Code Injection in Apache Log4j - CVE-2021-44228
Published: December 10, 2021 / Updated: April 14, 2025
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation when processing LDAP requests. A remote attacker can send a specially crafted request to the application and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Note, we are aware of attackers exploiting the vulnerability in the wild.
Affected software
Nutanix Objects
VMware Workspace One Access
eap7-jboss-server-migration (Red Hat package)
eap7-wildfly-elytron (Red Hat package)
apache-log4j2 (Debian package)
eap7-undertow (Red Hat package)
eap7-jboss-xnio-base (Red Hat package)
eap7-hibernate (Red Hat package)
eap7-wildfly (Red Hat package)
eap7-wildfly-openssl-el7 (Red Hat package)
eap7-wildfly-openssl-el8 (Red Hat package)
thrift
libthrift-java
perl-thrift
python3-thrift
thrift-debugsource
thrift-devel
thrift-glib
thrift-qt
wildfly-elytron
wildfly-elytron-javadoc
eap7-yasson (Red Hat package)
wildfly-common-help
wildfly-common
wildfly-security-manager
wildfly-security-manager-javadoc
wildfly-build-tools-javadoc
wildfly-server-provisioning-standalone
wildfly-feature-pack-build-maven-plugin
wildfly-server-provisioning
wildfly-build-tools
wildfly-server-provisioning-maven-plugin
storm-supervisor
storm
storm-nimbus
log4j12
log4j12-help
eap7-xom (Red Hat package)
eap7-jettison (Red Hat package)
eap7-velocity (Red Hat package)
flink
eap7-snakeyaml (Red Hat package)
jansi
avalon-logkit-help
avalon-logkit
wildfly-core-javadoc
wildfly-core
wildfly-core-feature-pack
eap7-wildfly-openssl (Red Hat package)
HikariCP-help
HikariCP
json-lib-help
jenkins-json-lib
json-lib
eap7-jackson-databind (Red Hat package)
liblog4j2-java (Ubuntu package)
eap7-jackson-annotations (Red Hat package)
eap7-jackson-core (Red Hat package)
eap7-jackson-jaxrs-providers (Red Hat package)
eap7-jackson-modules-java8 (Red Hat package)
eap7-jackson-modules-base (Red Hat package)
log4j-jmx-gui
log4j-nosql
log4j-slf4j
log4j-taglib
log4j-jcl
log4j-help
log4j-web
log4j-bom
log4j
eap7-activemq-artemis (Red Hat package)
eap7-log4j (Red Hat package)
mx4j-manual
mx4j-javadoc
mx4j
eap7-resteasy (Red Hat package)
metrics-httpclient
metrics-servlet
metrics-parent
metrics-logback
metrics-log4j2
metrics-log4j
metrics-annotation
metrics-jvm
metrics-json
metrics-jersey2
metrics-jdbi
metrics-javadoc
metrics-httpasyncclient
metrics-benchmarks
metrics-doc
metrics-servlets
metrics-ehcache
metrics-healthchecks
metrics-graphite
metrics-ganglia
metrics
eap7-apache-cxf (Red Hat package)
datanucleus-api-jdo
datanucleus-api-jdo-javadoc
mybatis
mybatis-javadoc
datanucleus-rdbms-javadoc
datanucleus-rdbms
datanucleus-core
datanucleus-core-javadoc
eap7-jboss-vfs (Red Hat package)
eap7-hal-console (Red Hat package)
springframework-jms
springframework-help
springframework-expression
springframework-jdbc
springframework-context
springframework-tx
springframework-beans
springframework-aop
springframework-orm
springframework-orm-hibernate4
springframework-oxm
springframework-web
springframework-instrument
springframework
jboss-logging
jboss-logging-javadoc
apache-zookeeper
jgroups-help
jgroups
eap7-ecj (Red Hat package)
netty
netty-help
eap7-netty (Red Hat package)
avalon-framework
avalon-framework-help
eap7-jbossws-cxf (Red Hat package)
eap7-narayana (Red Hat package)
infinispan-help
infinispan
eap7-objectweb-asm (Red Hat package)
eap7-infinispan (Red Hat package)
Riverbed UCExpert
Scon EX Director
CloudVision Portal
Scon EX Analytics
Tanzu Greenplum
VMware Tanzu GemFire
FortiSOAR
FortiAIOps
FortiConverter
FortiCASB
PowerManage
Tanzu Scheduler
Telco Cloud Operations
AppDefense Appliance
VMware vCenter Cloud Gateway
Spring Cloud Gateway for Kubernetes
VMware Tanzu Kubernetes Grid Integrated Edition
Smart Assurance SAM
Riverbed NetIM
Riverbed Portal
EMC NetWorker Server
Dell NetWorker Virtual Edition
Smart Assurance NCM
vRealize Business for Cloud
Wowza Streaming Engine
Rational Test Automation Server
Apache Ozone
Apache EventMesh
Apache Archiva
Apache Tika
SPSS Statistics Subscription
Carbon Black Cloud Workload appliance
IBM Netcool Agile Service Manager
IBM PureData System for Operational Analytics
Jazz for Service Management
IBM Cloud Application Business Insights
Log Analysis
IBM Spectrum Protect Snapshot for VMware
IBM Watson Assistant for IBM Cloud Pak for Data
Netcool Operations Insight
Apache Geode
openHAB Distribution
IBM Cloud Transformation Advisor
IBM Spectrum Copy Data Management
VMware Tanzu Application Service for VMs
IBM Spectrum Conductor
Okta RADIUS Server Agent
DeepGit
GitHub Enterprise Server
Financial Transaction Manager for ACH Services and Check Services
Financial Transaction Manager for Digital Payments (DP)
Financial Transaction Manager for Corporate Payment Services (CPS)
IBM Watson Knowledge Catalog in Cloud Pak for Data
VMware HCX
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
FileCap Server
IBM Edge Application Manger
IBM Spectrum Scale for IBM Elastic Storage Server
IBM Spectrum Control
IBM Sterling B2B Integrator
Nutanix AOS
SYNCHRO 4D Pro
Red Hat Integration Camel-K
NSX Data Center for vSphere
IBM Sterling Connect:Direct for zOS
IBM UrbanCode Release
IBM Tivoli Monitoring
IBM Spectrum Symphony
StoredIQ
vSphere Replication
Netcool/OMNIbus
IBM Business Process Manager
Industry Models – IBM Insurance Information Warehouse
Industry Models – IBM Banking and Financial Markets Data Warehouse
IBM Sterling Transformation Extender
IBM Spectrum Protect Plus
RSA RT
InfoSphere Master Data Management
IBM Business Automation Workflow
Dell EMC Data Protection Search
Sumo Logic
IBM SPSS Statistics Server
IBM Resilient SOAR
Database Performance Analyzer
API Portal for VMware Tanzu
Spring Cloud Gateway for VMware Tanzu
Healthwatch for Tanzu Application Service
Single Sign-On for VMware Tanzu Application Service
Cloud Director Object Storage Extension
Horizon Cloud Connector
App Metrics
VMware Tanzu Observability by Wavefront Nozzle
Dell EMC VNXe3200
Spring Cloud Services for VMware Tanzu
IBM Decision Optimization for Cloud Pak for Data
Dell EMC Unisphere Central
Dell Secure Connect Gateway
IBM Global High Availability Mailbox
Carbon Black EDR Server
IBM Cloud Application Performance Management (APM)
IBM Tivoli Netcool/OMNIbus Integration – Transport Module Common Integration Library
IBM Maximo Application Suite
IBM Common Licensing
Connectrix MDS-DCNM
EMC Data Protection Advisor
Security Director Insights
IBM Tivoli Netcool/OMNIbus Integration – Java Netcool Utility Library
Operations Dashboard
Automation Assets in IBM Cloud Pak for Integration (CP4I)
Intel Secure Device Onboard
Intel System Debugger
Intel oneAPI sample browser plugin for Eclipse
Intel Datacenter Manager
Integrated OpenStack
ZAP
Apache JMeter
Red Hat OpenShift Container Platform
Amazon Linux AMI
HPE Helion Openstack
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
Ubuntu
openEuler
Fedora
Telco Cloud Automation
vRealize Orchestrator
NSX
VMware Tanzu Operations Manager
vCenter Server
VMware Horizon
Aria Automation (formerly vRealize Automation)
VMware Identity Manager
Symantec Advanced Authentication
Dell EMC Ruckus Virtual Software
Power Protect Data Manager (PPDM)
BSN Controller Node
UIoT
Enhanced Interactive Unified Mediation (eIUM)
InCenter
Risk Intelligence
F-Secure Policy Manager for Linux
F-Secure Policy Manager Proxy
F-Secure Policy Manager Proxy for Linux
F-Secure Endpoint Proxy
MobileIron Core Connector
VMware Workspace One Access Connector
Spectator
vRO Plug-in for Dell EMC PowerStore
Netflix Atlas
Apache Calcite Avatica
unimus
Authentication Server Function (AUSF)
Unified Data Management (UDM)
Unstructured Data Storage Function (UDSF)
User Data Repository (UDR)
Containerized private minion (CPM)
Apache Fortress
OpenMRS Platform
Reference Application
dgs-framework
SkyWalking
PowerFlex Manager
