec 10, 2021 |
| Freebsd | — | Upgrade openhabUpgrade bastillionUpgrade openhab2Upgrade opensearchUpgrade graylogUpgrade serviio | Nov 4, 2022 | Dec 15, 2021 |
| Ibm Was | — | Upgrade to minimal fix pack levels as required by interim fixes and then apply latest Interim Fix. | Aug 26, 2022 | Dec 10, 2021 |
| Panos | — | Update PAN-OS 10.0 to the latest workaround for your deviceUpdate PAN-OS 9.1 to the latest workaround for your deviceUpdate PAN-OS 2.1 to the latest workaround for your deviceUpdate PAN-OS 9.0 to the latest workaround for your device | Jun 22, 2022 | Dec 10, 2021 |
| Progress Moveit Automation | — | Upgrade Progress MOVEit Automation to the latest version | Nov 12, 2025 | Dec 10, 2021 |
| Red Hat Jboss Eap | — | Upgrade Red Hat JBoss EAP to the latest version | Sep 19, 2024 | Dec 10, 2021 |
| Sonicwall Email Security | — | Update SonicWall Email Security to version 10.0.13 or later | Sep 22, 2025 | Dec 11, 2021 |
| Sonicwall Email Security Appliances | — | — | Sep 4, 2025 | Dec 11, 2021 |
| Suse | — | Upgrade disruptorUpgrade logback-accessUpgrade log4j-jclUpgrade logback-examplesUpgrade log4jUpgrade log4j-javadocUpgrade disruptor-javadocUpgrade logbackUpgrade log4j-slf4jUpgrade jakarta-servlet-javadocUpgrade logback-javadocUpgrade jakarta-servlet | Dec 14, 2021 | Dec 10, 2021 |
| Ubuntu | — | Upgrade liblog4j2-javaUpgrade liblog4j2-java (Ubuntu Pro) | Dec 15, 2021 | Dec 10, 2021 |
| Vcenter Log4j | — | Upgrade to non vulnerable version of vCenter when available, or implement mitigation measures as detailed by VMware in KB87081 | Feb 4, 2022 | Jan 7, 2022 |
| Vmsa 2021 0028 | — | Upgrade to VMware Workspace ONE Access version 21.08.0.1.19010796Upgrade to VMware Workspace ONE Access version 20.10.0.1.17586971Upgrade to VMware Workspace ONE Access version 21.08.0.0.18530336Upgrade to VMware Workspace ONE Access version 20.10.0.0.17035009 | Jan 4, 2022 | Jan 4, 2022 |
| Vmware Horizon Agent | — | Upgrade VMware Horizon Agent to 8.4.0.19050247Upgrade VMware Horizon Agent to 7.13.0.19067039Upgrade VMware Horizon Agent to 7.10.3.19069158Upgrade VMware Horizon Agent to 7.13.1.19066964Upgrade VMware Horizon Agent to 7.10.3.19066964Upgrade VMware Horizon Agent to 8.4.0.18964730Upgrade VMware Horizon Agent to 7.13.1.19067315 | Feb 9, 2022 | Dec 10, 2021 |
| Vmware Horizon Connection Server | — | Upgrade VMware Horizon Connection Server to 7.10.3.19069415Upgrade VMware Horizon Connection Server to 7.13.1.19069458Upgrade VMware Horizon Connection Server to 8.4.0.19052438 | Feb 1, 2022 | Dec 10, 2021 |
| Vmware Vrealize | — | Upgrade vRealize to version 8.6.2.19081814 | Jan 4, 2022 | Jan 4, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub