8.1
CWE
502 20
Advisory Published
CVE Published
Advisory Published
Updated

CVE-2021-4104: Deserialization of untrusted data in JMSAppender in Apache Log4j 1.2

First published: Fri Dec 10 2021(Updated: )

JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-44228. Note this issue only affects Log4j 1.2 when specifically configured to use JMSAppender, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.

Credit: security@apache.org security@apache.org secalert@redhat.com

Affected SoftwareAffected VersionHow to fix
redhat/log4j<0:1.2.14-6.5.el6_10
0:1.2.14-6.5.el6_10
redhat/log4j<0:1.2.17-17.el7_4
0:1.2.17-17.el7_4
redhat/log4j<0:1.2.17-16.el7_3
0:1.2.17-16.el7_3
redhat/log4j-eap6<0:1.2.17-3.redhat_00008.1.ep6.el6
0:1.2.17-3.redhat_00008.1.ep6.el6
redhat/log4j-jboss-logmanager<0:1.1.4-3.Final_redhat_00002.1.ep6.el6
0:1.1.4-3.Final_redhat_00002.1.ep6.el6
redhat/jboss-as-appclient<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jbossas-appclient<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jbossas-bundles<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jboss-as-cli<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jboss-as-client-all<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jboss-as-clustering<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jboss-as-cmp<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jboss-as-configadmin<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jboss-as-connector<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jboss-as-controller<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jboss-as-controller-client<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jbossas-core<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jboss-as-core-security<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jboss-as-deployment-repository<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jboss-as-deployment-scanner<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jbossas-domain<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jboss-as-domain-http<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jboss-as-domain-management<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jboss-as-ee<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jboss-as-ee-deployment<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jboss-as-ejb3<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jboss-as-embedded<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jboss-as-host-controller<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jboss-as-jacorb<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jbossas-javadocs<0:7.5.24-1.Final_redhat_00001.1.ep6.el6
0:7.5.24-1.Final_redhat_00001.1.ep6.el6
redhat/jboss-as-jaxr<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jboss-as-jaxrs<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jboss-as-jdr<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jboss-as-jmx<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jboss-as-jpa<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jboss-as-jsf<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jboss-as-jsr77<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jboss-as-logging<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jboss-as-mail<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jboss-as-management-client-content<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jboss-as-messaging<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jboss-as-modcluster<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jbossas-modules-eap<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jboss-as-naming<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jboss-as-network<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jboss-as-osgi<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jboss-as-osgi-configadmin<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jboss-as-osgi-service<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jboss-as-picketlink<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jboss-as-platform-mbean<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jboss-as-pojo<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jboss-as-process-controller<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jbossas-product-eap<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jboss-as-protocol<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jboss-as-remoting<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jboss-as-sar<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jboss-as-security<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jboss-as-server<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jbossas-standalone<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jboss-as-system-jmx<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jboss-as-threads<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jboss-as-transactions<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jboss-as-version<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jboss-as-web<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jboss-as-webservices<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jbossas-welcome-content-eap<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jboss-as-weld<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jboss-as-xts<0:7.5.24-2.Final_redhat_00001.1.ep6.el6