PowerFlex Presentation Server
OFBiz
NoTouch Center
Dell Policy Manager for Secure Connect Gateway (SCG)
RecoverPoint Classic
EMC Enterprise Storage Analytics for vRealize Operations
Java agent
The Java Graphical Authorship Attribution Program
UrbanCode Build
IBM Engineering Lifecycle Optimization - Publishing
DevOps
vRealize Suite Lifecycle Manager
IBM Maximo Scheduler Optimization
IBM Engineering Systems Design Rhapsody
Opencast
Content Manager OnDemand for Multiplatforms
Dell Data Protection Central
PaperCut NG
PaperCut MF
Ivanti File Director
vRO Plug-in for Dell EMC PowerScale
Dell EMC OpenManage Enterprise Services
OpenSearch
Remote SIM Provisioning Manager (RSPM)
Dell EMC Streaming Data Platform
Oxygen Feedback
Gradle Enterprise Test Distribution Agent
Arduino IDE
Dell EMC OpenManage Enterprise Modular
Dell EMC PowerStore Family Operating System
Edge Infrastructure Automation
IBM Planning Analytics Workspace
Oxygen Content Fusion
Git Client
Real Time Management System (RTMS)
Dynamic SIM Provisioning (DSP)
Batch Documents Converter
EMC ECS
Dell Wyse Management Suite
Service Director (SD)
Dell Support Assist Enterprise
3PAR Service Processors
Alertus Console
UniFi Network Application
Dell EMC Metro Node
Stardog
Yellowfin
Trueview Inventory Software Series
Sterling Configure, Price, Quote
Build Cache Node
LucaNet
Fraud Risk Management (FRM)
Dell EMC Cloud Disaster Recovery
Dell EMC vProtect
LiveNX
LiveNA
Oxygen Web Author Test Server Add-on
Oxygen XML Developer
Oxygen XML WebHelp
Oxygen PDF Chemistry
Oxygen XML Publishing Engine
Oxygen XML Author
XSD to JSON Schema Converter
Oxygen XML Web Author
Web Author PDF Plugin
Oxygen License Server
Gradle Enterprise
Dell EMC Ruckus SmartZone 100 Controller
Dell EMC Ruckus SmartZone 300 Controller
VNXe1600
HPE StoreServ Management Console
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
VMWare Unified Access Gateway
eCatcher
Intel Audio Development Kit
PortEx
Nelson
Kafka Connect for Azure Cosmos DB
SwingSet
Jena
Jedis
Neo4j: Graphs for Everyone
Deep Discovery Director
SoapUI
Ghidra
Apple Xcode
SPPA-T3000 Application Server
API Gateway
AMQ Streams
IBM Informix Dynamic Server on Cloud Pak for Data
Bitbucket Server
JBoss Enterprise Application Platform
Fuse
IBM WebSphere Application Server
NetAtlas Element Management System (EMS)
IBM DCNM
IBM DS8000 Hardware Management Console
Horizon DaaS
Reporting Database (RDB)
Cloud Pak for Security (CP4S)
EMC ESRS Policy Manager
Apache Solr
Aria Operations for Logs (formerly vRealize Log Insight)
IBM Cognos Controller
Cloud Pak for Data
JBoss Data Grid
Endpoint Manager Mobile (formerly MobileIron Core)
Apache Traffic Control
FortiPortal
EMC Integrated Data Protection Appliance
FortiNAC
MobileIron Sentry
Zoho ManageEngine EventLog Analyzer
Atlas Search
Apache Nifi
Apache Hive
Flink
IBM DB2
Apache Druid
F-Secure Policy Manager
Silver Peak Orchestrator
Dell EMC VxRail Appliance
API Manager
Apereo CAS
HPE SANnav Management Software
Metabase
Graylog
Operational Decision Manager
IBM Cognos Analytics
Planning Analytics Local
Apache Spark
CF Deployment
Industry Models – IBM Data Model For Energy and Utilities
IBM TRIRIGA Application Platform
IBM TRIRIGA
Dell EMC Storage Monitoring and Reporting (SMR)
exacqVision Enterprise System Manager
Avalanche
Industry Models – IBM Unified Data Model for Healthcare
IBM Cloud Pak System
Cloud Foundation
VMware Aria Operations (formerly vRealize Operations)
vCenter Server Appliance
Crypto Hardware Initialization and Maintenance (CHIM)
FortiSIEM
Rundeck
Apache Tapestry
SecureTransport
IBM Sterling File Gateway
Dell Storage Manager
Rational Publishing Engine
RecoverPoint
RecoverPoint for VMs
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
cPanel
Sitecore XP
YouTrack
Symantec Endpoint Protection Manager
Minecraft
EMC ViPR SRM
EMC Data Domain
Informix Dynamic Server
Hub
How to mitigate CVE-2021-44228
VMware Tanzu GemFire - addressed in versions 1.13.4, 1.14.1
PowerManage - update to 4.10
API Manager - update to February 2022
API Gateway - update to February 2022
Apache Nifi - update to 1.15.1
PortEx - addressed in versions 3.0.2, 3.0.3
Spectator - update to 1.0.9
Metabase - addressed in versions 0.38.6, 0.39.7, 0.40.7, 0.41.4, 1.38.6, 1.39.7, 1.40.7, 1.41.4
Apache Ozone - update to 1.2.1
Apache EventMesh - update to 1.3.0
Apache Archiva - update to 2.2.6
ZAP - update to 2.11.1
Apache Tika - addressed in versions 1.28, 2.2.1
Apache Spark - update to 3.3.0
vRO Plug-in for Dell EMC PowerStore - addressed in versions 1.0.4, 1.1.1, 1.2.4
eCatcher - update to 6.7.6
Kafka Connect for Azure Cosmos DB - update to 1.2.1
Apache Traffic Control - addressed in versions 5.1.5, 6.0.2
Jazz for Service Management - update to 1.1.3.13
Netflix Atlas - update to 1.7.0
IBM Spectrum Protect Snapshot for VMware - update to 4.1.6.13
AMQ Streams - addressed in versions 1.6.5, 1.8.4
Apache Calcite Avatica - update to 1.20.0
eap7-jboss-server-migration (Red Hat package) - addressed in versions 1.10.0-15.Final_redhat_00014.1.el7eap, 1.10.0-15.Final_redhat_00014.1.el8eap
unimus - update to 2.1.4
Flink - addressed in versions 1.11.6, 1.13.4, 1.14.1, 1.15.0
Apache Geode - addressed in versions 1.12.6, 1.13.5, 1.14.1
eap7-wildfly-elytron (Red Hat package) - addressed in versions 1.15.11-1.Final_redhat_00002.1.el7eap, 1.15.11-1.Final_redhat_00002.1.el8eap
Authentication Server Function (AUSF) - addressed in versions 1.2109.1, 1.2112.0
Unified Data Management (UDM) - addressed in versions 1.2109.2, 1.2112.0
Unstructured Data Storage Function (UDSF) - update to 1.2112.0
User Data Repository (UDR) - update to 1.2112.0
apache-log4j2 (Debian package) - addressed in versions 2.16.0-1~deb10u1, 2.16.0-1~deb11u1
Containerized private minion (CPM) - update to 3.0.57
SwingSet - update to 4.0.6
Apache JMeter - update to 5.4.1
openHAB Distribution - addressed in versions 3.0.4, 3.1.1
Apache Fortress - update to 2.0.7
eap7-undertow (Red Hat package) - addressed in versions 2.2.16-1.Final_redhat_00001.1.el7eap, 2.2.16-1.Final_redhat_00001.1.el8eap
IBM Spectrum Copy Data Management - update to 2.2.14.1
FortiPortal - addressed in versions 5.3.8, 6.0.8
VMware Tanzu Application Service for VMs - addressed in versions 2.7.42, 2.10.22, 2.11.10, 2.12.3
OpenMRS Platform - update to 2.4.2
EMC Integrated Data Protection Appliance - update to 2.7.3
VMware Tanzu Operations Manager - update to 2.10.23
Jena - update to 4.3.1
Okta RADIUS Server Agent - update to 2.17.0
Reference Application - update to 2.12.1
dgs-framework - update to 4.9.11
Jedis - addressed in versions 3.7.1, 4.0.0 rc2
DeepGit - update to 4
GitHub Enterprise Server - addressed in versions 3.0.22, 3.1.14, 3.2.6, 3.3.1
Crypto Hardware Initialization and Maintenance (CHIM) - update to 3.0.1
SkyWalking - update to 8.9.1
Rundeck - addressed in versions 3.3.16, 3.4.8
Graylog - addressed in versions 3.3.15, 4.0.14, 4.1.9, 4.2.3
PowerFlex Manager - update to 3.8.0-8187
PowerFlex Presentation Server - addressed in versions 3.5.1.5, 3.6.0.3
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 3.5.8, 4.0.4
eap7-jboss-xnio-base (Red Hat package) - addressed in versions 3.8.6-1.Final_redhat_00001.1.el7eap, 3.8.6-1.Final_redhat_00001.1.el8eap
Red Hat OpenShift Container Platform - addressed in versions 4.6.52, 4.7.40, 4.8.24
OFBiz - update to 18.12.03
IBM Informix Dynamic Server on Cloud Pak for Data - update to 4.0.1
VMware HCX - addressed in versions 4.1.0.2, 4.2.3
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.0.5
FileCap Server - update to 5.1.1
Neo4j: Graphs for Everyone - addressed in versions 4.2.12, 4.3.8, 4.4.1
NoTouch Center - update to 4.5.231
Dell EMC Storage Monitoring and Reporting (SMR) - addressed in versions 4.5.0.2, 4.6.0.2
Apache Tapestry - update to 5.8.0
Dell Policy Manager for Secure Connect Gateway (SCG) - update to 5.00.05.11
