First published: Fri Dec 10 2021(Updated: )
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-44228. Note this issue only affects Log4j 1.2 when specifically configured to use JMSAppender, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.
Credit: security@apache.org secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/log4j | <0:1.2.14-6.5.el6_10 | 0:1.2.14-6.5.el6_10 |
redhat/log4j | <0:1.2.17-17.el7_4 | 0:1.2.17-17.el7_4 |
redhat/log4j | <0:1.2.17-16.el7_3 | 0:1.2.17-16.el7_3 |
redhat/log4j-eap6 | <0:1.2.17-3.redhat_00008.1.ep6.el6 | 0:1.2.17-3.redhat_00008.1.ep6.el6 |
redhat/log4j-jboss-logmanager | <0:1.1.4-3.Final_redhat_00002.1.ep6.el6 | 0:1.1.4-3.Final_redhat_00002.1.ep6.el6 |
redhat/jboss-as-appclient | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jbossas-appclient | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jbossas-bundles | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-cli | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-client-all | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-clustering | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-cmp | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-configadmin | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-connector | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-controller | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-controller-client | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jbossas-core | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-core-security | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-deployment-repository | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-deployment-scanner | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jbossas-domain | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-domain-http | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-domain-management | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-ee | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-ee-deployment | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-ejb3 | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-embedded | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-host-controller | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-jacorb | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jbossas-javadocs | <0:7.5.24-1.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-1.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-jaxr | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-jaxrs | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-jdr | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-jmx | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-jpa | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-jsf | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-jsr77 | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-logging | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-mail | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-management-client-content | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-messaging | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-modcluster | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jbossas-modules-eap | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-naming | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-network | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-osgi | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-osgi-configadmin | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-osgi-service | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-picketlink | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-platform-mbean | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-pojo | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-process-controller | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jbossas-product-eap | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-protocol | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-remoting | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-sar | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-security | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-server | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jbossas-standalone | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-system-jmx | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-threads | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-transactions | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-version | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-web | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-webservices | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jbossas-welcome-content-eap | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-weld | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-xts | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jbossts | <1:4.17.45-2.Final_redhat_2.1.ep6.el6 | 1:4.17.45-2.Final_redhat_2.1.ep6.el6 |
redhat/jbossweb | <0:7.5.32-2.Final_redhat_1.2.ep6.el6 | 0:7.5.32-2.Final_redhat_1.2.ep6.el6 |
redhat/log4j-eap6 | <0:1.2.17-3.redhat_00008.1.ep6.el7 | 0:1.2.17-3.redhat_00008.1.ep6.el7 |
