Code Injection in Apache Log4j - CVE-2021-45046
Published: December 15, 2021 / Updated: April 14, 2025
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The
vulnerability exists due to incomplete patch in Apache Log4j 2.15.0 for
a code injection vulnerability #VU58816 (CVE-2021-44228) in certain
non-default configurations. A remote attacker with control over Thread
Context Map (MDC) input data when the logging configuration uses a
non-default Pattern Layout with either a Context Lookup (for example,
$${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) can
pass malicious data using a JNDI Lookup pattern and perform a denial of
service (DoS) attack, exfiltrate data or execute arbitrary code.
Later discovery demonstrates a remote code execution on macOS but no other tested environments.
Affected software
Nutanix Objects
Intel Datacenter Manager
Intel oneAPI sample browser plugin for Eclipse
Intel System Debugger
Intel Secure Device Onboard
IBM Data Management Platform for EDB Postgres Enterprise
IBM Data Management Platform for EDB Postgres Standard
IBM Disconnected Log Collector
IBM Spectrum Protect Snapshot for Windows
Red Hat OpenShift Container Platform
IBM Spectrum Protect Backup-Archive Client
Atlas Search
IBM DB2
UIoT
Enhanced Interactive Unified Mediation (eIUM)
vRO Plug-in for Dell EMC PowerStore
Authentication Server Function (AUSF)
Unified Data Management (UDM)
User Data Repository (UDR)
Unstructured Data Storage Function (UDSF)
Containerized private minion (CPM)
dgs-framework
PowerFlex Manager
PowerFlex Presentation Server
RecoverPoint Classic
Java agent
EMC Enterprise Storage Analytics for vRealize Operations
IBM Maximo Scheduler Optimization
Opencast
Dell Data Protection Central
PaperCut NG
PaperCut MF
Dell EMC OpenManage Enterprise Services
Remote SIM Provisioning Manager (RSPM)
Dell EMC Streaming Data Platform
Dell EMC OpenManage Enterprise Modular
Dell EMC PowerStore Family Operating System
Edge Infrastructure Automation
IBM Planning Analytics Workspace
Real Time Management System (RTMS)
Dynamic SIM Provisioning (DSP)
EMC ECS
Service Director (SD)
Dell Support Assist Enterprise
3PAR Service Processors
Dell EMC Metro Node
Trueview Inventory Software Series
Sterling Configure, Price, Quote
Fraud Risk Management (FRM)
Dell EMC Cloud Disaster Recovery
Dell EMC vProtect
SPPA-T3000 Application Server
API Gateway
JBoss Enterprise Application Platform
Fuse
Amazon Linux AMI
Gentoo Linux
IBM Security Identity Manager Virtual Appliance
openEuler
Ubuntu
Fedora
NetAtlas Element Management System (EMS)
IBM DCNM
IBM DS8000 Hardware Management Console
Intel Audio Development Kit
PortEx
IBM Cloud Private
SoapUI
Deep Discovery Director
IBM App Connect Enterprise
Silver Peak Orchestrator
Dell EMC VxRail Appliance
IBM SANnav Management Portal
IBM SANnav Global View
IBM Telco Network Cloud Manager - Performance (TNCP)
SPSS Statistics Subscription
i2 Connect
IBM Observability with Instana Infrastructure Quality Monitoring
IBM Observability with Instana Application Performance Monitoring
IBM Observability by Instana Application Performance Monitoring
IBM Observability by Instana Infrastructure Quality Monitoring
z/Transaction Processing Facility ( z/TPF)
IBM Netcool Agile Service Manager
IBM PureData System for Operational Analytics
Jazz for Service Management
IBM Cloud Application Business Insights
TPF Operations Server
IBM Operations Analytics Predictive Insights
Sterling Connect Direct File Agent
Netcool Operations Insight
IBM Spectrum Protect Snapshot for VMware
IBM Spectrum Copy Data Management
IBM Cloud Pak for Multicloud Management Monitoring
IBM Spectrum Conductor
IBM Cloud Transformation Advisor
IBM Security Guardium Key Lifecycle Manager (GKLM)
Okta RADIUS Server Agent
Red Hat Advanced Cluster Security for Kubernetes
IBM Security Guardium Insights
IBM SPSS Analytic Server
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Guardium Data Encryption (GDE)
FileCap Server
IBM Tivoli System Automation Application Manager
IBM Sterling Connect:Direct for UNIX
i2 Analyze
IBM Spectrum Scale for IBM Elastic Storage Server
IBM Elastic Storage System
IBM Sterling B2B Integrator
Nutanix AOS
Red Hat Integration Camel-K
IBM Sterling Connect:Direct Web Services
IBM Sterling Partner Engagement Manager
IBM Sterling Connect:Direct for zOS
IBM Tivoli Monitoring
IBM Spectrum Protect Operations Center
IBM Tivoli Netcool Impact
IBM Spectrum Symphony
StoredIQ
Netcool/OMNIbus
IBM Security Access Manager for Enterprise Single-Sign On
IBM Common Licensing
IBM MQ
IBM Customer and Network Analytics for Communications Service Providers and Datasets
IBM Spectrum Protect Plus
IBM Spectrum Protect Plus Container Backup and Restore for Kubernetes
IBM Spectrum Protect Plus Container Backup and Restore for OpenShift