RecoverPoint Classic - update to 5.1 SP4 P4
Deep Discovery Director - update to 5.3 CP B1225
SoapUI - update to 5.6.1
eap7-hibernate (Red Hat package) - addressed in versions 5.3.25-1.Final_redhat_00002.1.el7eap, 5.3.25-1.Final_redhat_00002.1.el8eap
IBM Spectrum Control - update to 5.4.5.1
SecureTransport - update to 5.5-20220127
exacqVision Enterprise System Manager - update to 21.12.1
EMC Enterprise Storage Analytics for vRealize Operations - addressed in versions 6.1.1, 6.2.2, 6.3.0
Java agent - addressed in versions 6.5.3, 7.4.3, 7.5.0
The Java Graphical Authorship Attribution Program - update to 8.0.2
SYNCHRO 4D Pro - addressed in versions 6.2.4.2, 6.4.3.2
Red Hat Integration Camel-K - update to 6.1.3
NSX Data Center for vSphere - update to 6.4.12
IBM UrbanCode Release - update to 6.2.5.5
Apereo CAS - addressed in versions 6.3.7.2, 6.4.4
Bitbucket Server - addressed in versions 6.10.16, 7.6.12, 7.14.2, 7.15.3, 7.16.3, 7.17.4, 7.18.3, 7.19.1, 7.21.0
EMC ESRS Policy Manager - update to 7.1
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.11.1
DevOps - update to 7.1.0.2
JBoss Enterprise Application Platform - addressed in versions 7.1.9, 7.3.12, 7.4.4
Apache Solr - update to 8.11.1
eap7-wildfly (Red Hat package) - addressed in versions 7.1.9-2.GA_redhat_00002.1.ep7.el7, 7.3.12-3.GA_redhat_00002.1.el7eap, 7.4.4-3.GA_redhat_00011.1.el7eap, 7.4.4-3.GA_redhat_00011.1.el8eap
StoredIQ - update to siq_7_6_0_22_log4j_2_17_1_
Fuse - addressed in versions 7.8.2, 7.9.1, 7.10.0, 7.10.1
IBM WebSphere Application Server - addressed in versions 8.5.5.21, 9.0.5.11
IBM Maximo Scheduler Optimization - update to 8.0.3
Netcool/OMNIbus - update to 8.1.0.27
Opencast - addressed in versions 9.10, 10.6
Ghidra - update to 10.1
Content Manager OnDemand for Multiplatforms - addressed in versions 10.1.0.10, 10.5.0.4
IBM Spectrum Protect Plus - update to 10.1.9.1
IBM DB2 - addressed in versions 11.5.6.0, 11.5.7.0
IBM Cognos Analytics - addressed in versions 11.0.13.4, 11.1.7.7, 11.2.1.2
Apple Xcode - update to 13.3
CF Deployment - update to 17.1.0
Dell EMC Data Protection Search - addressed in versions 19.6.1, 19.6.2
Dell Data Protection Central - update to 19.5.0.8
Sumo Logic - update to 19.361-12
PaperCut NG - update to 21.2.4
PaperCut MF - update to 21.2.4
YouTrack - update to 2021.4.35970
Zoho ManageEngine EventLog Analyzer - update to 12212
eap7-wildfly-openssl-el7 (Red Hat package) - update to x86_64-2.2.0-2.Final_redhat_00002.1.el7eap
eap7-wildfly-openssl-el8 (Red Hat package) - update to x86_64-2.2.0-2.Final_redhat_00002.1.el8eap
thrift - addressed in versions 0.14.0-4, 0.14.0-5
libthrift-java - addressed in versions 0.14.0-4, 0.14.0-5
perl-thrift - addressed in versions 0.14.0-4, 0.14.0-5
python3-thrift - addressed in versions 0.14.0-4, 0.14.0-5
thrift-debugsource - addressed in versions 0.14.0-4, 0.14.0-5
thrift-devel - addressed in versions 0.14.0-4, 0.14.0-5
thrift-glib - addressed in versions 0.14.0-4, 0.14.0-5
thrift-qt - addressed in versions 0.14.0-4, 0.14.0-5
Apache Druid - update to 0.22.1
wildfly-elytron - update to 1.0.2-2
wildfly-elytron-javadoc - update to 1.0.2-2
vRO Plug-in for Dell EMC PowerScale - addressed in versions 1.0.4, 1.1.1, 1.2.4
API Portal for VMware Tanzu - update to 1.0.7
eap7-yasson (Red Hat package) - addressed in versions 1.0.10-1.redhat_00001.1.el7eap, 1.0.10-1.redhat_00001.1.el8eap
wildfly-common-help - update to 1.1.0-8
wildfly-common - update to 1.1.0-8
wildfly-security-manager - update to 1.1.2-2
wildfly-security-manager-javadoc - update to 1.1.2-2
Spring Cloud Gateway for VMware Tanzu - update to 1.1.3
wildfly-build-tools-javadoc - update to 1.1.6-2
wildfly-server-provisioning-standalone - update to 1.1.6-2
wildfly-feature-pack-build-maven-plugin - update to 1.1.6-2
wildfly-server-provisioning - update to 1.1.6-2
wildfly-build-tools - update to 1.1.6-2
wildfly-server-provisioning-maven-plugin - update to 1.1.6-2
Dell EMC OpenManage Enterprise Services - update to 1.2.1
OpenSearch - update to 1.2.1
storm-supervisor - addressed in versions 1.2.3-3.5.1, 1.2.3-3.8.2
storm - addressed in versions 1.2.3-3.5.1, 1.2.3-3.8.2
storm-nimbus - addressed in versions 1.2.3-3.5.1, 1.2.3-3.8.2
log4j12 - update to 1.2.17-25
log4j12-help - update to 1.2.17-25
Remote SIM Provisioning Manager (RSPM) - addressed in versions 1.3GA HF08, 1.3.2 HF04, 1.4.1 HF04
Dell EMC Streaming Data Platform - update to 1.3.1.1
eap7-xom (Red Hat package) - addressed in versions 1.3.7-1.redhat_00001.1.el7eap, 1.3.7-1.redhat_00001.1.el8eap
eap7-jettison (Red Hat package) - addressed in versions 1.3.8-2.redhat_00002.1.ep7.el7, 1.5.2-2.redhat_00002.1.el7eap
Oxygen Feedback - update to 1.4.5 2021121314
Gradle Enterprise Test Distribution Agent - update to 1.6.2
eap7-velocity (Red Hat package) - update to 1.7.0-3.redhat_00006.1.ep7.el7
Healthwatch for Tanzu Application Service - addressed in versions 1.8.6, 2.1.7
Arduino IDE - update to 1.8.18
flink - update to 1.12.7-2
Single Sign-On for VMware Tanzu Application Service - update to 1.14.5
Minecraft - update to 1.18.1
eap7-snakeyaml (Red Hat package) - addressed in versions 1.33.0-1.SP1_redhat_00001.1.el7eap, 1.33.0-1.SP1_redhat_00001.1.ep7.el7
Dell EMC OpenManage Enterprise Modular - update to 1.40.10
Cloud Director Object Storage Extension - addressed in versions 2.0.0.3, 2.1.0.1
Dell EMC PowerStore Family Operating System - update to 2.0.1.3-1538564
Edge Infrastructure Automation - update to 2.0.6.1
Planning Analytics Local - update to 2.0.9.11
IBM Planning Analytics Workspace - update to 2.0.72
Horizon Cloud Connector - update to 2.1.1
App Metrics - update to 2.1.1
jansi - update to 2.1.1-4.fc34
HPE SANnav Management Software - addressed in versions 2.1.1.7, 2.2.0.1
avalon-logkit-help - addressed in versions 2.1-33, 2.1-34
avalon-logkit - addressed in versions 2.1-33, 2.1-34
wildfly-core-javadoc - addressed in versions 2.2.0-2, 2.2.0-3
wildfly-core - addressed in versions 2.2.0-2, 2.2.0-3
wildfly-core-feature-pack - addressed in versions 2.2.0-2, 2.2.0-3
eap7-wildfly-openssl (Red Hat package) - addressed in versions 2.2.0-3.Final_redhat_00002.1.el7eap, 2.2.0-3.Final_redhat_00002.1.el8eap
HikariCP-help - addressed in versions 2.4.3-5, 2.4.3-6
HikariCP - addressed in versions 2.4.3-5, 2.4.3-6
json-lib-help - addressed in versions 2.4-18, 2.4-19
jenkins-json-lib - addressed in versions 2.4-18, 2.4-19
json-lib - addressed in versions 2.4-18, 2.4-19
eap7-jackson-databind (Red Hat package) - addressed in versions 2.8.11.6-2.SP1_redhat_00002.1.ep7.el7, 2.10.4-4.redhat_00004.1.el7eap
liblog4j2-java (Ubuntu package) - addressed in versions 2.10.0-2ubuntu0.1, 2.15.0-0.20.04.1, 2.15.0-0.21.04.1, 2.15.0-0.21.10.1, 2.16.0-0.20.04.1, 2.16.0-0.21.04.1, 2.16.0-0.21.10.1, 2.42ubuntu0.1~esm1
eap7-jackson-annotations (Red Hat package) - update to 2.10.4-2.redhat_00004.1.el7eap
eap7-jackson-core (Red Hat package) - update to 2.10.4-2.redhat_00004.1.el7eap
eap7-jackson-jaxrs-providers (Red Hat package) - update to 2.10.4-2.redhat_00004.1.el7eap
eap7-jackson-modules-java8 (Red Hat package) - update to 2.10.4-2.redhat_00004.1.el7eap
eap7-jackson-modules-base (Red Hat package) - update to 2.10.4-4.redhat_00004.1.el7eap
log4j-jmx-gui - addressed in versions 2.13.2-2, 2.13.2-3, 2.17.0-1, 2.17.0-3
log4j-nosql - addressed in versions 2.13.2-2, 2.13.2-3
log4j-slf4j - addressed in versions 2.13.2-2, 2.13.2-3, 2.17.0-1, 2.17.0-3
log4j-taglib - addressed in versions 2.13.2-2, 2.13.2-3, 2.17.0-1, 2.17.0-3
log4j-jcl - addressed in versions 2.13.2-2, 2.13.2-3, 2.17.0-1, 2.17.0-3
log4j-help - addressed in versions 2.13.2-2, 2.13.2-3, 2.17.0-1, 2.17.0-3
log4j-web - addressed in versions 2.13.2-2, 2.13.2-3, 2.17.0-1, 2.17.0-3
log4j-bom - addressed in versions 2.13.2-2, 2.13.2-3, 2.17.0-1, 2.17.0-3
log4j - addressed in versions 2.13.2-2, 2.13.2-3, 2.17.0-1, 2.17.0-3
