imPC@ndo EN

Tracker / CVE-2021-45105

CVE-2021-45105

Media 5.9

Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.

Prodotti e versioni affette

apache log4j · 2.0 → 2.3.1
apache log4j · 2.13.0 → 2.16.0
apache log4j · 2.4 → 2.12.3
debian debian_linux
netapp cloud_manager
oracle agile_engineering_data_management
oracle agile_plm
oracle agile_plm_mcad_connector
oracle autovue_for_agile_product_lifecycle_management
oracle banking_deposits_and_lines_of_credit_servicing
oracle banking_enterprise_default_management
oracle banking_loans_servicing
oracle banking_party_management
oracle banking_payments
oracle banking_platform
oracle banking_trade_finance
oracle banking_treasury_management
oracle business_intelligence
oracle communications_asap
oracle communications_billing_and_revenue_management
oracle communications_cloud_native_core_console
oracle communications_cloud_native_core_network_function_cloud_native_environment
oracle communications_cloud_native_core_network_repository_function
oracle communications_cloud_native_core_network_slice_selection_function
oracle communications_cloud_native_core_policy
oracle communications_cloud_native_core_security_edge_protection_proxy
oracle communications_cloud_native_core_service_communication_proxy
oracle communications_cloud_native_core_unified_data_repository
oracle communications_convergence
oracle communications_convergent_charging_controller
oracle communications_convergent_charging_controller · 12.0.1.0.0 → 12.0.4.0.0
oracle communications_diameter_signaling_router · 8.3.0.0 → 8.5.1.0
oracle communications_eagle_element_management_system
oracle communications_eagle_ftp_table_base_retrieval
oracle communications_element_manager · … → 9.0
oracle communications_evolved_communications_application_server
oracle communications_interactive_session_recorder
oracle communications_ip_service_activator
oracle communications_messaging_server
oracle communications_network_charging_and_control
oracle communications_network_charging_and_control · 12.0.1.0.0 → 12.0.4.0.0
oracle communications_network_integrity
oracle communications_performance_intelligence_center
oracle communications_pricing_design_center
oracle communications_service_broker
oracle communications_services_gatekeeper
oracle communications_session_report_manager · … → 9.0
oracle communications_session_route_manager · … → 9.0
oracle communications_unified_inventory_management
oracle communications_user_data_repository
oracle communications_webrtc_session_controller
oracle data_integrator
oracle e-business_suite
oracle enterprise_manager_base_platform
oracle enterprise_manager_for_peoplesoft
oracle enterprise_manager_ops_center
oracle financial_services_analytical_applications_infrastructure · 8.0.7 → 8.1.1
oracle financial_services_model_management_and_governance
oracle flexcube_universal_banking
oracle flexcube_universal_banking · 12.1.0 → 12.4

Analisi

Questa pagina non è ancora indicizzabile.Finché non contiene un’analisi originale — cosa espone davvero, come verificare in due minuti se un sistema è stato toccato, cosa fare se lo è stato — la pagina resta noindex. È il database a deciderlo, non il modello di pagina.

Riferimenti