RSA RT
IBM Robotic Process Automation with Automation Anywhere
IBM SPSS Modeler
Dell EMC Data Protection Search
IBM SPSS Statistics Server
Operations Dashboard
Log Analysis
IBM Decision Optimization for Cloud Pak for Data
Dell EMC Unisphere Central
IBM Cloud Application Performance Management (APM)
IBM Tivoli Netcool/OMNIbus Integration – Transport Module Common Integration Library
IBM Maximo Application Suite
Connectrix MDS-DCNM
EMC Data Protection Advisor
EMC NetWorker Server
Dell NetWorker Virtual Edition
IBM Tivoli Netcool/OMNIbus Integration – Java Netcool Utility Library
Automation Assets in IBM Cloud Pak for Integration (CP4I)
API Manager
IBM Integrated Analytics System
Cloudera Data Platform Private Cloud Base for IBM
i2 Analyst's Notebook Premium
Oracle Business Activity Monitoring
HPE SANnav Management Software
Metabase
IBM Cognos Analytics
Planning Analytics Local
Cloud Pak for Security (CP4S)
Event Streams
IBM Cognos Controller
IBM SPSS Statistics Desktop
Cloud Pak for Data
JBoss Data Grid
eap7-jboss-server-migration (Red Hat package)
eap7-wildfly-elytron (Red Hat package)
apache-log4j2 (Debian package)
eap7-undertow (Red Hat package)
eap7-jboss-xnio-base (Red Hat package)
eap7-hibernate (Red Hat package)
eap7-wildfly (Red Hat package)
eap7-wildfly-openssl-el7 (Red Hat package)
eap7-wildfly-openssl-el8 (Red Hat package)
thrift-devel
python3-thrift
perl-thrift
libthrift-java
thrift-debugsource
thrift
thrift-qt
thrift-glib
wildfly-elytron
wildfly-elytron-javadoc
eap7-yasson (Red Hat package)
wildfly-common
wildfly-common-help
wildfly-security-manager
wildfly-security-manager-javadoc
wildfly-build-tools-javadoc
wildfly-feature-pack-build-maven-plugin
wildfly-server-provisioning
wildfly-server-provisioning-maven-plugin
wildfly-server-provisioning-standalone
wildfly-build-tools
eap7-xom (Red Hat package)
eap7-jettison (Red Hat package)
eap7-velocity (Red Hat package)
eap7-snakeyaml (Red Hat package)
avalon-logkit-help
avalon-logkit
wildfly-core-javadoc
wildfly-core
wildfly-core-feature-pack
eap7-wildfly-openssl (Red Hat package)
HikariCP-help
HikariCP
jenkins-json-lib
json-lib-help
json-lib
eap7-jackson-databind (Red Hat package)
eap7-jackson-core (Red Hat package)
eap7-jackson-annotations (Red Hat package)
eap7-jackson-modules-java8 (Red Hat package)
eap7-jackson-jaxrs-providers (Red Hat package)
eap7-jackson-modules-base (Red Hat package)
log4j-bom
log4j-jmx-gui
log4j-web
log4j-help
log4j-jcl
log4j-taglib
log4j-nosql
log4j-slf4j
log4j
liblog4j2-java (Ubuntu package)
eap7-activemq-artemis (Red Hat package)
eap7-log4j (Red Hat package)
mx4j-javadoc
mx4j-manual
mx4j
eap7-resteasy (Red Hat package)
metrics-servlet
metrics-servlets
metrics
metrics-parent
metrics-annotation
metrics-logback
metrics-log4j2
metrics-log4j
metrics-jvm
metrics-json
metrics-jersey2
metrics-jdbi
metrics-javadoc
metrics-httpasyncclient
metrics-healthchecks
metrics-graphite
metrics-ganglia
metrics-httpclient
metrics-ehcache
metrics-benchmarks
metrics-doc
eap7-apache-cxf (Red Hat package)
datanucleus-api-jdo-javadoc
datanucleus-api-jdo
mybatis
mybatis-javadoc
datanucleus-rdbms
datanucleus-rdbms-javadoc
datanucleus-core
datanucleus-core-javadoc
eap7-jboss-vfs (Red Hat package)
eap7-hal-console (Red Hat package)
springframework
springframework-tx
springframework-web
springframework-oxm
springframework-orm-hibernate4
springframework-orm
springframework-jms
springframework-jdbc
springframework-instrument
springframework-help
springframework-expression
springframework-context
springframework-beans
springframework-aop
jboss-logging
jboss-logging-javadoc
apache-zookeeper
jgroups-help
jgroups
eap7-ecj (Red Hat package)
netty
netty-help
eap7-netty (Red Hat package)
avalon-framework
avalon-framework-help
eap7-jbossws-cxf (Red Hat package)
eap7-narayana (Red Hat package)
net-wireless/unifi
infinispan
infinispan-help
eap7-objectweb-asm (Red Hat package)
eap7-infinispan (Red Hat package)
IBM Cloud Pak System
EMC Integrated Data Protection Appliance
IBM Security SOAR
Zoho ManageEngine EventLog Analyzer
Apache Struts
IBM Analytic Accelerator Framework for Communication Service Providers
CF Deployment
Rundeck
Dell EMC Storage Monitoring and Reporting (SMR)
IBM Spectrum Scale
IBM Sterling File Gateway
Dell Storage Manager
IBM Sterling Global Mailbox (GM)
IBM Spectrum Protect for Virtual Environments: Data Protection for VMware
IBM Spectrum Protect for Virtual Environments: Data Protection for Hyper-V
IBM Security Guardium
IBM Spectrum Protect for Space Management
IntroSpect
HPE StoreServ Management Console
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
vCenter Server Appliance
Informix Dynamic Server
How to mitigate CVE-2021-45046
API Manager - update to February 2022