log4j - addressed in versions 2.15.0-1.fc35, 2.16.0-1.fc34, 2.17.0-1.fc34, 2.17.0-1.fc35
eap7-activemq-artemis (Red Hat package) - addressed in versions 2.16.0-7.redhat_00034.1.el7eap, 2.16.0-7.redhat_00034.1.el8eap
eap7-log4j (Red Hat package) - addressed in versions 2.17.1-1.redhat_00001.1.el7eap, 2.17.1-1.redhat_00001.1.el8eap
Oxygen Content Fusion - addressed in versions 3.0.1 2021121414, 4.1.3 2021121315
Git Client - update to 3.0.1
mx4j-manual - addressed in versions 3.0.1-2, 3.0.1-3
mx4j-javadoc - addressed in versions 3.0.1-2, 3.0.1-3
mx4j - addressed in versions 3.0.1-2, 3.0.1-3
VMware Tanzu Observability by Wavefront Nozzle - update to 3.0.3
eap7-resteasy (Red Hat package) - addressed in versions 3.0.27-1.Final_redhat_00001.1.ep7.el7, 3.11.6-1.Final_redhat_00001.1.el7eap
Real Time Management System (RTMS) - update to 3.00.72.1
Dynamic SIM Provisioning (DSP) - addressed in versions 3.1.2 HF02, 3.3.0 HF03, 3.4.0 HF01
metrics-httpclient - addressed in versions 3.1.2-2, 3.1.2-3
metrics-servlet - addressed in versions 3.1.2-2, 3.1.2-3
metrics-parent - addressed in versions 3.1.2-2, 3.1.2-3
metrics-logback - addressed in versions 3.1.2-2, 3.1.2-3
metrics-log4j2 - addressed in versions 3.1.2-2, 3.1.2-3
metrics-log4j - addressed in versions 3.1.2-2, 3.1.2-3
metrics-annotation - addressed in versions 3.1.2-2, 3.1.2-3
metrics-jvm - addressed in versions 3.1.2-2, 3.1.2-3
metrics-json - addressed in versions 3.1.2-2, 3.1.2-3
metrics-jersey2 - addressed in versions 3.1.2-2, 3.1.2-3
metrics-jdbi - addressed in versions 3.1.2-2, 3.1.2-3
metrics-javadoc - addressed in versions 3.1.2-2, 3.1.2-3
metrics-httpasyncclient - addressed in versions 3.1.2-2, 3.1.2-3
metrics-benchmarks - addressed in versions 3.1.2-2, 3.1.2-3
metrics-doc - addressed in versions 3.1.2-2, 3.1.2-3
metrics-servlets - addressed in versions 3.1.2-2, 3.1.2-3
metrics-ehcache - addressed in versions 3.1.2-2, 3.1.2-3
metrics-healthchecks - addressed in versions 3.1.2-2, 3.1.2-3
metrics-graphite - addressed in versions 3.1.2-2, 3.1.2-3
metrics-ganglia - addressed in versions 3.1.2-2, 3.1.2-3
metrics - addressed in versions 3.1.2-2, 3.1.2-3
eap7-apache-cxf (Red Hat package) - update to 3.1.16-4.redhat_00003.1.ep7.el7
VNXe1600 - update to 3.1.16.10224109
Dell EMC VNXe3200 - update to 3.1.17.10223906
Spring Cloud Services for VMware Tanzu - update to 3.1.26
Batch Documents Converter - update to 3.2.1
datanucleus-api-jdo - addressed in versions 3.2.8-2, 3.2.8-3, 3.2.15-3
datanucleus-api-jdo-javadoc - addressed in versions 3.2.8-2, 3.2.8-3
mybatis - update to 3.2.8-3
mybatis-javadoc - update to 3.2.8-3
datanucleus-rdbms-javadoc - addressed in versions 3.2.13-2, 3.2.13-4
datanucleus-rdbms - addressed in versions 3.2.13-2, 3.2.13-4
datanucleus-core - addressed in versions 3.2.15-2, 3.2.15-3
datanucleus-core-javadoc - addressed in versions 3.2.15-2, 3.2.15-3
eap7-jboss-vfs (Red Hat package) - addressed in versions 3.2.16-1.Final_redhat_00001.1.el7eap, 3.2.16-1.Final_redhat_00001.1.el8eap
eap7-hal-console (Red Hat package) - addressed in versions 3.2.17-1.Final_redhat_00001.1.el7eap, 3.3.9-1.Final_redhat_00001.1.el7eap, 3.3.9-1.Final_redhat_00001.1.el8eap
springframework-jms - addressed in versions 3.2.18-9, 3.2.18-10
springframework-help - addressed in versions 3.2.18-9, 3.2.18-10
springframework-expression - addressed in versions 3.2.18-9, 3.2.18-10
springframework-jdbc - addressed in versions 3.2.18-9, 3.2.18-10
springframework-context - addressed in versions 3.2.18-9, 3.2.18-10
springframework-tx - addressed in versions 3.2.18-9, 3.2.18-10
springframework-beans - addressed in versions 3.2.18-9, 3.2.18-10
springframework-aop - addressed in versions 3.2.18-9, 3.2.18-10
springframework-orm - addressed in versions 3.2.18-9, 3.2.18-10
springframework-orm-hibernate4 - addressed in versions 3.2.18-9, 3.2.18-10
springframework-oxm - addressed in versions 3.2.18-9, 3.2.18-10
springframework-web - addressed in versions 3.2.18-9, 3.2.18-10
springframework-instrument - addressed in versions 3.2.18-9, 3.2.18-10
springframework - addressed in versions 3.2.18-9, 3.2.18-10
EMC ECS - addressed in versions 3.3.0.4, 3.4.0.6, 3.5.1.6, 3.6.2.1, 3.6.2.2, 3.7.0
jboss-logging - addressed in versions 3.3.0-6, 3.3.0-7
jboss-logging-javadoc - addressed in versions 3.3.0-6, 3.3.0-7
Dell Wyse Management Suite - addressed in versions 3.5.1, 3.5.2
IBM Decision Optimization for Cloud Pak for Data - addressed in versions 3.5.11, 4.0.5
apache-zookeeper - update to 3.6.1-2.3
jgroups-help - addressed in versions 3.6.10-7, 3.6.10-8
jgroups - addressed in versions 3.6.10-7, 3.6.10-8
Service Director (SD) - update to 3.7.1-PB2
HPE StoreServ Management Console - update to 3.8.2.1
eap7-ecj (Red Hat package) - addressed in versions 3.26.0-1.redhat_00002.1.el7eap, 3.26.0-1.redhat_00002.1.el8eap
Cloud Pak for Data - update to 4.0.4
Dell EMC Unisphere Central - update to 4.0.9.1541235
netty - addressed in versions 4.1.13-14, 4.1.13-15
netty-help - addressed in versions 4.1.13-14, 4.1.13-15
eap7-netty (Red Hat package) - addressed in versions 4.1.63-1.Final_redhat_00002.1.ep7.el7, 4.1.63-4.Final_redhat_00002.1.el7eap
avalon-framework - addressed in versions 4.3-23, 4.3-24
avalon-framework-help - addressed in versions 4.3-23, 4.3-24
EMC ViPR SRM - addressed in versions 4.5.0.2, 4.6.0.2
Dell EMC VxRail Appliance - update to 4.5.471
Dell Secure Connect Gateway - addressed in versions 5.00.06, 5.00.07
Dell Support Assist Enterprise - update to 5.00.06
3PAR Service Processors - update to 5.0.9.2
Dell EMC Unity XT Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC Unity VSA Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC Unity Operating Environment (OE) - update to 5.1.2.0.5.007
RecoverPoint - update to 5.1.4.2
RecoverPoint for VMs - update to 5.3.2.2
eap7-jbossws-cxf (Red Hat package) - addressed in versions 5.4.4-1.Final_redhat_00001.1.el7eap, 5.4.4-1.Final_redhat_00001.1.el8eap
eap7-narayana (Red Hat package) - addressed in versions 5.11.4-1.Final_redhat_00001.1.el7eap, 5.11.4-1.Final_redhat_00001.1.el8eap
Alertus Console - update to 5.15.0
IBM Global High Availability Mailbox - addressed in versions 6.0.1.2.1, 6.0.2.3.1, 6.0.3.5.1, 6.1.0.4.1, 6.1.1.0.1
vCenter Server Appliance - addressed in versions 6.5 U3s, 6.7 U3q, 7.0 U3c
UniFi Network Application - update to 6.5.54
Dell EMC Metro Node - update to 7.0.1.02.00.01
Carbon Black EDR Server - update to 7.6.0
EMC Data Domain - addressed in versions 7.7.1.0, 7.8.0.0
Stardog - update to 7.8.1
VMware Horizon - addressed in versions 7.10.3-19067347, 7.13.1-19066964, 8.4.0-19066680
Yellowfin - addressed in versions 8.0.10.4, 9.7.0.3
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
IBM Tivoli Netcool/OMNIbus Integration – Transport Module Common Integration Library - update to 8.2
JBoss Data Grid - addressed in versions 8.2.2, 8.2.3
infinispan-help - addressed in versions 8.2.4-9, 8.2.4-10
infinispan - addressed in versions 8.2.4-9, 8.2.4-10
IBM Maximo Application Suite - addressed in versions 8.6.3, 8.7.1
Trueview Inventory Software Series - addressed in versions 8.6.22.1, 8.7.3
IBM Common Licensing - update to 9.0.0.1
eap7-objectweb-asm (Red Hat package) - addressed in versions 9.1.0-1.redhat_00002.1.el7eap, 9.1.0-1.redhat_00002.1.el8eap
Sterling Configure, Price, Quote - update to 10.0.0.23
Build Cache Node - update to 10.1
eap7-infinispan (Red Hat package) - addressed in versions 11.0.15-1.Final_redhat_00001.1.el7eap, 11.0.15-1.Final_redhat_00001.1.el8eap
Connectrix MDS-DCNM - update to 11.5(1x)
LucaNet - addressed in versions 12 LTS - 1911.0.191+3, 13 LTS - 2011.0.110+6, 22 LTS - 2111.0.9+17
Informix Dynamic Server - addressed in versions 12.10.xC15, 14.10.FC7W1
Fraud Risk Management (FRM) - addressed in versions 14.0.2 Revision 10, 14.1 Revision 3
EMC Data Protection Advisor - addressed in versions 19.4 B104, 19.5 B74, 19.5 74, 19.6 B24
