SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-44832

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has…

MEDIUM 6.6EPSS 97.9%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 97.9%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.

Description

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.

CVSS 3.1
6.6 MEDIUMCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
97.91% probability · 100th percentile
CISA KEV
Not listed
Weakness
CWE-20, CWE-74
Affected
apache/log4j · oracle/communications diameter signaling router · oracle/communications interactive session recorder · oracle/primavera gateway · oracle/primavera p6 enterprise project portfolio management · oracle/primavera unifier · oracle/retail assortment planning · oracle/retail fiscal management · oracle/siebel ui framework · oracle/weblogic server · cisco/cloudcenter · fedoraproject/fedora · debian/debian linux · oracle/communications brm - elastic charging engine · oracle/communications offline mediation controller · oracle/flexcube private banking · oracle/health sciences data management workbench · oracle/policy automation · oracle/policy automation for mobile devices · oracle/product lifecycle analytics · +2 more
Source
security@apache.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.