API Gateway - update to February 2022
Metabase - addressed in versions 0.41.5, 1.41.5
IBM Integrated Analytics System - update to 1.0.26.3
vRO Plug-in for Dell EMC PowerStore - addressed in versions 1.0.4, 1.1.1, 1.2.4
IBM Netcool Agile Service Manager - update to 1.1.10
Jazz for Service Management - update to 1.1.3.13
IBM Disconnected Log Collector - update to 1.7.2
eap7-jboss-server-migration (Red Hat package) - addressed in versions 1.10.0-15.Final_redhat_00014.1.el7eap, 1.10.0-15.Final_redhat_00014.1.el8eap
eap7-wildfly-elytron (Red Hat package) - addressed in versions 1.15.11-1.Final_redhat_00002.1.el7eap, 1.15.11-1.Final_redhat_00002.1.el8eap
Authentication Server Function (AUSF) - addressed in versions 1.2109.1, 1.2112.0
Unified Data Management (UDM) - addressed in versions 1.2109.2, 1.2112.0
User Data Repository (UDR) - update to 1.2112.0
Unstructured Data Storage Function (UDSF) - update to 1.2112.0
apache-log4j2 (Debian package) - addressed in versions 2.16.0-1~deb10u1, 2.16.0-1~deb11u1
Containerized private minion (CPM) - update to 3.0.57
PortEx - update to 3.0.3
eap7-undertow (Red Hat package) - addressed in versions 2.2.16-1.Final_redhat_00001.1.el7eap, 2.2.16-1.Final_redhat_00001.1.el8eap
IBM Spectrum Copy Data Management - update to 2.2.14.2
IBM Cloud Pak for Multicloud Management Monitoring - update to 2.3 Fixpack 4
EMC Integrated Data Protection Appliance - update to 2.7.3
Apache Struts - update to 2.5.28.1
IBM Security Guardium Key Lifecycle Manager (GKLM) - addressed in versions 4.1 FP3, 4.1.1 FP3
Okta RADIUS Server Agent - update to 2.17.1
dgs-framework - update to 4.9.14
Red Hat Advanced Cluster Security for Kubernetes - update to 3.68
Rundeck - addressed in versions 3.3.16, 3.4.8
PowerFlex Manager - update to 3.8.0-8187
PowerFlex Presentation Server - addressed in versions 3.5.1.5, 3.6.0.3
eap7-jboss-xnio-base (Red Hat package) - addressed in versions 3.8.6-1.Final_redhat_00001.1.el7eap, 3.8.6-1.Final_redhat_00001.1.el8eap
IBM Analytic Accelerator Framework for Communication Service Providers - update to 4.0.0.2
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.0.5
FileCap Server - update to 5.1.2
IBM Spectrum Protect Snapshot for Windows - addressed in versions 7.1.8.14, 8.1.13.2
Dell EMC Storage Monitoring and Reporting (SMR) - addressed in versions 4.5.0.2, 4.6.0.2
Red Hat OpenShift Container Platform - addressed in versions 4.6.52, 4.7.40
RecoverPoint Classic - update to 5.1 SP4 P4
SoapUI - update to 5.6.1
Deep Discovery Director - update to 5.3 CP B1225
eap7-hibernate (Red Hat package) - addressed in versions 5.3.25-1.Final_redhat_00002.1.el7eap, 5.3.25-1.Final_redhat_00002.1.el8eap
Java agent - addressed in versions 6.5.3, 7.4.3
EMC Enterprise Storage Analytics for vRealize Operations - addressed in versions 6.1.1, 6.2.2, 6.3.0
Red Hat Integration Camel-K - update to 6.1.3
IBM Sterling Partner Engagement Manager - addressed in versions 6.1.2.3.4, 6.2.0.1.3
JBoss Enterprise Application Platform - addressed in versions 7.1.9, 7.3.12, 7.4.4
IBM Spectrum Protect Operations Center - addressed in versions 7.1.14.200, 8.1.13.200
IBM Spectrum Protect for Virtual Environments: Data Protection for VMware - addressed in versions 7.1.8.14, 8.1.13.2
IBM Spectrum Protect for Space Management - addressed in versions 7.1.8.14, 8.1.13.2
IBM Spectrum Protect Backup-Archive Client - addressed in versions 7.1.8.14, 8.1.13.2
eap7-wildfly (Red Hat package) - addressed in versions 7.1.9-2.GA_redhat_00002.1.ep7.el7, 7.3.12-3.GA_redhat_00002.1.el7eap, 7.4.4-3.GA_redhat_00011.1.el7eap, 7.4.4-3.GA_redhat_00011.1.el8eap
StoredIQ - update to siq_7_6_0_22_log4j_2_17_1_
Fuse - addressed in versions 7.8.2, 7.9.1, 7.10.1
IBM Maximo Scheduler Optimization - update to 8.0.3
Netcool/OMNIbus - update to 8.1.0.28
IBM Spectrum Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.1.13.2
Opencast - addressed in versions 9.11, 10.7, 11.1
IBM Customer and Network Analytics for Communications Service Providers and Datasets - update to 10.0.0.2
IBM Spectrum Protect Plus - update to 10.1.9.2
IBM Spectrum Protect Plus Container Backup and Restore for Kubernetes - update to 10.1.9.2
IBM Spectrum Protect Plus Container Backup and Restore for OpenShift - update to 10.1.9.2
IBM Cognos Analytics - addressed in versions 11.0.13.4, 11.1.7.7, 11.2.1.2
IBM DB2 - addressed in versions 11.5.6.0, 11.5.7.0
CF Deployment - update to 17.1.0
Dell EMC Data Protection Search - addressed in versions 19.6.1, 19.6.2
Dell Data Protection Central - update to 19.5.0.8
PaperCut NG - update to 21.2.4
PaperCut MF - update to 21.2.4
IBM Security SOAR - addressed in versions 42.2.41, 43.0.7662
Zoho ManageEngine EventLog Analyzer - update to 12213
eap7-wildfly-openssl-el7 (Red Hat package) - update to x86_64-2.2.0-2.Final_redhat_00002.1.el7eap
eap7-wildfly-openssl-el8 (Red Hat package) - update to x86_64-2.2.0-2.Final_redhat_00002.1.el8eap
thrift-devel - addressed in versions 0.14.0-4, 0.14.0-5
python3-thrift - addressed in versions 0.14.0-4, 0.14.0-5
perl-thrift - addressed in versions 0.14.0-4, 0.14.0-5
libthrift-java - addressed in versions 0.14.0-4, 0.14.0-5
thrift-debugsource - addressed in versions 0.14.0-4, 0.14.0-5
thrift - addressed in versions 0.14.0-4, 0.14.0-5
thrift-qt - addressed in versions 0.14.0-4, 0.14.0-5
thrift-glib - addressed in versions 0.14.0-4, 0.14.0-5
wildfly-elytron - update to 1.0.2-2
wildfly-elytron-javadoc - update to 1.0.2-2
eap7-yasson (Red Hat package) - addressed in versions 1.0.10-1.redhat_00001.1.el7eap, 1.0.10-1.redhat_00001.1.el8eap
wildfly-common - update to 1.1.0-8
wildfly-common-help - update to 1.1.0-8
wildfly-security-manager - update to 1.1.2-2
wildfly-security-manager-javadoc - update to 1.1.2-2
wildfly-build-tools-javadoc - update to 1.1.6-2
wildfly-feature-pack-build-maven-plugin - update to 1.1.6-2
wildfly-server-provisioning - update to 1.1.6-2
wildfly-server-provisioning-maven-plugin - update to 1.1.6-2
wildfly-server-provisioning-standalone - update to 1.1.6-2
wildfly-build-tools - update to 1.1.6-2
Dell EMC OpenManage Enterprise Services - update to 1.2.1
Remote SIM Provisioning Manager (RSPM) - addressed in versions 1.3GA HF08, 1.3.2 HF04, 1.4.1 HF04
Dell EMC Streaming Data Platform - update to 1.3.1.1
eap7-xom (Red Hat package) - addressed in versions 1.3.7-1.redhat_00001.1.el7eap, 1.3.7-1.redhat_00001.1.el8eap
Log Analysis - update to 1.3.7.2 IF002
eap7-jettison (Red Hat package) - addressed in versions 1.3.8-2.redhat_00002.1.ep7.el7, 1.5.2-2.redhat_00002.1.el7eap
eap7-velocity (Red Hat package) - update to 1.7.0-3.redhat_00006.1.ep7.el7
eap7-snakeyaml (Red Hat package) - addressed in versions 1.33.0-1.SP1_redhat_00001.1.el7eap, 1.33.0-1.SP1_redhat_00001.1.ep7.el7
Dell EMC OpenManage Enterprise Modular - update to 1.40.10
Dell EMC PowerStore Family Operating System - update to 2.0.1.3-1538564
Edge Infrastructure Automation - update to 2.0.6.1
Planning Analytics Local - update to 2.0.9.11
IBM Planning Analytics Workspace - update to 2.0.72
HPE SANnav Management Software - addressed in versions 2.1.1.7, 2.2.0.1
avalon-logkit-help - addressed in versions 2.1-33, 2.1-34
avalon-logkit - addressed in versions 2.1-33, 2.1-34
wildfly-core-javadoc - addressed in versions 2.2.0-2, 2.2.0-3
wildfly-core - addressed in versions 2.2.0-2, 2.2.0-3
wildfly-core-feature-pack - addressed in versions 2.2.0-2, 2.2.0-3
eap7-wildfly-openssl (Red Hat package) - addressed in versions 2.2.0-3.Final_redhat_00002.1.el7eap, 2.2.0-3.Final_redhat_00002.1.el8eap
HikariCP-help - addressed in versions 2.4.3-5, 2.4.3-6
HikariCP - addressed in versions 2.4.3-5, 2.4.3-6
jenkins-json-lib - addressed in versions 2.4-18, 2.4-19
json-lib-help - addressed in versions 2.4-18, 2.4-19
json-lib - addressed in versions 2.4-18, 2.4-19
IntroSpect - update to 2.5.0.7
eap7-jackson-databind (Red Hat package) - addressed in versions 2.8.11.6-2.SP1_redhat_00002.1.ep7.el7, 2.10.4-4.redhat_00004.1.el7eap
eap7-jackson-core (Red Hat package) - update to 2.10.4-2.redhat_00004.1.el7eap
eap7-jackson-annotations (Red Hat package) - update to 2.10.4-2.redhat_00004.1.el7eap
eap7-jackson-modules-java8 (Red Hat package) - update to 2.10.4-2.redhat_00004.1.el7eap
eap7-jackson-jaxrs-providers (Red Hat package) - update to 2.10.4-2.redhat_00004.1.el7eap
eap7-jackson-modules-base (Red Hat package) - update to 2.10.4-4.redhat_00004.1.el7eap
log4j-bom - addressed in versions 2.13.2-3, 2.17.0-1, 2.17.0-3
log4j-jmx-gui - addressed in versions 2.13.2-3, 2.17.0-1, 2.17.0-3
log4j-web - addressed in versions 2.13.2-3, 2.17.0-1, 2.17.0-3
log4j-help - addressed in versions 2.13.2-3, 2.17.0-1, 2.17.0-3
log4j-jcl - addressed in versions 2.13.2-3, 2.17.0-1, 2.17.0-3
log4j-taglib - addressed in versions 2.13.2-3, 2.17.0-1, 2.17.0-3
log4j-nosql - update to 2.13.2-3
log4j-slf4j - addressed in versions 2.13.2-3, 2.17.0-1, 2.17.0-3
log4j - addressed in versions 2.13.2-3, 2.17.0-1, 2.17.0-3
liblog4j2-java (Ubuntu package) - addressed in versions 2.16.0-0.20.04.1, 2.16.0-0.21.04.1, 2.16.0-0.21.10.1
eap7-activemq-artemis (Red Hat package) - addressed in versions 2.16.0-7.redhat_00034.1.el7eap, 2.16.0-7.redhat_00034.1.el8eap
log4j - addressed in versions 2.17.0-1.fc34, 2.17.0-1.fc35
eap7-log4j (Red Hat package) - addressed in versions 2.17.1-1.redhat_00001.1.el7eap, 2.17.1-1.redhat_00001.1.el8eap
mx4j-javadoc - addressed in versions 3.0.1-2, 3.0.1-3
mx4j-manual - addressed in versions 3.0.1-2, 3.0.1-3
mx4j - addressed in versions 3.0.1-2, 3.0.1-3
eap7-resteasy (Red Hat package) - addressed in versions 3.0.27-1.Final_redhat_00001.1.ep7.el7, 3.11.6-1.Final_redhat_00001.1.el7eap
Real Time Management System (RTMS) - update to 3.00.72.1
Dynamic SIM Provisioning (DSP) - addressed in versions 3.1.2 HF02, 3.3.0 HF03, 3.4.0 HF01
metrics-servlet - addressed in versions 3.1.2-2, 3.1.2-3
metrics-servlets - addressed in versions 3.1.2-2, 3.1.2-3
metrics - addressed in versions 3.1.2-2, 3.1.2-3
metrics-parent - addressed in versions 3.1.2-2, 3.1.2-3
metrics-annotation - addressed in versions 3.1.2-2, 3.1.2-3
metrics-logback - addressed in versions 3.1.2-2, 3.1.2-3
metrics-log4j2 - addressed in versions 3.1.2-2, 3.1.2-3
metrics-log4j - addressed in versions 3.1.2-2, 3.1.2-3
metrics-jvm - addressed in versions 3.1.2-2, 3.1.2-3
metrics-json - addressed in versions 3.1.2-2, 3.1.2-3
metrics-jersey2 - addressed in versions 3.1.2-2, 3.1.2-3
metrics-jdbi - addressed in versions 3.1.2-2, 3.1.2-3
metrics-javadoc - addressed in versions 3.1.2-2, 3.1.2-3
metrics-httpasyncclient - addressed in versions 3.1.2-2, 3.1.2-3
metrics-healthchecks - addressed in versions 3.1.2-2, 3.1.2-3
metrics-graphite - addressed in versions 3.1.2-2, 3.1.2-3
metrics-ganglia - addressed in versions 3.1.2-2, 3.1.2-3
metrics-httpclient - addressed in versions 3.1.2-2, 3.1.2-3
metrics-ehcache - addressed in versions 3.1.2-2, 3.1.2-3
metrics-benchmarks - addressed in versions 3.1.2-2, 3.1.2-3
metrics-doc - addressed in versions 3.1.2-2, 3.1.2-3
eap7-apache-cxf (Red Hat package) - update to 3.1.16-4.redhat_00003.1.ep7.el7
datanucleus-api-jdo-javadoc - addressed in versions 3.2.8-2, 3.2.8-3
datanucleus-api-jdo - addressed in versions 3.2.8-2, 3.2.8-3, 3.2.15-3
mybatis - update to 3.2.8-3
mybatis-javadoc - update to 3.2.8-3
datanucleus-rdbms - addressed in versions 3.2.13-2, 3.2.13-4
datanucleus-rdbms-javadoc - addressed in versions 3.2.13-2, 3.2.13-4
datanucleus-core - addressed in versions 3.2.15-2, 3.2.15-3
datanucleus-core-javadoc - addressed in versions 3.2.15-2, 3.2.15-3
eap7-jboss-vfs (Red Hat package) - addressed in versions 3.2.16-1.Final_redhat_00001.1.el7eap, 3.2.16-1.Final_redhat_00001.1.el8eap
eap7-hal-console (Red Hat package) - addressed in versions 3.2.17-1.Final_redhat_00001.1.el7eap, 3.3.9-1.Final_redhat_00001.1.el7eap, 3.3.9-1.Final_redhat_00001.1.el8eap
springframework - addressed in versions 3.2.18-9, 3.2.18-10
springframework-tx - addressed in versions 3.2.18-9, 3.2.18-10
springframework-web - addressed in versions 3.2.18-9, 3.2.18-10
springframework-oxm - addressed in versions 3.2.18-9, 3.2.18-10
springframework-orm-hibernate4 - addressed in versions 3.2.18-9, 3.2.18-10
springframework-orm - addressed in versions 3.2.18-9, 3.2.18-10
springframework-jms - addressed in versions 3.2.18-9, 3.2.18-10
springframework-jdbc - addressed in versions 3.2.18-9, 3.2.18-10
springframework-instrument - addressed in versions 3.2.18-9, 3.2.18-10
springframework-help - addressed in versions 3.2.18-9, 3.2.18-10
springframework-expression - addressed in versions 3.2.18-9, 3.2.18-10
springframework-context - addressed in versions 3.2.18-9, 3.2.18-10
springframework-beans - addressed in versions 3.2.18-9, 3.2.18-10
springframework-aop - addressed in versions 3.2.18-9, 3.2.18-10
EMC ECS - addressed in versions 3.3.0.4, 3.4.0.6, 3.5.1.6, 3.6.2.1, 3.6.2.2, 3.7.0
jboss-logging - addressed in versions 3.3.0-6, 3.3.0-7
jboss-logging-javadoc - addressed in versions 3.3.0-6, 3.3.0-7
Cloud Pak for Data - addressed in versions 3.5.10, 4.0.5
IBM Decision Optimization for Cloud Pak for Data - addressed in versions 3.5.11, 4.0.5
apache-zookeeper - update to 3.6.1-2.3
jgroups-help - addressed in versions 3.6.10-7, 3.6.10-8
jgroups - addressed in versions 3.6.10-7, 3.6.10-8
Service Director (SD) - update to 3.7.1-PB2
HPE StoreServ Management Console - update to 3.8.2.1
eap7-ecj (Red Hat package) - addressed in versions 3.26.0-1.redhat_00002.1.el7eap, 3.26.0-1.redhat_00002.1.el8eap
Dell EMC Unisphere Central - update to 4.0.9.1541235
netty - addressed in versions 4.1.13-14, 4.1.13-15
netty-help - addressed in versions 4.1.13-14, 4.1.13-15
eap7-netty (Red Hat package) - addressed in versions 4.1.63-1.Final_redhat_00002.1.ep7.el7, 4.1.63-4.Final_redhat_00002.1.el7eap
avalon-framework - addressed in versions 4.3-23, 4.3-24
avalon-framework-help - addressed in versions 4.3-23, 4.3-24
Dell EMC VxRail Appliance - update to 4.5.471
Dell Support Assist Enterprise - update to 5.00.06
3PAR Service Processors - update to 5.0.9.2
Dell EMC Unity Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC Unity VSA Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC Unity XT Operating Environment (OE) - update to 5.1.2.0.5.007
eap7-jbossws-cxf (Red Hat package) - addressed in versions 5.4.4-1.Final_redhat_00001.1.el7eap, 5.4.4-1.Final_redhat_00001.1.el8eap