0:7.5.24-2.Final_redhat_00001.1.ep6.el6
redhat/jbossts<1:4.17.45-2.Final_redhat_2.1.ep6.el6
1:4.17.45-2.Final_redhat_2.1.ep6.el6
redhat/jbossweb<0:7.5.32-2.Final_redhat_1.2.ep6.el6
0:7.5.32-2.Final_redhat_1.2.ep6.el6
redhat/log4j-eap6<0:1.2.17-3.redhat_00008.1.ep6.el7
0:1.2.17-3.redhat_00008.1.ep6.el7
redhat/log4j-jboss-logmanager<0:1.1.4-3.Final_redhat_00002.1.ep6.el7
0:1.1.4-3.Final_redhat_00002.1.ep6.el7
redhat/jboss-as-appclient<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jbossas-appclient<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jbossas-bundles<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jboss-as-cli<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jboss-as-client-all<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jboss-as-clustering<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jboss-as-cmp<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jboss-as-configadmin<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jboss-as-connector<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jboss-as-controller<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jboss-as-controller-client<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jbossas-core<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jboss-as-core-security<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jboss-as-deployment-repository<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jboss-as-deployment-scanner<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jbossas-domain<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jboss-as-domain-http<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jboss-as-domain-management<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jboss-as-ee<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jboss-as-ee-deployment<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jboss-as-ejb3<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jboss-as-embedded<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jboss-as-host-controller<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jboss-as-jacorb<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jbossas-javadocs<0:7.5.24-1.Final_redhat_00001.1.ep6.el7
0:7.5.24-1.Final_redhat_00001.1.ep6.el7
redhat/jboss-as-jaxr<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jboss-as-jaxrs<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jboss-as-jdr<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jboss-as-jmx<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jboss-as-jpa<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jboss-as-jsf<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jboss-as-jsr77<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jboss-as-logging<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jboss-as-mail<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jboss-as-management-client-content<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jboss-as-messaging<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jboss-as-modcluster<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jbossas-modules-eap<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jboss-as-naming<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jboss-as-network<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jboss-as-osgi<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jboss-as-osgi-configadmin<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jboss-as-osgi-service<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jboss-as-picketlink<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jboss-as-platform-mbean<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jboss-as-pojo<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jboss-as-process-controller<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jbossas-product-eap<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jboss-as-protocol<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jboss-as-remoting<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jboss-as-sar<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jboss-as-security<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jboss-as-server<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jbossas-standalone<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jboss-as-system-jmx<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jboss-as-threads<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jboss-as-transactions<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jboss-as-version<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jboss-as-web<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jboss-as-webservices<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jbossas-welcome-content-eap<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jboss-as-weld<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jboss-as-xts<0:7.5.24-2.Final_redhat_00001.1.ep6.el7
0:7.5.24-2.Final_redhat_00001.1.ep6.el7
redhat/jbossts<1:4.17.45-2.Final_redhat_2.1.ep6.el7