Dell EMC Cloud Disaster Recovery - addressed in versions 19.6.0.3, 19.7.0.3, 19.8.0.7, 19.9.0.4
Dell EMC vProtect - update to 19.9.0.430-4
Dell Storage Manager - update to 20.1.2
LiveNX - update to 21.5.1
LiveNA - update to 21.5.1
Oxygen Web Author Test Server Add-on - addressed in versions 22.1.1, 23.1.2, 24.0.1
Oxygen XML Developer - addressed in versions 23.1 2021121317, 24.0 2021121317
Oxygen XML WebHelp - addressed in versions 23.1 2021121412, 24.0 2021121311
Oxygen PDF Chemistry - addressed in versions 23.1 2021121413, 24.0 2021121314
Oxygen XML Publishing Engine - addressed in versions 23.1 2021121413, 24.0 2021121314
Oxygen XML Author - addressed in versions 23.1 2021121415, 24.0 2021121317
Security Director Insights - update to 23.1R1
XSD to JSON Schema Converter - addressed in versions 23.1.1, 24.0.1
Oxygen XML Web Author - addressed in versions 23.1.1.2 2021121408, 24.0.0 2021121314
Web Author PDF Plugin - addressed in versions 23.1.1.2, 24.0.0.1
Oxygen License Server - update to 24.0 2021121311
IBM Tivoli Netcool/OMNIbus Integration – Java Netcool Utility Library - update to 33.2
IBM DS8000 Hardware Management Console - addressed in versions 88.50.184.0, 89.12.8.0
Operations Dashboard - addressed in versions 2020.4.1-6-eus, 2021.4.1-2
Hub - update to 2021.1.14080
Gradle Enterprise - update to 2021.3.6
Automation Assets in IBM Cloud Pak for Integration (CP4I) - update to 2021.4.1-2
Links to Public Exploits and PoC-codes
- Exploit #10752 - AD Manager Plus 7122 - Remote Code Execution (RCE) (October 25, 2024)
- Exploit #9045 - log4j-exploit-fork-bomb (??? Proof of Concept: пример запуска fork-бомбы на удаленном сервере благодаря уязвимости CVE-2021-44228) (May 7, 2023)
- Exploit #8887 - Log4j_Vulnerability_Demo (A simple program to demonstrate how Log4j vulnerability can be exploited ( CVE-2021-44228 ) ) (March 4, 2023)
- Exploit #8602 - log4j-payload-generator (log4j-paylaod generator : A generic payload generator for Apache log4j RCE CVE-2021-44228) (November 13, 2022)
- Exploit #8404 - StudyRoom ( Repository created for study and POC's on vulnerabilities.) (September 26, 2022)
- Exploit #8350 - gosploitoy (A simple golang tool to search for exploit-db cve's) (September 7, 2022)
- Exploit #8320 - CVE-2021-44228 (PoC for CVE-2021-44228.) (September 1, 2022)
- Exploit #8218 - log4shell-rmi-poc (A Proof of Concept of the Log4j vulnerabilities (CVE-2021-44228) over Java-RMI) (August 5, 2022)
- Exploit #8203 - MobileIron Core Unauthenticated JNDI Injection RCE (via Log4Shell) (August 2, 2022)
- Exploit #8180 - cve-maker (Tool to find CVEs and Exploits.) (July 26, 2022)
- Exploit #8118 - CVEsLab (? A collection of proof-of-concept exploit scripts on docker lab environments has been discovered by Securi Trust Team. Vulnerabilities has been written by SecuriTrust team for various CVEs.) (July 6, 2022)
- Exploit #8098 - log4j-exploit-builder (Script to create a log4j (CVE-2021-44228) exploit with support for different methods of getting a reverse shell) (June 30, 2022)
- Exploit #8000 - log4j-shell-csw (A Proof-Of-Concept Exploit for CVE-2021-44228 vulnerability.) (June 9, 2022)
- Exploit #7941 - log4j-exploit-builder (Script to create a log4j (CVE-2021-44228) exploit with support for different methods of getting a reverse shell) (June 1, 2022)
- Exploit #7825 - Apache Log4j2 2.14.1 - Information Disclosure (May 13, 2022)
- Exploit #7824 - Apache Log4j 2 - Remote Code Execution (RCE) (May 13, 2022)
- Exploit #7480 - log4j-dork-scanner (A script to search, scrape and scan for Apache Log4j CVE-2021-44228 affected files using Google dorks) (March 14, 2022)
- Exploit #7313 - apache-tomcat-log4j (Log4j2 CVE-2021-44228 Vulnerability POC in Apache Tomcat) (February 1, 2022)
- Exploit #7254 - UniFi Network Application Unauthenticated JNDI Injection RCE (via Log4Shell) (January 21, 2022)
- Exploit #7252 - VMware vCenter Server Unauthenticated JNDI Injection RCE (via Log4Shell) (January 20, 2022)
- Exploit #7231 - Log4Shell HTTP Header Injection (January 12, 2022)
- Exploit #7230 - Log4jHorizon (Exploiting CVE-2021-44228 in VMWare Horizon for remote code execution and more.) (January 10, 2022)
- Exploit #7180 - Log4Shell HTTP Scanner (December 16, 2021)
- Exploit #7172 - Log4j_CVE-2021-45046 (Log4j 2.15.0 Privilege Escalation -- CVE-2021-45046) (December 15, 2021)
- Exploit #7164 - Log4j-RCE (Log4j RCE - (CVE-2021-44228)) (December 13, 2021)
- Exploit #7163 - CVE_2021_44228_Check (Check if Java allows JNDI remote code exec by default) (December 13, 2021)
- Exploit #7159 - exploit-CVE-2021-44228 (This is a proof-of-concept exploit for Log4j RCE Unauthenticated (CVE-2021-44228).) (December 13, 2021)
- Exploit #7158 - vcenter-log4j (Script to apply official workaround for VMware vCenter log4j vulnerability CVE-2021-44228) (December 13, 2021)
- Exploit #7156 - Log4J-Scanner (Burp extension to scan Log4Shell (CVE-2021-44228) vulnerability pre and post auth.) (December 13, 2021)
- Exploit #7155 - log4j-jndi-be-gone (A Byte Buddy Java agent-based fix for CVE-2021-44228, the log4j 2.x "JNDI LDAP" vulnerability.) (December 13, 2021)
- Exploit #7152 - log4j-scan (A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228 ) (December 13, 2021)
- Exploit #7151 - nse-log4shell (Nmap NSE scripts to check against log4shell or LogJam vulnerabilities (CVE-2021-44228)) (December 13, 2021)
- Exploit #7145 - CVE-2021-44228_Example () (December 12, 2021)
- Exploit #7144 - log4j_CVE-2021-44228_tester (Test for log4j vulnerability across your external footprint) (December 12, 2021)
- Exploit #7143 - sample-ldap-exploit (A short demo of CVE-2021-44228) (December 12, 2021)
- Exploit #7142 - cve-2021-44228-minecraft-poc (Log4J CVE-2021-44228 Minecraft PoC) (December 12, 2021)
- Exploit #7139 - log4j2burpscanner (CVE-2021-44228 Log4j2 BurpSuite Scanner,Customize ceye.io api or other apis,including internal networks) (December 12, 2021)
- Exploit #7138 - log4j-poc (CVE-2021-44228 test demo) (December 12, 2021)
- Exploit #7137 - log4j-shell-poc (A Proof-Of-Concept for the CVE-2021-44228 vulnerability. ) (December 12, 2021)
- Exploit #7136 - CVE-2021-44228-example (vulnerability POC) (December 12, 2021)
- Exploit #7134 - python-log4rce (An All-In-One Pure Python PoC for CVE-2021-44228) (December 12, 2021)
- Exploit #7133 - CVE-2021-44228 (Abuse Log4J CVE-2021-44228 to patch CVE-2021-44228 in vulnerable Minecraft game sessions to prevent exploitation in the session :) ) (December 12, 2021)
- Exploit #7132 - hotpatch-for-apache-log4j2 (An agent to hotpatch the log4j RCE from CVE-2021-44228.) (December 12, 2021)
- Exploit #7131 - log4shell-vulnerable-app (Spring Boot web application vulnerable to Log4Shell (CVE-2021-44228).) (December 12, 2021)
- Exploit #7130 - CVE-2021-44228-Scanner (Vulnerability scanner and mitigation patch for Log4j2 CVE-2021-44228) (December 12, 2021)
- Exploit #7129 - CVE-2021-44228-PoC-log4j-bypass-words (?? ✂️ ? CVE-2021-44228 - LOG4J Java exploit - WAF bypass tricks) (December 12, 2021)
- Exploit #7128 - CVE-2021-44228-Apache-Log4j-Rce (Apache Log4j 远程代码执行) (December 12, 2021)
- Exploit #7127 - CVE-2021-44228 (Apache Log4j 2 a remote code execution vulnerability via the ldap JNDI parser.) (December 10, 2021)
- Exploit #7126 - Log4J-RCE-Proof-Of-Concept (Log4j-RCE (CVE-2021-44228) Proof of Concept with additional information) (December 10, 2021)
External References
Related Security Bulletins
- Remote code execution in Apache Log4J
- Remote code execution in VMware vCenter Server (Apache Log4j component)
- Debian update for apache-log4j2
- Remote code execution in FortiSIEM (Apache Log4j component)
- Remote code execution in FortiCASB (Apache Log4j component)
- Remote code execution in FortiPortal (Apache Log4j component)
- Remote code execution in FortiNAC (Apache Log4j component)