eap7-narayana (Red Hat package) - addressed in versions 5.11.4-1.Final_redhat_00001.1.el7eap, 5.11.4-1.Final_redhat_00001.1.el8eap
vCenter Server Appliance - addressed in versions 6.5 U3s, 6.7 U3q, 7.0 U3c
net-wireless/unifi - update to 6.5.55
Dell EMC Metro Node - update to 7.0.1.02.00.01
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
IBM Tivoli Netcool/OMNIbus Integration – Transport Module Common Integration Library - update to 8.2
JBoss Data Grid - update to 8.2.3
infinispan - addressed in versions 8.2.4-9, 8.2.4-10
infinispan-help - addressed in versions 8.2.4-9, 8.2.4-10
IBM Maximo Application Suite - addressed in versions 8.6.3, 8.7.1
Trueview Inventory Software Series - addressed in versions 8.6.22.1, 8.7.3
eap7-objectweb-asm (Red Hat package) - addressed in versions 9.1.0-1.redhat_00002.1.el7eap, 9.1.0-1.redhat_00002.1.el8eap
Sterling Configure, Price, Quote - update to 10.0.0.24
eap7-infinispan (Red Hat package) - addressed in versions 11.0.15-1.Final_redhat_00001.1.el7eap, 11.0.15-1.Final_redhat_00001.1.el8eap
Connectrix MDS-DCNM - addressed in versions 11.5(4), 12.1.1e
Informix Dynamic Server - addressed in versions 12.10.FC15W1, 14.10.FC7W1
Fraud Risk Management (FRM) - addressed in versions 14.0.2 Revision 10, 14.1 Revision 3
EMC Data Protection Advisor - addressed in versions 19.4 B104, 19.5 B74, 19.6 B24
EMC NetWorker Server - addressed in versions 19.4.0.6, 19.5.0.5, 19.6.0
Dell NetWorker Virtual Edition - addressed in versions 19.4.0.6, 19.5.0.5, 19.6.0
Dell EMC Cloud Disaster Recovery - addressed in versions 19.6.0.3, 19.7.0.3, 19.8.0.7, 19.9.0.4
Dell EMC vProtect - update to 19.9.0.430-4
Dell Storage Manager - update to 20.1.2
IBM Tivoli Netcool/OMNIbus Integration – Java Netcool Utility Library - update to 33.2
IBM DS8000 Hardware Management Console - addressed in versions 88.50.184.0, 89.12.8.0
Automation Assets in IBM Cloud Pak for Integration (CP4I) - update to 2021.4.1-2
Links to Public Exploits and PoC-codes
- Exploit #7194 - log4j2_vul_local_scanner (Log4j 漏洞本地检测脚本。 Scan all java processes on your host to check whether it's affected by log4j2 remote code execution vulnerability (CVE-2021-45046)) (December 21, 2021)
- Exploit #7181 - CVE-2021-45046-Info (Oh no another one) (December 16, 2021)
- Exploit #7171 - Log4j_CVE-2021-45046 (Log4j 2.15.0 Privilege Escalation -- CVE-2021-45046) (December 15, 2021)
External References
Related Security Bulletins
- Improper input validation in Apache Log4j
- Remote code execution in Intel Audio Development Kit (Apache Log4j component)
- Remote code execution in Intel Datacenter Manager (Apache Log4j component)
- Remote code execution in Intel oneAPI sample browser plugin for Eclipse (Apache Log4j component)
- Remote code execution in Intel System Debugger (Apache Log4j component)
- Remote code execution in Intel Secure Device Onboard (Apache Log4j component)
- Remote code execution in Rundeck (Apache Log4j component)
- Remote code execution in Siemens SPPA-T3000 (Apache Log4j component)
- OpenShift Container Platform 4.6 update for log4j
- PortEx update for Apache Log4j
- Metabase update for Apache Log4j
- FileCap Server update for Apache Log4j
- Remote code execution in Zyxel NetAtlas EMS (Apache Log4j component)
- Debian update for apache-log4j2
- Amazon Linux AMI update for java-1.8.0-openjdk, java-1.7.0-openjdk, java-1.6.0-openjdk
- Multiple vulnerabilities in CF Deployment
- Netflix dgs-framework update for Apache Log4j
- Multiple Vulnerabilities PaperCut MF
- Multiple Vulnerabilities PaperCut NG
- Remote code execution in Atlas Search (Apache Log4j component)
- Opencast update for Apache Log4j
- Multiple Vulnerabilities in Containerized private minion (CPM)
- Multiple Vulnerabilities in Java agent
- Multiple vulnerabilities in IBM SPSS Analytic Server
- Multiple vulnerabilities in Trend Micro Deep Discovery Director (Apache Log4j component)
- Multiple vulnerabilities in IBM Cloud Application Business Insights
- Code injection in IBM Cloud Private (Apache Log4j component)
- Multiple vulnerabilities in Sterling Connect Direct File Agent
- Multiple vulnerabilities in IBM Cognos Controller (Apache Log4j component)
- Multiple vulnerabilities in IBM Cognos Analytics (Apache Log4j component)
- Zoho ManageEngine EventLog Analyzer update for Apache Log4j
- Multiple vulnerabilities in IBM Jazz for Service Management (Apache Log4j component)
- Multiple vulnerabilities in IBM Sterling Connect:Direct Web Services
- Multiple vulnerabilities in IBM Event Streams
- Multiple vulnerabilities in IBM SPSS Statistics Desktop
- Multiple vulnerabilities in IBM SPSS Statistics Server
- Multiple vulnerabilities in SPSS Statistics Subscription
- Multiple vulnerabilities in IBM DB2 (Apache Log4j component)
- Multiple vulnerabilities in IBM SPSS Modeler
