peter bassill · operator
$ cve CVE-2021-45046 JSON

CVE-2021-45046 KEV

9.0
CRITICAL · CVSS 3.1 · EPSS 100% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2023-05-22.

Description

It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in an information leak and remote code execution in some environments and local code execution in all environments. Log4j 2.16.0 (Java 8) and 2.12.2 (Java 7) fix this issue by removing support for message lookup patterns and disabling JNDI functionality by default.

Scoring

CVSS9.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS99.98% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-917
On CISA KEVyes — remediate by 2023-05-22
Public exploitnone known
Published2021-12-14
Last modified2026-06-17

CISA KEV

NameApache Log4j2 Deserialization of Untrusted Data Vulnerability
Added2023-05-01
Due2023-05-22
Vendor / productApache / Log4j2
Ransomware useknown

Affected (40)

VendorProduct
apachelog4j
cvatcomputer vision annotation tool
intelaudio development kit
inteldatacenter manager
intelgenomics kernel library
inteloneapi
intelsecure device onboard
intelsensor solution firmware development kit
intelsystem debugger
intelsystem studio
siemenscaptial
siemenscomos
siemensdesigo cc advanced reports
siemensdesigo cc info center
siemense-car operation center
siemensenergy engage
siemensenergyip
siemensenergyip prepay
siemensgma-manager
siemenshead-end system universal device integration system
siemensindustrial edge management
siemensindustrial edge management hub
siemenslogo\! soft comfort
siemensmendix
siemensmindsphere
siemensnavigator
siemensnx
siemensopcenter intelligence
siemensoperation scheduler
siemenssentron powermanager
siemenssiguard dsa
siemenssipass integrated
siemenssiveillance command
siemenssiveillance control pro
siemenssiveillance identity
siemenssiveillance vantage
siemenssiveillance viewpoint
siemenssolid edge cam pro
siemenssppa-t3000 ses3000
siemenssppa-t3000 ses3000 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD