{
    "id": "CVE-2021-45046",
    "published": "2021-12-14 19:15:07",
    "last_modified": "2026-06-17 04:13:05",
    "cvss_score": "9.0",
    "cvss_severity": "CRITICAL",
    "cvss_version": "3.1",
    "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
    "cwe": "CWE-917",
    "description": "It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in an information leak and remote code execution in some environments and local code execution in all environments. Log4j 2.16.0 (Java 8) and 2.12.2 (Java 7) fix this issue by removing support for message lookup patterns and disabling JNDI functionality by default.",
    "epss_score": "0.99977",
    "epss_percentile": "0.99979",
    "kev": 1,
    "kev_due": "2023-05-22",
    "has_exploit": 0,
    "updated_at": "2026-09-26 18:28:28",
    "priority": {
        "rank": 1,
        "label": "Patch first",
        "why": "On CISA KEV — known exploited in the wild, due 2023-05-22."
    },
    "products": [
        {
            "vendor": "apache",
            "product": "log4j"
        },
        {
            "vendor": "cvat",
            "product": "computer_vision_annotation_tool"
        },
        {
            "vendor": "intel",
            "product": "audio_development_kit"
        },
        {
            "vendor": "intel",
            "product": "datacenter_manager"
        },
        {
            "vendor": "intel",
            "product": "genomics_kernel_library"
        },
        {
            "vendor": "intel",
            "product": "oneapi"
        },
        {
            "vendor": "intel",
            "product": "secure_device_onboard"
        },
        {
            "vendor": "intel",
            "product": "sensor_solution_firmware_development_kit"
        },
        {
            "vendor": "intel",
            "product": "system_debugger"
        },
        {
            "vendor": "intel",
            "product": "system_studio"
        },
        {
            "vendor": "siemens",
            "product": "captial"
        },
        {
            "vendor": "siemens",
            "product": "comos"
        },
        {
            "vendor": "siemens",
            "product": "desigo_cc_advanced_reports"
        },
        {
            "vendor": "siemens",
            "product": "desigo_cc_info_center"
        },
        {
            "vendor": "siemens",
            "product": "e-car_operation_center"
        },
        {
            "vendor": "siemens",
            "product": "energy_engage"
        },
        {
            "vendor": "siemens",
            "product": "energyip"
        },
        {
            "vendor": "siemens",
            "product": "energyip_prepay"
        },
        {
            "vendor": "siemens",
            "product": "gma-manager"
        },
        {
            "vendor": "siemens",
            "product": "head-end_system_universal_device_integration_system"
        },
        {
            "vendor": "siemens",
            "product": "industrial_edge_management"
        },
        {
            "vendor": "siemens",
            "product": "industrial_edge_management_hub"
        },
        {
            "vendor": "siemens",
            "product": "logo\\!_soft_comfort"
        },
        {
            "vendor": "siemens",
            "product": "mendix"
        },
        {
            "vendor": "siemens",
            "product": "mindsphere"
        },
        {
            "vendor": "siemens",
            "product": "navigator"
        },
        {
            "vendor": "siemens",
            "product": "nx"
        },
        {
            "vendor": "siemens",
            "product": "opcenter_intelligence"
        },
        {
            "vendor": "siemens",
            "product": "operation_scheduler"
        },
        {
            "vendor": "siemens",
            "product": "sentron_powermanager"
        },
        {
            "vendor": "siemens",
            "product": "siguard_dsa"
        },
        {
            "vendor": "siemens",
            "product": "sipass_integrated"
        },
        {
            "vendor": "siemens",
            "product": "siveillance_command"
        },
        {
            "vendor": "siemens",
            "product": "siveillance_control_pro"
        },
        {
            "vendor": "siemens",
            "product": "siveillance_identity"
        },
        {
            "vendor": "siemens",
            "product": "siveillance_vantage"
        },
        {
            "vendor": "siemens",
            "product": "siveillance_viewpoint"
        },
        {
            "vendor": "siemens",
            "product": "solid_edge_cam_pro"
        },
        {
            "vendor": "siemens",
            "product": "sppa-t3000_ses3000"
        },
        {
            "vendor": "siemens",
            "product": "sppa-t3000_ses3000_firmware"
        }
    ],
    "kev_detail": {
        "cve_id": "CVE-2021-45046",
        "date_added": "2023-05-01",
        "due_date": "2023-05-22",
        "vendor": "Apache",
        "product": "Log4j2",
        "name": "Apache Log4j2 Deserialization of Untrusted Data Vulnerability",
        "ransomware": 1
    },
    "exploits": [],
    "refs_list": [
        "http://www.openwall.com/lists/oss-security/2021/12/14/4",
        "http://www.openwall.com/lists/oss-security/2021/12/15/3",
        "http://www.openwall.com/lists/oss-security/2021/12/18/1",
        "https://cert-portal.siemens.com/productcert/pdf/ssa-397453.pdf",
        "https://cert-portal.siemens.com/productcert/pdf/ssa-479842.pdf",
        "https://cert-portal.siemens.com/productcert/pdf/ssa-661247.pdf",
        "https://cert-portal.siemens.com/productcert/pdf/ssa-714170.pdf",
        "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EOKPQGV24RRBBI4TBZUDQMM4MEH7MXCY/",
        "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SIG7FZULMNK2XF6FZRU4VWYDQXNMUGAJ/",
        "https://logging.apache.org/log4j/2.x/security.html",
        "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0032",
        "https://security.gentoo.org/glsa/202310-16",
        "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd",
        "https://www.cve.org/CVERecord?id=CVE-2021-44228",
        "https://www.debian.org/security/2021/dsa-5022",
        "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00646.html",
        "https://www.kb.cert.org/vuls/id/930724",
        "https://www.oracle.com/security-alerts/alert-cve-2021-44228.html",
        "https://www.oracle.com/security-alerts/cpuapr2022.html",
        "https://www.oracle.com/security-alerts/cpujan2022.html",
        "https://www.oracle.com/security-alerts/cpujul2022.html",
        "http://www.openwall.com/lists/oss-security/2021/12/14/4",
        "http://www.openwall.com/lists/oss-security/2021/12/15/3",
        "http://www.openwall.com/lists/oss-security/2021/12/18/1",
        "https://cert-portal.siemens.com/productcert/pdf/ssa-397453.pdf"
    ]
}