- Multiple vulnerabilities in IBM Spectrum Protect Operations Center (Apache Log4j component)
- Multiple vulnerabilities in IBM SANnav
- Remote code execution in IBM DCNM (Apache Log4j component)
- Multiple vulnerabilities in IBM SPSS Statistics
- Multiple vulnerabilities in Dell EMC Unity (Apache Log4j component)
- Multiple vulnerabilities in IBM Guardium Data Encryption (GDE)
- Multiple vulnerabilities in IBM Security Guardium
- Multiple vulnerabilities in IBM Common Licensing
- Multiple vulnerabilities in Storage Center-Dell Storage Manager
- Multiple vulnerabilities in Nutanix AOS
- Multiple vulnerabilities in Nutanix Objects
- IBM App Connect Enterprise update for Apache Log4j
- Multiple vulnerabilities in IBM Sterling File Gateway
- Multiple vulnerabilities in IBM Sterling B2B Integrator
- Multiple vulnerabilities in IBM Elastic Storage System (Apache Log4j component)
- Multiple vulnerabilities in IBM Spectrum Scale
- Multiple vulnerabilities in IBM Spectrum Scale for IBM Elastic Storage Server
- Multiple vulnerabilities in IBM i2 Analyze, i2 Analyst's Notebook Premium and IBM i2 Connect
- Dell EMC Unisphere Central update for Apache Log4j
- Remote code execution in IBM Sterling Global Mailbox (Apache Log4j component)
- Multiple vulnerabilities in IBM Spectrum Protect Plus Container Backup and Restore
- Multiple vulnerabilities in IBM Spectrum Protect Plus
- Multiple vulnerabilities in IBM Sterling Connect:Direct for UNIX
- Multiple vulnerabilities in IBM Spectrum Copy Data Management
- Remote code execution in Apache Struts (Apache Log4j component)
- Multiple vulnerabilities in IBM Tivoli System Automation Application Manager
- Multiple vulnerabilities in IBM Spectrum Protect for Space Management
- Multiple vulnerabilities in IBM Sterling Partner Engagement Manager
- Multiple vulnerabilities in IBM Sterling Connect:Direct for z/OS
- Multiple vulnerabilities in IBM Tivoli Monitoring
- Multiple vulnerabilities in SoapUI
- Multiple vulnerabilities in IBM Spectrum Protect Snapshot for Windows
- IBM Tivoli Netcool Impact update for Apache Log4j
- Multiple vulnerabilities in IBM Spectrum Protect Snapshot for VMware
- Multiple vulnerabilities in IBM Security SOAR
- Multiple vulnerabilities in IBM Spectrum Protect Backup-Archive Client
- Multiple vulnerabilities in IBM Spectrum Protect for Virtual Environments: Data Protection for VMware
- Multiple vulnerabilities in IBM Spectrum Protect for Virtual Environments: Data Protection for Hyper-V
- z/Transaction Processing Facility (z/TPF) update for Apache Log4j
- IBM TPF Operations Server update for Apache Log4j
- Multiple vulnerabilities in IBM Security Guardium Key Lifecycle Manager (GKLM)
- Multiple vulnerabilities in IBM Spectrum Symphony
- Remote code execution in IBM Operations Dashboard (Apache Log4j component)
- Multiple vulnerabilities in IBM MQ
- Multiple vulnerabilities in Red Hat Fuse
- Multiple vulnerabilities in IBM Telco Network Cloud Manager - Performance (TNCP)
- Multiple vulnerabilities in IBM Security Access Manager for Enterprise Single-Sign On
- Multiple vulnerabilities in IBM Robotic Process Automation with Automation Anywhere
- Multiple vulnerabilities in Cloud Pak for Security (CP4S)
- Multiple vulnerabilities in RSA RT
- Multiple vulnerabilities in Red Hat Integration Camel-K
- Multiple vulnerabilities in IBM Disconnected Log Collector
- Multiple vulnerabilities in IBM Integrated Analytics System
- Multiple vulnerabilities in IBM Spectrum Symphony
- Multiple vulnerabilities in IBM Spectrum Conductor
- Multiple vulnerabilities in IBM Operations Analytics Predictive Insights
- Multiple vulnerabilities in IBM Netcool Agile Service Manager
- Multiple vulnerabilities in IBM Security Guardium Insights
- Multiple vulnerabilities in IBM Observability with Instana Infrastructure Quality Monitoring
- Multiple vulnerabilities in IBM Observability with Instana Application Performance Monitoring
- Multiple vulnerabilities in IBM Observability by Instana Infrastructure Quality Monitoring
- Multiple vulnerabilities in IBM Observability by Instana Application Performance Monitoring
- Multiple vulnerabilities in IBM Tivoli Netcool/OMNIbus
- Multiple vulnerabilities in IBM Data Management Platform for EDB Postgres Enterprise
- Multiple vulnerabilities in IBM Data Management Platform for EDB Postgres Standard
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in IBM Cloud Pak for Multicloud Management Monitoring
- Multiple vulnerabilities in IBM Cloud Pak System
- Multiple vulnerabilities in Cloudera Data Platform Private Cloud Base for IBM
- Multiple vulnerabilities in Red Hat JBoss Enterprise Application Platform
- JBoss Enterprise Application Platform 7.4 for RHEL 8 update for log4j