redhat/log4j-jboss-logmanager | <0:1.1.4-3.Final_redhat_00002.1.ep6.el7 | 0:1.1.4-3.Final_redhat_00002.1.ep6.el7 |
redhat/jboss-as-appclient | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jbossas-appclient | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jbossas-bundles | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-cli | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-client-all | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-clustering | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-cmp | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-configadmin | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-connector | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-controller | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-controller-client | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jbossas-core | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-core-security | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-deployment-repository | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-deployment-scanner | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jbossas-domain | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-domain-http | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-domain-management | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-ee | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-ee-deployment | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-ejb3 | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-embedded | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-host-controller | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-jacorb | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jbossas-javadocs | <0:7.5.24-1.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-1.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-jaxr | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-jaxrs | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-jdr | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-jmx | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-jpa | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-jsf | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-jsr77 | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-logging | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-mail | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-management-client-content | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-messaging | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-modcluster | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jbossas-modules-eap | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-naming | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-network | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-osgi | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-osgi-configadmin | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-osgi-service | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-picketlink | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-platform-mbean | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-pojo | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-process-controller | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jbossas-product-eap | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-protocol | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-remoting | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-sar | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-security | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-server | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jbossas-standalone | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-system-jmx | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-threads | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-transactions | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-version | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-web | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-webservices | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jbossas-welcome-content-eap | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-weld | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-xts | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jbossts | <1:4.17.45-2.Final_redhat_2.1.ep6.el7 | 1:4.17.45-2.Final_redhat_2.1.ep6.el7 |
redhat/jbossweb | <0:7.5.32-2.Final_redhat_1.2.ep6.el7 | 0:7.5.32-2.Final_redhat_1.2.ep6.el7 |
redhat/eap7-log4j-jboss-logmanager | <0:1.2.2-1.Final_redhat_00002.1.el8ea | 0:1.2.2-1.Final_redhat_00002.1.el8ea |
redhat/eap7-log4j | <0:2.17.1-1.redhat_00001.1.el8ea | 0:2.17.1-1.redhat_00001.1.el8ea |
redhat/eap7-log4j-jboss-logmanager | <0:1.2.2-1.Final_redhat_00002.1.el7ea | 0:1.2.2-1.Final_redhat_00002.1.el7ea |
redhat/eap7-log4j | <0:2.17.1-1.redhat_00001.1.el7ea | 0:2.17.1-1.redhat_00001.1.el7ea |
redhat/tomcat7 | <0:7.0.70-46.ep7.el7 | 0:7.0.70-46.ep7.el7 |
redhat/tomcat8 | <0:8.0.36-49.ep7.el7 | 0:8.0.36-49.ep7.el7 |
redhat/tomcat-native | <0:1.2.23-26.redhat_26.ep7.el7 | 0:1.2.23-26.redhat_26.ep7.el7 |
