CVE-2021-45105

Published Dec 18, 2021

Last updated 10 days ago

CVSS medium 5.9
Log4Shell
Sonicwall
API
Supply chain
Port (443)

Overview

Description
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.
Source
security@apache.org
NVD status
Modified
Products
log4j, cloud_manager, debian_linux, email_security, network_security_manager, web_application_firewall, 6bk1602-0aa12-0tp0_firmware, 6bk1602-0aa22-0tp0_firmware, 6bk1602-0aa32-0tp0_firmware, 6bk1602-0aa42-0tp0_firmware, 6bk1602-0aa52-0tp0_firmware, agile_engineering_data_management, agile_plm, agile_plm_mcad_connector, autovue_for_agile_product_lifecycle_management, banking_deposits_and_lines_of_credit_servicing, banking_enterprise_default_management, banking_loans_servicing, banking_party_management, banking_payments, banking_platform, banking_trade_finance, banking_treasury_management, business_intelligence, communications_asap, communications_billing_and_revenue_management, communications_cloud_native_core_console, communications_cloud_native_core_network_function_cloud_native_environment, communications_cloud_native_core_network_repository_function, communications_cloud_native_core_network_slice_selection_function, communications_cloud_native_core_policy, communications_cloud_native_core_security_edge_protection_proxy, communications_cloud_native_core_service_communication_proxy, communications_cloud_native_core_unified_data_repository, communications_convergence, communications_convergent_charging_controller, communications_diameter_signaling_router, communications_eagle_element_management_system, communications_eagle_ftp_table_base_retrieval, communications_element_manager, communications_evolved_communications_application_server, communications_interactive_session_recorder, communications_ip_service_activator, communications_messaging_server, communications_network_charging_and_control, communications_network_integrity, communications_performance_intelligence_center, communications_pricing_design_center, communications_service_broker, communications_services_gatekeeper, communications_session_report_manager, communications_session_route_manager, communications_unified_inventory_management, communications_user_data_repository, communications_webrtc_session_controller, data_integrator, e-business_suite, enterprise_manager_base_platform, enterprise_manager_for_peoplesoft, enterprise_manager_ops_center, financial_services_analytical_applications_infrastructure, financial_services_model_management_and_governance, flexcube_universal_banking, health_sciences_empirica_signal, health_sciences_inform, health_sciences_information_manager, healthcare_data_repository, healthcare_foundation, healthcare_master_person_index, healthcare_translational_research, hospitality_suite8, hospitality_token_proxy_service, hyperion_bi\+, hyperion_data_relationship_management, hyperion_infrastructure_technology, hyperion_planning, hyperion_profitability_and_cost_management, hyperion_tax_provision, identity_management_suite, identity_manager_connector, instantis_enterprisetrack, insurance_data_gateway, insurance_insbridge_rating_and_underwriting, jdeveloper, managed_file_transfer, management_cloud_engine, mysql_enterprise_monitor, payment_interface, peoplesoft_enterprise_peopletools, primavera_gateway, primavera_p6_enterprise_project_portfolio_management, primavera_unifier, retail_back_office, retail_central_office, retail_customer_insights, retail_data_extractor_for_merchandising, retail_eftlink, retail_financial_integration, retail_integration_bus, retail_invoice_matching, retail_merchandising_system, retail_order_broker, retail_order_management_system, retail_point-of-service, retail_predictive_application_server, retail_price_management, retail_returns_management, retail_service_backbone, retail_store_inventory_management, siebel_ui_framework, sql_developer, taleo_platform, utilities_framework, webcenter_portal, webcenter_sites, weblogic_server

Risk scores

CVSS 3.1

Type
Primary
Base score
5.9
Impact score
3.6
Exploitability score
2.2
Vector string
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity
MEDIUM

CVSS 2.0

Type
Primary
Base score
4.3
Impact score
2.9
Exploitability score
8.6
Vector string
AV:N/AC:M/Au:N/C:N/I:N/A:P

Weaknesses

security@apache.org
CWE-20
nvd@nist.gov
CWE-20

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.