imPC@ndo EN

Tracker / CVE-2021-44228

CVE-2021-44228

Ransomware Critica 10.0

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.

Prodotti e versioni affette

apache log4j
apache log4j · 2.0.1 → 2.3.1
apache log4j · 2.13.0 → 2.15.0
apache log4j · 2.4.0 → 2.12.2
apple xcode · … → 13.3
bentley synchro · 6.1 → 6.2.4.2
bentley synchro_4d · … → 6.4.3.2
cisco advanced_malware_protection_virtual_private_cloud_appliance · … → 3.5.4
cisco automated_subsea_tuning
cisco automated_subsea_tuning · … → 2.1.0
cisco broadworks
cisco broadworks · … → 2021.11_1.162
cisco business_process_automation · … → 3.0.000.115
cisco business_process_automation · 3.1.000.000 → 3.1.000.044
cisco business_process_automation · 3.2.000.000 → 3.2.000.009
cisco cloud_connect · … → 12.6\(1\)
cisco cloudcenter · … → 4.10.0.16
cisco cloudcenter_cost_optimizer · … → 5.5.2
cisco cloudcenter_suite
cisco cloudcenter_suite_admin · … → 5.3.1
cisco cloudcenter_workload_manager · … → 5.5.2
cisco common_services_platform_collector
cisco common_services_platform_collector · … → 2.9.1.3
cisco common_services_platform_collector · 2.10.0 → 2.10.0.1
cisco connected_mobile_experiences
cisco contact_center_domain_manager · … → 12.5\(1\)
cisco contact_center_management_portal · … → 12.5\(1\)
cisco crosswork_data_gateway
cisco crosswork_data_gateway · … → 2.0.2
cisco crosswork_network_automation
cisco crosswork_network_controller
cisco crosswork_network_controller · … → 2.0.1
cisco crosswork_optimization_engine
cisco crosswork_optimization_engine · … → 2.0.1
cisco crosswork_platform_infrastructure
cisco crosswork_platform_infrastructure · … → 4.0.1
cisco crosswork_zero_touch_provisioning
cisco crosswork_zero_touch_provisioning · … → 2.0.1
cisco customer_experience_cloud_agent · … → 1.12.1
cisco cx_cloud_agent
cisco cyber_vision
cisco cyber_vision_sensor_management_extension
cisco cyber_vision_sensor_management_extension · … → 4.0.3
cisco data_center_network_manager
cisco data_center_network_manager · … → 11.3\(1\)
cisco dna_center
cisco dna_center · … → 2.1.2.8
cisco dna_center · 2.2.2.0 → 2.2.2.8
cisco dna_center · 2.2.3.0 → 2.2.3.4
cisco dna_spaces
cisco dna_spaces\ · … → 2.5
cisco dna_spaces_connector
cisco emergency_responder
cisco emergency_responder · … → 11.5\(4\)
cisco enterprise_chat_and_email
cisco enterprise_chat_and_email · … → 12.0\(1\)
cisco evolved_programmable_network_manager
cisco evolved_programmable_network_manager · … → 4.1.1
cisco finesse
cisco finesse · … → 12.6\(1\)

Analisi

Questa pagina non è ancora indicizzabile.Finché non contiene un’analisi originale — cosa espone davvero, come verificare in due minuti se un sistema è stato toccato, cosa fare se lo è stato — la pagina resta noindex. È il database a deciderlo, non il modello di pagina.

Riferimenti