Tracker / CVE-2021-45105
CVE-2021-45105
Media 5.9
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.
Prodotti e versioni affette
| apache | log4j · 2.0 → 2.3.1 |
|---|---|
| apache | log4j · 2.13.0 → 2.16.0 |
| apache | log4j · 2.4 → 2.12.3 |
| debian | debian_linux |
| netapp | cloud_manager |
| oracle | agile_engineering_data_management |
| oracle | agile_plm |
| oracle | agile_plm_mcad_connector |
| oracle | autovue_for_agile_product_lifecycle_management |
| oracle | banking_deposits_and_lines_of_credit_servicing |
| oracle | banking_enterprise_default_management |
| oracle | banking_loans_servicing |
| oracle | banking_party_management |
| oracle | banking_payments |
| oracle | banking_platform |
| oracle | banking_trade_finance |
| oracle | banking_treasury_management |
| oracle | business_intelligence |
| oracle | communications_asap |
| oracle | communications_billing_and_revenue_management |
| oracle | communications_cloud_native_core_console |
| oracle | communications_cloud_native_core_network_function_cloud_native_environment |
| oracle | communications_cloud_native_core_network_repository_function |
| oracle | communications_cloud_native_core_network_slice_selection_function |
| oracle | communications_cloud_native_core_policy |
| oracle | communications_cloud_native_core_security_edge_protection_proxy |
| oracle | communications_cloud_native_core_service_communication_proxy |
| oracle | communications_cloud_native_core_unified_data_repository |
| oracle | communications_convergence |
| oracle | communications_convergent_charging_controller |
| oracle | communications_convergent_charging_controller · 12.0.1.0.0 → 12.0.4.0.0 |
| oracle | communications_diameter_signaling_router · 8.3.0.0 → 8.5.1.0 |
| oracle | communications_eagle_element_management_system |
| oracle | communications_eagle_ftp_table_base_retrieval |
| oracle | communications_element_manager · … → 9.0 |
| oracle | communications_evolved_communications_application_server |
| oracle | communications_interactive_session_recorder |
| oracle | communications_ip_service_activator |
| oracle | communications_messaging_server |
| oracle | communications_network_charging_and_control |
| oracle | communications_network_charging_and_control · 12.0.1.0.0 → 12.0.4.0.0 |
| oracle | communications_network_integrity |
| oracle | communications_performance_intelligence_center |
| oracle | communications_pricing_design_center |
| oracle | communications_service_broker |
| oracle | communications_services_gatekeeper |
| oracle | communications_session_report_manager · … → 9.0 |
| oracle | communications_session_route_manager · … → 9.0 |
| oracle | communications_unified_inventory_management |
| oracle | communications_user_data_repository |
| oracle | communications_webrtc_session_controller |
| oracle | data_integrator |
| oracle | e-business_suite |
| oracle | enterprise_manager_base_platform |
| oracle | enterprise_manager_for_peoplesoft |
| oracle | enterprise_manager_ops_center |
| oracle | financial_services_analytical_applications_infrastructure · 8.0.7 → 8.1.1 |
| oracle | financial_services_model_management_and_governance |
| oracle | flexcube_universal_banking |
| oracle | flexcube_universal_banking · 12.1.0 → 12.4 |
Analisi
Questa pagina non è ancora indicizzabile.Finché non contiene un’analisi originale — cosa espone davvero, come verificare in due minuti se un sistema è stato toccato, cosa fare se lo è stato — la pagina resta noindex. È il database a deciderlo, non il modello di pagina.