imPC@ndo IT

Tracker / CVE-2021-44832

CVE-2021-44832

Medium 6.6

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.

Affected products and versions

apache log4j
apache log4j · 2.0.1 → 2.3.2
apache log4j · 2.13.0 → 2.17.1
apache log4j · 2.4 → 2.12.4
cisco cloudcenter
debian debian_linux
fedoraproject fedora
oracle communications_brm_-_elastic_charging_engine
oracle communications_brm_-_elastic_charging_engine · … → 12.0.0.4.6
oracle communications_diameter_signaling_router · 8.0.0.0 → 8.5.1.0
oracle communications_diameter_signaling_router · 8.3.0.0 → 8.5.1.0
oracle communications_interactive_session_recorder
oracle communications_offline_mediation_controller
oracle communications_offline_mediation_controller · … → 12.0.0.4.4
oracle flexcube_private_banking
oracle health_sciences_data_management_workbench
oracle policy_automation · 12.2.0 → 12.2.24
oracle policy_automation_for_mobile_devices · 12.2.0 → 12.2.24
oracle primavera_gateway
oracle primavera_gateway · 17.12.0 → 17.12.11
oracle primavera_gateway · 18.8.0 → 18.8.13
oracle primavera_gateway · 19.12.0 → 19.12.12
oracle primavera_gateway · 20.12.0 → 20.12.7
oracle primavera_p6_enterprise_project_portfolio_management
oracle primavera_p6_enterprise_project_portfolio_management · 19.12.0 → 19.12.18.0
oracle primavera_p6_enterprise_project_portfolio_management · 19.12.0.0 → 19.12.18.0
oracle primavera_p6_enterprise_project_portfolio_management · 20.12.0.0 → 20.12.12.0
oracle primavera_unifier
oracle product_lifecycle_analytics
oracle retail_assortment_planning
oracle retail_fiscal_management
oracle retail_order_broker
oracle retail_xstore_point_of_service
oracle siebel_ui_framework
oracle siebel_ui_framework · … → 21.12
oracle weblogic_server

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References