- Remote code execution in FortiConverter (Apache Log4j component)
- Remote code execution in FortiAIOps (Apache Log4j component)
- Remote code execution in FortiSOAR (Apache Log4j component)
- Remote code execution in IBM WebSphere Application Server (Apache Log4j component)
- Remote code execution in SolarWinds Database Performance Analyzer (Apache Log4j component)
- Remote code execution in Symantec Advanced Authentication (Apache Log4j component)
- Remote code execution in Symantec Endpoint Protection Manager (Apache Log4j component)
- Multiple vulnerabilities in Metabase
- Remote code execution in Ghidra (Apache Log4j component)
- Remote code execution in VMware Horizon (Apache Log4j component)
- Remote code execution in VMware HCX (Apache Log4j component)
- Remote code execution in VMware NSX-T Data Center (Apache Log4j component)
- Remote code execution in VMware Unified Access Gateway (Apache Log4j component)
- Remote code execution in VMware Workspace ONE Access (Apache Log4j component)
- Remote code execution in VMware Identity Manager (Apache Log4j component)
- Remote code execution in VMware vRealize Operations (Apache Log4j component)
- Remote code execution in VMware vRealize Log Insight (Apache Log4j component)
- Remote code execution in VMware vRealize Automation (Apache Log4j component)
- Remote code execution in VMware vRealize Lifecycle Manager (Apache Log4j component)
- Remote code execution in VMware Telco Cloud Automation (Apache Log4j component)
- Remote code execution in VMware Carbon Black Cloud Workload Appliance (Apache Log4j component)
- Remote code execution in VMware Carbon Black EDR Server (Apache Log4j component)
- Remote code execution in VMware Site Recovery Manager, vSphere Replication (Apache Log4j component)
- Remote code execution in VMware Tanzu GemFire (Apache Log4j component)
- Remote code execution in VMware Tanzu Greenplum (Apache Log4j component)
- Remote code execution in VMware Tanzu Operations Manager (Apache Log4j component)
- Remote code execution in VMware Tanzu Application Service for VMs (Apache Log4j component)
- Remote code execution in Apache Flink (Apache Log4j component)
- Remote code execution in Apache Solr (Apache Log4j component)
- Remote code execution in Apache Tika (Apache Log4j component)
- Remote code execution in Apereo CAS (Apache Log4j component)
- Remote code execution in cPanel Solr plugin (Apache Log4j component)
- Remote code execution in Minecraft (Apache Log4j component)
- Remote code execution in OWASP ZAP (Apache Log4j component)
- Remote code execution in VMware Tanzu Kubernetes Grid Integrated Edition (Apache Log4j component)
- Remote code execution in VMware Tanzu Observability by Wavefront Nozzle (Apache Log4j component)
- Remote code execution in Healthwatch for Tanzu Application Service (Apache Log4j component)
- Remote code execution in Spring Cloud Services for VMware Tanzu (Apache Log4j component)
- Remote code execution in Spring Cloud Gateway for VMware Tanzu (Apache Log4j component)
- Remote code execution in Spring Cloud Gateway for Kubernetes (Apache Log4j component)
- Remote code execution in API Portal for VMware Tanzu (Apache Log4j component)
- Remote code execution in Single Sign-On for VMware Tanzu Application Service (Apache Log4j component)
- Remote code execution in App Metrics (Apache Log4j component)
- Remote code execution in VMware vCenter Cloud Gateway (Apache Log4j component)
- Remote code execution in vRealize Orchestrator (Apache Log4j component)
- Remote code execution in Cloud Foundation (Apache Log4j component)
- Remote code execution in Horizon DaaS (Apache Log4j component)
- Remote code execution in Horizon Cloud Connector (Apache Log4j component)
- Remote code execution in NSX Data Center for vSphere (Apache Log4j component)
- Remote code execution in AppDefense Appliance (Apache Log4j component)
- Remote code execution in Cloud Director Object Storage Extension (Apache Log4j component)
- Remote code execution in Telco Cloud Operations (Apache Log4j component)
- Remote code execution in Tanzu Scheduler (Apache Log4j component)
- Remote code execution in Smart Assurance NCM (Apache Log4j component)
- Remote code execution in Smart Assurance SAM (Apache Log4j component)
- Remote code execution in VMware Workspace One Access Connector (Apache Log4j component)
- Remote code execution in vRealize Business for Cloud (Apache Log4j component)
- Remote code execution in Integrated OpenStack (Apache Log4j component)
- Remote code execution in Wowza Streaming Engine (Apache Log4j component)
- Remote code execution in Graylog (Apache Log4j component)
- Remote code execution in Silver Peak Orchestrator (Apache Log4j component)
- Remote code execution in Riverbed Portal (Apache Log4j component)
- Remote code execution in Riverbed NetIM (Apache Log4j component)
- Remote code execution in Riverbed UCExpert (Apache Log4j component)
- Remote code execution in Scon EX Director (Apache Log4j component)
- Remote code execution in Scon EX Analytics (Apache Log4j component)
- Remote code execution in Jedis (Apache Log4j component)
- Remote code execution in PortEx (Apache Log4j component)
- Remote code execution in Kafka Connect for Azure Cosmos DB (Apache Log4j component)
- Remote code execution in GitHub Enterprise Server (Apache Log4j component)
- Remote code execution in Red Hat OpenShift Container Platform (Apache Log4j component)
- Remote code execution in Okta RADIUS Server Agent (Apache Log4j component)
- Remote code execution in DeepGit (Apache Log4j component)
- Remote code execution in Sumo Logic (Apache Log4j component)
- Remote code execution in Neo4j: Graphs for Everyone (Apache Log4j component)
- Remote code execution in Nelson (Apache Log4j component)
- Multiple vulnerabilities in Opencast
- Remote code execution in SwingSet (Apache Log4j component)
- Remote code execution in Intel Audio Development Kit (Apache Log4j component)
- Remote code execution in Intel Datacenter Manager (Apache Log4j component)
- Remote code execution in Intel oneAPI sample browser plugin for Eclipse (Apache Log4j component)
- Remote code execution in Intel System Debugger (Apache Log4j component)
- Remote code execution in Intel Secure Device Onboard (Apache Log4j component)
- Remote code execution in Rundeck (Apache Log4j component)
- Remote code execution in Gradle Enterprise (Apache Log4j component)
- Remote code execution in Gradle Enterprise Test Distribution Agent (Apache Log4j component)
- Remote code execution in Build Cache Node (Apache Log4j component)
- Remote code execution in Red Hat AMQ Streams (Apache Log4j component)
- Remote code execution in eCatcher (Apache Log4j component)
- Remote code execution in Alertus Console (Apache Log4j component)
- Remote code execution in Netflix Atlas (Apache Log4j component)
- Remote code execution in openHAB Distribution (Apache Log4j component)
- Remote code execution in The Java Graphical Authorship Attribution Program (Apache Log4j component)
- Remote code execution in dgs-framework (Apache Log4j component)
- Remote code execution in Spectator (Apache Log4j component)
- Remote code execution in Dell NetWorker Server (Apache Log4j component)
- Remote code execution in Dell NetWorker Virtual Edition (Apache Log4j component)
- Remote code execution in YouTrack (Apache Log4j component)
- Remote code execution in Bitbucket Server (Apache Log4j component)
- Remote code execution in LucaNet (Apache Log4j component)
- Remote code execution in Apache Archiva (Apache Log4j component)
- Remote code execution in Apache Calcite Avatica (Apache Log4j component)
- Remote code execution in Apache EventMesh (Apache Log4j component)
- Remote code execution in Apache Druid (Apache Log4j component)
- Remote code execution in Apache Fortress (Apache Log4j component)
