MEDIUM · 6.6

CVE-2021-44832

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with...

Vulnerability Description

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.

CVSS Score

6.6

MEDIUM

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
ApacheLog4J>= 2.0.1, < 2.3.2
OracleCommunications Diameter Signaling Router>= 8.0.0.0, <= 8.5.1.0
OracleCommunications Interactive Session Recorder6.3
OraclePrimavera Gateway>= 17.12.0, <= 17.12.11
OraclePrimavera P6 Enterprise Project Portfolio Management>= 19.12.0, <= 19.12.18.0
OraclePrimavera Unifier18.8
OracleRetail Assortment Planning16.0.3
OracleRetail Fiscal Management14.2
OracleSiebel Ui Framework21.12
OracleWeblogic Server12.2.1.3.0
CiscoCloudcenter4.10.0.16
FedoraprojectFedora34
DebianDebian Linux9.0
OracleCommunications Brm - Elastic Charging Engine< 12.0.0.4.6
OracleCommunications Offline Mediation Controller< 12.0.0.4.4
OracleFlexcube Private Banking12.1.0
OracleHealth Sciences Data Management Workbench2.5.2.1
OraclePolicy Automation>= 12.2.0, <= 12.2.24
OraclePolicy Automation For Mobile Devices>= 12.2.0, <= 12.2.24
OracleProduct Lifecycle Analytics3.6.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-44832?

CVE-2021-44832 is a vulnerability with a CVSS score of 6.6 (MEDIUM). Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with...

How severe is CVE-2021-44832?

CVE-2021-44832 has been rated MEDIUM with a CVSS base score of 6.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-44832?

Check the references section above for vendor advisories and patch information. Affected products include: Apache Log4J, Oracle Communications Diameter Signaling Router, Oracle Communications Interactive Session Recorder, Oracle Primavera Gateway, Oracle Primavera P6 Enterprise Project Portfolio Management.