1:4.17.45-2.Final_redhat_2.1.ep6.el7
redhat/jbossweb<0:7.5.32-2.Final_redhat_1.2.ep6.el7
0:7.5.32-2.Final_redhat_1.2.ep6.el7
redhat/eap7-log4j-jboss-logmanager<0:1.2.2-1.Final_redhat_00002.1.el8ea
0:1.2.2-1.Final_redhat_00002.1.el8ea
redhat/eap7-log4j<0:2.17.1-1.redhat_00001.1.el8ea
0:2.17.1-1.redhat_00001.1.el8ea
redhat/eap7-log4j-jboss-logmanager<0:1.2.2-1.Final_redhat_00002.1.el7ea
0:1.2.2-1.Final_redhat_00002.1.el7ea
redhat/eap7-log4j<0:2.17.1-1.redhat_00001.1.el7ea
0:2.17.1-1.redhat_00001.1.el7ea
redhat/tomcat7<0:7.0.70-46.ep7.el7
0:7.0.70-46.ep7.el7
redhat/tomcat8<0:8.0.36-49.ep7.el7
0:8.0.36-49.ep7.el7
redhat/tomcat-native<0:1.2.23-26.redhat_26.ep7.el7
0:1.2.23-26.redhat_26.ep7.el7
redhat/rh-sso7-keycloak<0:15.0.4-1.redhat_00003.1.el7
0:15.0.4-1.redhat_00003.1.el7
redhat/rh-sso7-keycloak<0:15.0.4-1.redhat_00003.1.el8
0:15.0.4-1.redhat_00003.1.el8
redhat/rh-maven36-log4j12<0:1.2.17-23.3.el7
0:1.2.17-23.3.el7
redhat/snmp4j<0:3.6.4-0.1.el8e
0:3.6.4-0.1.el8e
redhat/redhat-sso<7-sso75-openshift-rhel8
7-sso75-openshift-rhel8
maven/org.zenframework.z8.dependencies.commons:log4j-1.2.17<=2.0
maven/log4j:log4j>=1.2.0<=1.2.17
Apache Log4j=1.2
Fedoraproject Fedora=35
Redhat Codeready Studio=12.0
Redhat Integration Camel K
Redhat Integration Camel Quarkus
Redhat Jboss A-mq=6.0.0
Redhat Jboss A-mq=7
Redhat Jboss A-mq Streaming
Redhat Jboss Data Grid=7.0.0
Redhat Jboss Data Virtualization=6.0.0
Redhat Jboss Enterprise Application Platform=6.0.0
Redhat Jboss Enterprise Application Platform=7.0
Redhat Jboss Fuse=6.0.0
Redhat Jboss Fuse=7.0.0
Redhat Jboss Fuse Service Works=6.0
Redhat Jboss Operations Network=3.0
Redhat Jboss Web Server=3.0
Redhat Openshift Application Runtimes
Redhat Openshift Container Platform=4.6
Redhat Openshift Container Platform=4.7
Redhat Openshift Container Platform=4.8
Redhat Process Automation=7.0
Redhat Single Sign-on=7.0
Redhat Software Collections
Redhat Enterprise Linux=6.0
Redhat Enterprise Linux=7.0
Redhat Enterprise Linux=8.0
Oracle Advanced Supply Chain Planning=12.1
Oracle Advanced Supply Chain Planning=12.2
Oracle Business Intelligence=5.9.0.0.0
Oracle Business Intelligence=12.2.1.3.0
Oracle Business Intelligence=12.2.1.4.0
Oracle Business Process Management Suite=12.2.1.3.0
Oracle Business Process Management Suite=12.2.1.4.0
Oracle Communications Eagle Ftp Table Base Retrieval=4.5
Oracle Communications Messaging Server=8.1
Oracle Communications Network Integrity=7.3.6
Oracle Communications Offline Mediation Controller<12.0.0.4.0
Oracle Communications Offline Mediation Controller=12.0.0.5.0
Oracle Communications Unified Inventory Management=7.3.4
Oracle Communications Unified Inventory Management=7.3.5
Oracle Communications Unified Inventory Management=7.4.1
Oracle Communications Unified Inventory Management=7.4.2
Oracle E-business Suite Cloud Manager And Cloud Backup Module=2.2.1.1.1
Oracle Enterprise Manager Base Platform=13.4.0.0
Oracle Enterprise Manager Base Platform=13.5.0.0
Oracle Financial Services Revenue Management And Billing Analytics=2.7.0.0
Oracle Financial Services Revenue Management And Billing Analytics=2.7.0.1
Oracle Financial Services Revenue Management And Billing Analytics=2.8.0.0
Oracle Fusion Middleware Common Libraries And Tools=12.2.1.4.0
Oracle GoldenGate
Oracle Healthcare Data Repository=8.1.0
Oracle Hyperion Data Relationship Management<11.2.8.0
Oracle Hyperion Infrastructure Technology<11.2.8.0
Oracle Identity Management Suite=12.2.1.3.0
Oracle Identity Management Suite=12.2.1.4.0
Oracle JDeveloper=12.2.1.3.0
Oracle Mysql Enterprise Monitor<=8.0.29
Oracle Retail Allocation=14.1.3.2
Oracle Retail Allocation=15.0.3.1
Oracle Retail Allocation=16.0.3
Oracle Retail Allocation=19.0.1
Oracle Retail Extract Transform And Load=13.2.5
Oracle Stream Analytics
Oracle Timesten Grid
Oracle Tuxedo=12.2.2.0.0
Oracle Utilities Testing Accelerator=6.0.0.1.1
Oracle Utilities Testing Accelerator=6.0.0.2.2
Oracle Utilities Testing Accelerator=6.0.0.3.1
Oracle WebLogic Server=12.2.1.3.0
Oracle WebLogic Server=12.2.1.4.0
Oracle WebLogic Server=14.1.1.0.0
IBM QRadar SIEM<=7.5 - 7.5.0 UP7
redhat/log4j<2.15.0
2.15.0
=1.2
=35
=12.0
=6.0.0
=7
=7.0.0
=6.0.0
=6.0.0
=7.0
=6.0.0
=7.0.0
=6.0
=3.0
=3.0
=4.6
=4.7
=4.8
=7.0
=7.0
=6.0
=7.0
=8.0
=12.1
=12.2
=5.9.0.0.0
=12.2.1.3.0
=12.2.1.4.0
=12.2.1.3.0
=12.2.1.4.0
=4.5
=8.1
=7.3.6
<12.0.0.4.0
=12.0.0.5.0
=7.3.4
=7.3.5
=7.4.1
=7.4.2
=2.2.1.1.1
=13.4.0.0
=13.5.0.0
=2.7.0.0
=2.7.0.1
=2.8.0.0
=12.2.1.4.0
=8.1.0
<11.2.8.0
<11.2.8.0
=12.2.1.3.0
=12.2.1.4.0
=12.2.1.3.0
<=8.0.29
=14.1.3.2
=15.0.3.1
=16.0.3
=19.0.1
=13.2.5
=12.2.2.0.0
=6.0.0.1.1
=6.0.0.2.2
=6.0.0.3.1
=12.2.1.3.0
=12.2.1.4.0
=14.1.1.0.0

Remedy

These are the possible mitigations for this flaw for releases version 1.x: - Comment out or remove JMSAppender in the Log4j configuration if it is used - Remove the JMSAppender class from the classpath. For example: ``` zip -q -d log4j-*.jar org/apache/log4j/net/JMSAppender.class ``` - Restrict access for the OS user on the platform running the application to prevent modifying the Log4j configuration by the attacker.

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Reference Links

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203