- Remote code execution in Apache Geode (Apache Log4j component)
- Remote code execution in Apache Hive (Apache Log4j component)
- Remote code execution in Jena (Apache Log4j component)
- Remote code execution in Apache JMeter (Apache Log4j component)
- Remote code execution in OFBiz (Apache Log4j component)
- Remote code execution in Apache Ozone (Apache Log4j component)
- Remote code execution in SkyWalking (Apache Log4j component)
- Remote code execution in Apache Traffic Control (Apache Log4j component)
- Remote code execution in InCenter (Apache Log4j component)
- Remote code execution in Oxygen Content Fusion (Apache Log4j component)
- Remote code execution in Oxygen XML Web Author (Apache Log4j component)
- Remote code execution in Oxygen Feedback (Apache Log4j component)
- Remote code execution in Oxygen XML Publishing Engine (Apache Log4j component)
- Remote code execution in Oxygen XML WebHelp (Apache Log4j component)
- Remote code execution in Oxygen PDF Chemistry (Apache Log4j component)
- Remote code execution in Oxygen License Server (Apache Log4j component)
- Remote code execution in Oxygen XML Author (Apache Log4j component)
- Remote code execution in Oxygen XML Developer (Apache Log4j component)
- Remote code execution in Web Author PDF Plugin (Apache Log4j component)
- Remote code execution in Oxygen Web Author Test Server Add-on (Apache Log4j component)
- Remote code execution in XSD to JSON Schema Converter (Apache Log4j component)
- Remote code execution in Git Client (Apache Log4j component)
- Remote code execution in Batch Documents Converter (Apache Log4j component)
- Remote code execution in Siemens SPPA-T3000 (Apache Log4j component)
- OpenShift Container Platform 4.6 update for log4j
- Remote code execution in Red Hat AMQ Streams (Apache Log4j component)
- Remote code execution in Apache Nifi (Apache Log4j component)
- Remote code execution in FileCap Server (Apache Log4j component)
- Remote code execution in Stardog (Apache Log4j component)
- Remote code execution in Sitecore XP (Apache Log4j component)
- Remote code execution in Unimus (Apache Log4j component)
- Remote code execution in LiveNA (Apache Log4j component)
- Remote code execution in LiveNX (Apache Log4j component)
- Remote code execution in Hub (Apache Log4j component)
- Remote code execution in Yellowfin (Apache Log4j component)
- Remote code execution in NoTouch Center (Apache Log4j component)
- Remote code execution in Arduino IDE (Apache Log4j component)
- Remote code execution in Apache Tapestry (Apache Log4j component)
- Remote code execution in Zyxel NetAtlas EMS (Apache Log4j component)
- Remote code execution in Apache Spark (Apache Log4j component)
- Remote code execution in CloudVision Portal (Apache Log4j component)
- Amazon Linux AMI update for java-1.8.0-openjdk, java-1.7.0-openjdk, java-1.6.0-openjdk
- Multiple vulnerabilities in CF Deployment
- Remote code execution in Avalanche (Apache Log4j component)
- Remote code execution in Ivanti File Director (Apache Log4j component)
- Remote code execution in MobileIron Core (Apache Log4j component)
- Remote code execution in MobileIron Sentry (Apache Log4j component)
- Remote code execution in MobileIron Core Connector (Apache Log4j component)
- Remote code execution in Reporting Database (RDB) (Apache Log4j component)
- Multiple Vulnerabilities PaperCut MF
- Multiple Vulnerabilities PaperCut NG
- Remote code execution in OpenSearch (Apache Log4j component)
- Remote code execution in OpenMRS Platform (Apache Log4j component)
- Remote code execution in Reference Application (Apache Log4j component)
- Remote code execution in Risk Intelligence (Apache Log4j component)
- Remote code execution in Atlas Search (Apache Log4j component)
- Remote code execution in UniFi Network Application (Apache Log4j component)
- Remote code execution in F-Secure Policy Manager (Apache Log4j component)
- Remote code execution in F-Secure Policy Manager for Linux (Apache Log4j component)
- Remote code execution in F-Secure Policy Manager Proxy (Apache Log4j component)
- Remote code execution in F-Secure Policy Manager Proxy for Linux (Apache Log4j component)
- Remote code execution in F-Secure Endpoint Proxy (Apache Log4j component)
- Multiple Vulnerabilities in Containerized private minion (CPM)
- Multiple Vulnerabilities in Java agent
- Remote code execution in IBM Spectrum Protect Plus (Apache Log4j component)
- Multiple vulnerabilities in Trend Micro Deep Discovery Director (Apache Log4j component)
- Remote code execution in IBM Cloud Application Business Insights (Apache Log4j component)
- Remote code execution in IBM Spectrum Protect Snapshot for VMware (Apache Log4j component)
- Multiple vulnerabilities in IBM Cognos Controller (Apache Log4j component)
- Multiple vulnerabilities in IBM Cognos Analytics (Apache Log4j component)
- Amazon Linux AMI update for log4j-cve-2021-44228-hotpatch
- Remote code execution in IBM Spectrum Copy Data Management (Apache Log4j component)
- Remote code execution in IBM Business Automation Workflow and IBM Business Process Manager (Apache Log4j component)
- Remote code execution in Zoho ManageEngine EventLog Analyzer (Apache Log4j component)
- Remote code execution in exacqVision Enterprise System Manager (Apache Log4j component)
- Remote code execution in Netcool/OMNIbus (Apache Log4j component)
- Remote code execution in IBM Edge Application Manger (Apache Log4j component)
- Remote code execution in Resilient OnPrem SOAR (Apache Log4j component)
- Remote code execution in Jazz for Service Management (Apache Log4j component)
- Multiple vulnerabilities in IBM DB2 (Apache Log4j component)
- Remote code execution in IBM Watson Assistant for IBM Cloud Pak for Data (Apache Log4j component)
- Remote code execution in SPSS Statistics Subscription (Apache Log4j component)
- Remote code execution in IBM SPSS Statistics Server (Apache Log4j component)
- Remote code execution in IBM DCNM (Apache Log4j component)
- Multiple vulnerabilities in Dell EMC Unity (Apache Log4j component)
- Remote code execution in IBM Spectrum Scale for IBM Elastic Storage Server (Apache Log4j component)
- Remote code execution in IBM Netcool Operations Insight and Agile Service Manager (Apache Log4j component)
- Remote code execution in IBM Watson Knowledge Catalog in Cloud Pak for Data (Apache Log4j component)
- Multiple vulnerabilities in Storage Center-Dell Storage Manager
- Remote code execution in Connectrix MDS-DCNM (Apache Log4j component)
- Multiple vulnerabilities in Nutanix AOS
- Multiple vulnerabilities in Nutanix Objects
- Remote code execution in Industry Models – IBM Data Model For Energy and Utilities (Apache Log4j component)
- Remote code execution in Industry Models – IBM Unified Data Model for Healthcare (Apache Log4j component)
- Remote code execution in Industry Models – IBM Banking and Financial Markets Data Warehouse (Apache Log4j component)
- Remote code execution in Industry Models – IBM Insurance Information Warehouse (Apache Log4j component)
- Dell EMC Unisphere Central update for Apache Log4j
- Remote code execution in IBM Crypto Hardware Initialization and Maintenance (Apache Log4j component)
- Remote code execution in IBM Sterling Connect:Direct for zOS (Apache Log4j component)
- Remote code execution in IBM Tivoli Monitoring (Apache Log4j component)
- Remote code execution in IBM Sterling Transformation Extender (Apache Log4j component)
- Remote code execution in IBM Sterling B2B Integrator (Apache Log4j component)
- Multiple vulnerabilities in SoapUI
- Remote code execution in IBM Spectrum Symphony (Apache Log4j component)
- Remote code execution in IBM Spectrum Conductor (Apache Log4j component)
- Remote code execution in IBM Sterling File Gateway (Apache Log4j component)
