CVE-2021-45105
MEDIUM(5.9)CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
- CVSS 5.9 — Mittel
- EPSS 100% — sehr wahrscheinlich ausgenutzt
Erwähnungen (letzte 60 Tage)
EPSS-Score
100.0%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
5.9
Technische Schwere
SecBoard-Einordnung
CVE-2021-45105 betrifft Apache Log4j2-Versionen von 2.0-alpha1 bis 2.16.0 (ausgenommen 2.12.3 und 2.3.1). Die Schwachstelle ermöglicht eine unkontrollierte Rekursion durch selbstreferenzielle Lookups. Ein Angreifer, der die Kontrolle über Thread Context Map-Daten hat, kann durch eine manipulierte Zeichenkette einen Denial of Service (DoS) verursachen, wenn diese interpretiert wird.
KI-gestützte Einordnung auf Basis der NVD-Daten.
Beschreibung
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.
Betroffene Produkte
- cpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:*
- cpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:*
- cpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:cloud_manager:-:*:*:*:*:*:*:*
- cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
- cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
- cpe:2.3:a:sonicwall:email_security:*:*:*:*:*:*:*:*
- cpe:2.3:a:sonicwall:network_security_manager:*:*:*:*:on-premises:*:*:*
- cpe:2.3:a:sonicwall:network_security_manager:*:*:*:*:saas:*:*:*
- cpe:2.3:a:sonicwall:web_application_firewall:*:*:*:*:*:*:*:*
- cpe:2.3:o:sonicwall:6bk1602-0aa12-0tp0_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:sonicwall:6bk1602-0aa22-0tp0_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:sonicwall:6bk1602-0aa32-0tp0_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:sonicwall:6bk1602-0aa42-0tp0_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:sonicwall:6bk1602-0aa52-0tp0_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:agile_engineering_data_management:6.2.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:agile_plm_mcad_connector:3.6:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:agile_product_lifecycle_management:9.3.6:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:autovue_for_agile_product_lifecycle_management:21.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:banking_deposits_and_lines_of_credit_servicing:2.12.0:*:*:*:*:*:*:*
GitHub Advisories
Apache Log4j2 vulnerable to Improper Input Validation and Uncontrolled Recursion
Referenzen
- http://www.openwall.com/lists/oss-security/2021/12/19/1
- https://cert-portal.siemens.com/productcert/pdf/ssa-479842.pdf
- https://cert-portal.siemens.com/productcert/pdf/ssa-501673.pdf
- https://logging.apache.org/log4j/2.x/security.html
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0032
- https://security.netapp.com/advisory/ntap-20211218-0001/
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-a...
- https://www.debian.org/security/2021/dsa-5024
- https://www.kb.cert.org/vuls/id/930724
- https://www.oracle.com/security-alerts/cpuapr2022.html