redhat/rh-sso7-keycloak | <0:15.0.4-1.redhat_00003.1.el7 | 0:15.0.4-1.redhat_00003.1.el7 |
redhat/rh-sso7-keycloak | <0:15.0.4-1.redhat_00003.1.el8 | 0:15.0.4-1.redhat_00003.1.el8 |
redhat/rh-maven36-log4j12 | <0:1.2.17-23.3.el7 | 0:1.2.17-23.3.el7 |
redhat/snmp4j | <0:3.6.4-0.1.el8e | 0:3.6.4-0.1.el8e |
redhat/redhat-sso | <7-sso75-openshift-rhel8 | 7-sso75-openshift-rhel8 |
maven/org.zenframework.z8.dependencies.commons:log4j-1.2.17 | <=2.0 | |
maven/log4j:log4j | >=1.2.0<=1.2.17 | |
redhat/log4j | <2.15.0 | 2.15.0 |
Apache Log4j | =1.2 | |
Fedora | =35 | |
redhat codeready studio | =12.0 | |
Apache Camel | ||
Apache Camel | ||
redhat jboss a-mq | =6.0.0 | |
redhat jboss a-mq | =7 | |
redhat jboss a-mq streaming | ||
redhat jboss data grid | =7.0.0 | |
redhat jboss data virtualization | =6.0.0 | |
redhat jboss enterprise application platform | =6.0.0 | |
redhat jboss enterprise application platform | =7.0 | |
Red Hat JBoss Fuse | =6.0.0 | |
Red Hat JBoss Fuse | =7.0.0 | |
redhat jboss fuse service works | =6.0 | |
redhat jboss operations network | =3.0 | |
redhat jboss web server | =3.0 | |
redhat openshift application runtimes | ||
redhat openshift container platform | =4.6 | |
redhat openshift container platform | =4.7 | |
redhat openshift container platform | =4.8 | |
Red Hat Process Automation Manager | =7.0 | |
redhat single sign-on | =7.0 | |
redhat software collections | ||
Red Hat Enterprise Linux | =6.0 | |
Red Hat Enterprise Linux | =7.0 | |
Red Hat Enterprise Linux | =8.0 | |
Oracle Advanced Supply Chain Planning | =12.1 | |
Oracle Advanced Supply Chain Planning | =12.2 | |
Oracle Business Intelligence Enterprise Edition | =5.9.0.0.0 | |
Oracle Business Intelligence Enterprise Edition | =12.2.1.3.0 | |
Oracle Business Intelligence Enterprise Edition | =12.2.1.4.0 | |
Oracle Business Process Management Suite | =12.2.1.3.0 | |
Oracle Business Process Management Suite | =12.2.1.4.0 | |
Oracle Communications Eagle FTP Table Base Retrieval | =4.5 | |
Sun iPlanet Messaging Server | =8.1 | |
Oracle Communications Network Integrity | =7.3.6 | |
oracle communications offline mediation controller | <12.0.0.4.0 | |
oracle communications offline mediation controller | =12.0.0.5.0 | |
Oracle Communications Unified Inventory Management | =7.3.4 | |
Oracle Communications Unified Inventory Management | =7.3.5 | |
Oracle Communications Unified Inventory Management | =7.4.1 | |
Oracle Communications Unified Inventory Management | =7.4.2 | |
oracle e-business suite cloud manager and cloud backup module | =2.2.1.1.1 | |
Oracle Enterprise Manager Base Platform | =13.4.0.0 | |
Oracle Enterprise Manager Base Platform | =13.5.0.0 | |
oracle financial services revenue management and billing analytics | =2.7.0.0 | |
oracle financial services revenue management and billing analytics | =2.7.0.1 | |
oracle financial services revenue management and billing analytics | =2.8.0.0 | |
oracle fusion middleware common libraries and tools | =12.2.1.4.0 | |
Oracle GoldenGate | ||
Oracle Healthcare Data Repository | =8.1.0 | |
Oracle Hyperion Data Relationship Management | <11.2.8.0 | |
oracle hyperion infrastructure technology | <11.2.8.0 | |
Oracle Identity Management Suite | =12.2.1.3.0 | |
Oracle Identity Management Suite | =12.2.1.4.0 | |
Oracle JDeveloper | =12.2.1.3.0 | |
MySQL Enterprise Monitor | <=8.0.29 | |
oracle retail allocation | =14.1.3.2 | |
oracle retail allocation | =15.0.3.1 | |
oracle retail allocation | =16.0.3 | |
oracle retail allocation | =19.0.1 | |
Oracle Retail Extract Transform And Load | =13.2.5 | |
oracle stream analytics | ||
oracle timesten grid | ||
Oracle Tuxedo | =12.2.2.0.0 | |
Oracle Utilities Testing Accelerator | =6.0.0.1.1 | |
Oracle Utilities Testing Accelerator | =6.0.0.2.2 | |
Oracle Utilities Testing Accelerator | =6.0.0.3.1 | |
Oracle WebLogic Server | =12.2.1.3.0 | |
Oracle WebLogic Server | =12.2.1.4.0 | |
Oracle WebLogic Server | =14.1.1.0.0 | |
IBM QRadar Security Information and Event Manager | <=7.5 - 7.5.0 UP7 |
These are the possible mitigations for this flaw for releases version 1.x: - Comment out or remove JMSAppender in the Log4j configuration if it is used - Remove the JMSAppender class from the classpath. For example: ``` zip -q -d log4j-*.jar org/apache/log4j/net/JMSAppender.class ``` - Restrict access for the OS user on the platform running the application to prevent modifying the Log4j configuration by the attacker.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
The severity of CVE-2021-4104 is classified as low, but it still poses a risk due to potential remote code execution via JNDI lookups.
To fix CVE-2021-4104, update your Log4j to versions 1.2.17-3.redhat_00008.1.ep6 or later, or to any version above 2.15.0.
CVE-2021-4104 affects applications using Apache Log4j version 1.2.0 to 1.2.17, particularly those with write access to the Log4j configuration.
CVE-2021-4104 can potentially enable remote code execution attacks by allowing an attacker to manipulate JMSAppender configuration.
A possible workaround for CVE-2021-4104 is to disable the JMSAppender or restrict modification rights on the Log4j configuration.