REDHAT-BUG-2041959: High severity Apache Log4j vulnerability

Published Jan 18, 2022
·
Updated

By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converted from PatternLayout. The message converter, %m, is likely to always be included. This allows attackers to manipulate the SQL by entering crafted strings into input fields or headers of an application that are logged allowing unintended SQL queries to be executed.

Note this issue only affects Log4j 1.x when specifically configured to use the JDBCAppender, which is not the default. Beginning in version 2.0-beta8, the JDBCAppender was re-introduced with proper support for parameterized SQL queries and further customization over the columns written to in logs.

References:

https://www.openwall.com/lists/oss-security/2022/01/18/4

Affected Software

1 affected component
Apache Log4j>=1.0

Event History

Jan 18, 2022
Data Sourced
via Red Hat·03:48 PM
DescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2041959?

The severity of REDHAT-BUG-2041959 is considered high due to the potential SQL injection vulnerability.

2

How do I fix REDHAT-BUG-2041959?

To fix REDHAT-BUG-2041959, upgrade to a version of Log4j that is not affected, or implement input validation and sanitization for user-supplied data.

3

What versions are affected by REDHAT-BUG-2041959?

REDHAT-BUG-2041959 affects all versions of Apache Log4j 1.2.x.

4

What type of vulnerability is REDHAT-BUG-2041959?

REDHAT-BUG-2041959 is an SQL injection vulnerability that can be exploited via crafted strings in SQL statements.

5

Who is responsible for resolving REDHAT-BUG-2041959?

It is the responsibility of system administrators and developers to resolve REDHAT-BUG-2041959 by applying the necessary updates and patches.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203