- JBoss Enterprise Application Platform 7.4 for RHEL 7 update for log4j
- Multiple vulnerabilities in IBM Informix Dynamic Server
- Multiple vulnerabilities in IBM PureData System for Operational Analytics
- Multiple vulnerabilities in IBM DS8000 Hardware Management Console
- Multiple vulnerabilities in IBM Db2
- Multiple vulnerabilities in IBM Tivoli Netcool/OMNIbus Common Integration Libraries
- Amazon Linux AMI update for log4j-cve-2021-44228-hotpatch
- Multiple vulnerabilities in IBM Analytic Accelerator Framework for Communication Service Providers & IBM Customer and Network Analytics for Communications Service Providers and Datasets
- Ubuntu update for apache-log4j2
- Multiple Vulnerabilities in IBM StoredIQ
- Multiple vulnerabilities in IBM Maximo Scheduler Optimization
- Multiple vulnerabilities in Dell Data Protection Search
- Multiple vulnerabilities in IBM Security Identity Manager Virtual Appliance
- Multiple vulnerabilities in Dell EMC Support Assist Enterprise
- Multiple vulnerabilities in Dell EMC VxRail
- Multiple vulnerabilities in Dell EMC Cloud Disaster Recovery
- Multiple vulnerabilities in Dell EMC OpenManage Enterprise Services
- Multiple vulnerabilities in Dell EMC Streaming Data Platform
- Multiple vulnerabilities in Dell EMC OpenManage Enterprise Modular
- Multiple vulnerabilities in Dell EMC PowerStore Family Operating System
- Multiple vulnerabilities in Dell EMC ECS
- Multiple vulnerabilities in Dell EMC vProtect
- Multiple vulnerabilities in Dell PowerFlex Rack
- Remote code execution in in Dell EMC Metro Node
- Multiple vulnerabilities in Dell Connectrix MDS-DCNM
- Multiple vulnerabilities in Dell NetWorker
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in Dell Data Protection Search
- Multiple vulnerabilities in Automation Assets in IBM Cloud Pak for Integration
- Okta RADIUS Server Agent update for Apache Log4j2
- Multiple vulnerabilities in HPE B-Series SANnav Management Software
- Multiple vulnerabilities in HPE Universal IoT (UIoT) Log4j
- Multiple vulnerabilities in HPE Network Functions
- Multiple vulnerabilities in HPE Fraud Risk Management Software Series
- Multiple vulnerabilities in HPE Remote SIM Provisioning Manager (RSPM)
- Multiple vulnerabilities in HPE Dynamic SIM Provisioning (DSP)
- Multiple vulnerabilities in HPE 3PAR Service Processors
- Multiple vulnerabilities in HPE Trueview Inventory Software Series
- Multiple vulnerabilities in HPE enhanced Interactive Unified Mediation (eIUM)
- Multiple vulnerabilities in HPE Edge Infrastructure Automation
- Multiple vulnerabilities in API Gateway and API Manager
- Multiple vulnerabilities in IBM Maximo Application Suite
- Multiple vulnerabilities in Dell RecoverPoint Classic
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Code injection in IBM Operations Analytics - Log Analysis
- Multiple vulnerabilities in IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Decision Optimization for Cloud Pak for Data
- Gentoo update for Ubiquiti UniFi
- Multiple vulnerabilities in IBM Application Performance Management products
- openEuler update for log4j,jboss-logging,jgroups,json-lib,metrics,mx4j,netty,springframework,thrift,HikariCP,avalon-framework,avalon-logkit,datanucleus-api-jdo,datanucleus-core,datanucleus-rdbms,infinispan,wildfly-core,apache-zookeeper
- openEuler update for log4j,mybatis,netty,springframework,wildfly-security-manager,wildfly-elytron,wildfly-build-tools,wildfly-common,wildfly-core,thrift,json-lib,datanucleus-core,jgroups,mx4j,jboss-logging,infinispan,datanucleus-rdbms,avalon-logkit,datanu
- openEuler 20.03 LTS SP3 update for log4j
- Multiple vulnerabilities in IBM Sterling Configure, Price, Quote
- Multiple vulnerabilities in IBM Planning Analytics and IBM Planning Analytics Workspace
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.7
- Multiple vulnerabilities in JBoss Data Grid 8.2
- Fedora 35 update for log4j
- Fedora 34 update for log4j
- Multiple vulnerabilities in Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
- Multiple vulnerabilities in Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7
- Multiple vulnerabilities in HPE Real Time Management System (RTMS)
- Multiple vulnerabilities in HPE 3PAR/Primera StoreServ Management Console (SSMC)
- Multiple vulnerabilities in HPE Service Director (SD)
- Multiple vulnerabilities in HPE Aruba Silver Peak Orchestrator and Aruba IntroSpect
- Dell EMC Storage Monitoring and Reporting (SMR) update for Apache Log4j
- Dell Enterprise Storage Analytics for vRealize Operations update for Apache Log4j
- vRO Plug-in for Dell EMC PowerStore update for Apache Log4j
- Dell Data Protection Advisor update for Apache Log4j
- Dell Data Protection Central update for Apache Log4j
- Code Injection in Oracle Business Activity Monitoring