- Remote code execution in IBM Financial Transaction Manager for Digital Payments (Apache Log4j component)
- Remote code execution in IBM Financial Transaction Manager for Corporate Payment Services (Apache Log4j component)
- Remote code execution in IBM Financial Transaction Manager for ACH Services and Check Services (Apache Log4j component)
- newrelic-java-agent update for Apache Log4j
- Remote code execution in IBM Spectrum Control (Apache Log4j component)
- Remote code execution in IBM Operational Decision Manager (Apache Log4j component)
- Red Hat Process Automation Manager update for Apache Log4j
- Multiple vulnerabilities in Red Hat Fuse
- Remote code execution in Rational Test Automation Server (Apache Log4j component)
- Multiple vulnerabilities in Cloud Pak for Security (CP4S)
- Multiple vulnerabilities in RSA RT
- Multiple vulnerabilities in Red Hat Integration Camel-K
- Multiple vulnerabilities in IBM Global High Availability Mailbox
- Remote code execution in Log Analysis (Apache Log4j component)
- Remote code execution in Log Analysis (Apache Log4j component)
- Remote code execution in Johnson Controls PowerManage
- Multiple vulnerabilities in IBM Informix Dynamic Server on Cloud Pak for Data
- Multiple vulnerabilities in IBM Informix Dynamic Server
- Code injection in IBM UrbanCode Release (Apache Log4j component)
- Remote code execution in Bentley SYNCHRO 4D Pro (Apache Log4j component)
- Multiple vulnerabilities in IBM Cloud Pak System
- Multiple vulnerabilities in Apple Xcode
- Multiple vulnerabilities in IBM TRIRIGA
- Multiple vulnerabilities in Red Hat JBoss Enterprise Application Platform
- JBoss Enterprise Application Platform 7.4 for RHEL 8 update for log4j
- JBoss Enterprise Application Platform 7.4 for RHEL 7 update for log4j
- Multiple vulnerabilities in IBM PureData System for Operational Analytics
- Multiple vulnerabilities in IBM DS8000 Hardware Management Console
- Multiple vulnerabilities in IBM Db2
- Multiple vulnerabilities in IBM Tivoli Netcool/OMNIbus Common Integration Libraries
- Amazon Linux AMI update for log4j-cve-2021-44228-hotpatch
- SUSE update for storm
- SUSE update for storm-kit
- Ubuntu update for apache-log4j2
- Ubuntu update for apache-log4j2
- Ubuntu update for apache-log4j2
- Code Injection in IBM StoredIQ
- Code Injection in IBM Content Manager OnDemand for Multiplatforms
- Multiple vulnerabilities in IBM Maximo Scheduler Optimization
- Remote code execution in IBM Engineering Systems Design Rhapsody
- Remote code execution in IBM Engineering Lifecycle Optimization - Publishing and Rational Publishing Engine
- Multiple vulnerabilities in Dell Data Protection Search
- Remote code execution in IBM InfoSphere Master Data Management
- Multiple vulnerabilities in Dell EMC Support Assist Enterprise
- Multiple vulnerabilities in Dell EMC VxRail
- Multiple vulnerabilities in Dell EMC Cloud Disaster Recovery
- Multiple vulnerabilities in Dell EMC OpenManage Enterprise Services
- Remote code execution in Dell EMC DPA
- Multiple vulnerabilities in Dell EMC Streaming Data Platform
- Remote code execution in Dell EMC Secure Connect Gateway
- Multiple vulnerabilities in Dell EMC OpenManage Enterprise Modular
- Multiple vulnerabilities in Dell EMC PowerStore Family Operating System
- Remote code execution in Dell EMC Metro Node
- Remote code execution in Dell EMC VNXe3200
- Multiple vulnerabilities in Dell EMC ECS
- Remote code execution in Dell EMC SRM and Dell EMC Storage Monitoring and Reporting
- Remote code execution in Dell EMC Ruckus Wireless Controller and Virtual Software
- Remote code execution in Dell EMC Data Domain
- Remote code execution in Dell EMCRecoverPoint
- Remote code execution in Dell EMC Policy Manager for Secure Connect Gateway
- Remote code execution in Dell EMC SRS Policy Manager
- Remote code execution in Dell EMC Enterprise Storage Analytics for vRealize Operations
- Remote code execution in Dell Wyse Management Suite
- Multiple vulnerabilities in Dell EMC vProtect
- Multiple vulnerabilities in Dell PowerFlex Rack
- Remote code execution in Dell EMC Power Protect Data Manager
- Remote code execution in Dell EMC Data Protection Central
- Remote code execution in Dell EMC VNXe1600
- Remote code execution in vRealize Orchestrator (vRO) Plug-ins for Dell EMC Storage
- Remote code execution in Dell EMC BSN Controller Node
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in Dell Data Protection Search
- Multiple vulnerabilities in Automation Assets in IBM Cloud Pak for Integration
- Code injection in IBM Operations Dashboard
- Multiple vulnerabilities in HPE B-Series SANnav Management Software
- Multiple vulnerabilities in HPE Universal IoT (UIoT) Log4j
- Multiple vulnerabilities in HPE Network Functions
- Multiple vulnerabilities in HPE Fraud Risk Management Software Series
- Multiple vulnerabilities in HPE Remote SIM Provisioning Manager (RSPM)
- Multiple vulnerabilities in HPE Dynamic SIM Provisioning (DSP)
- Multiple vulnerabilities in HPE 3PAR Service Processors
- Multiple vulnerabilities in HPE Trueview Inventory Software Series
- Multiple vulnerabilities in HPE enhanced Interactive Unified Mediation (eIUM)
- Multiple vulnerabilities in HPE Edge Infrastructure Automation
- Multiple vulnerabilities in API Gateway and API Manager
- Axway SecureTransport update for Apache Log4j and OpenJDK JRE (January 2022)
- Multiple vulnerabilities in IBM Maximo Application Suite
- Multiple vulnerabilities in Dell RecoverPoint Classic
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Remote code execution in IBM Cloud Transformation Advisor (Apache Log4j component)
- Code injection in IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Decision Optimization for Cloud Pak for Data
- Multiple vulnerabilities in IBM Application Performance Management products
- Multiple vulnerabilities in Juniper Networks Security Director Insights
- openEuler update for log4j
- openEuler update for log4j,jboss-logging,jgroups,json-lib,metrics,mx4j,netty,springframework,thrift,HikariCP,avalon-framework,avalon-logkit,datanucleus-api-jdo,datanucleus-core,datanucleus-rdbms,infinispan,wildfly-core,apache-zookeeper
- openEuler update for log4j,mybatis,netty,springframework,wildfly-security-manager,wildfly-elytron,wildfly-build-tools,wildfly-common,wildfly-core,thrift,json-lib,datanucleus-core,jgroups,mx4j,jboss-logging,infinispan,datanucleus-rdbms,avalon-logkit,datanu
- openEuler update for log4j12
- openEuler 20.03 LTS SP1 update for flink
- openEuler 20.03 LTS SP3 update for log4j
- openEuler 22.03 LTS update for log4j12
- Code injection in IBM Sterling Configure, Price, Quote
- Multiple vulnerabilities in IBM Common Licensing
- Multiple vulnerabilities in IBM Planning Analytics and IBM Planning Analytics Workspace
- Code Injection in JBoss Data Grid 8.2
- Multiple vulnerabilities in Fuse 7.10
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.7
- Multiple vulnerabilities in JBoss Data Grid 8.2
- Fedora 35 update for log4j
- Fedora 34 update for jansi, log4j
- Fedora 35 update for log4j
- Fedora 34 update for log4j
- Multiple vulnerabilities in Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
- Multiple vulnerabilities in Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7
- Multiple vulnerabilities in HPE Real Time Management System (RTMS)
- Multiple vulnerabilities in HPE 3PAR/Primera StoreServ Management Console (SSMC)
- Multiple vulnerabilities in HPE Service Director (SD)
- Dell EMC Storage Monitoring and Reporting (SMR) update for Apache Log4j
- Dell Enterprise Storage Analytics for vRealize Operations update for Apache Log4j
- vRO Plug-in for Dell EMC PowerStore update for Apache Log4j
- Dell Data Protection Advisor update for Apache Log4j
- Dell Data Protection Central update for Apache Log4j
- Multiple vulnerabilities in IBM DevOps Build