Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
Configuration 9 (hide)
AND |
|
Configuration 10 (hide)
|
History
No history.
Information
Published : 2021-12-18 12:15
Updated : 2024-02-28 18:48
NVD link : CVE-2021-45105
Mitre link : CVE-2021-45105
CVE.ORG link : CVE-2021-45105
JSON object : View
Products Affected
oracle
- financial_services_analytical_applications_infrastructure
- healthcare_data_repository
- peoplesoft_enterprise_peopletools
- agile_plm_mcad_connector
- banking_platform
- banking_treasury_management
- communications_session_route_manager
- communications_eagle_element_management_system
- healthcare_foundation
- retail_data_extractor_for_merchandising
- healthcare_translational_research
- healthcare_master_person_index
- business_intelligence
- retail_order_broker
- hospitality_token_proxy_service
- banking_loans_servicing
- retail_order_management_system
- insurance_insbridge_rating_and_underwriting
- e-business_suite
- enterprise_manager_base_platform
- communications_evolved_communications_application_server
- hyperion_data_relationship_management
- identity_manager_connector
- communications_ip_service_activator
- hospitality_suite8
- hyperion_infrastructure_technology
- communications_cloud_native_core_security_edge_protection_proxy
- health_sciences_empirica_signal
- primavera_gateway
- banking_party_management
- health_sciences_inform
- primavera_unifier
- communications_cloud_native_core_policy
- utilities_framework
- communications_cloud_native_core_console
- communications_element_manager
- hyperion_bi\+
- communications_network_integrity
- communications_cloud_native_core_network_repository_function
- communications_messaging_server
- communications_user_data_repository
- communications_session_report_manager
- communications_performance_intelligence_center
- retail_service_backbone
- mysql_enterprise_monitor
- communications_diameter_signaling_router
- managed_file_transfer
- communications_asap
- retail_customer_insights
- webcenter_portal
- payment_interface
- hyperion_planning
- communications_cloud_native_core_unified_data_repository
- enterprise_manager_for_peoplesoft
- financial_services_model_management_and_governance
- autovue_for_agile_product_lifecycle_management
- communications_pricing_design_center
- communications_network_charging_and_control
- communications_billing_and_revenue_management
- jdeveloper
- retail_financial_integration
- communications_cloud_native_core_network_slice_selection_function
- communications_cloud_native_core_service_communication_proxy
- communications_eagle_ftp_table_base_retrieval
- identity_management_suite
- communications_cloud_native_core_network_function_cloud_native_environment
- siebel_ui_framework
- sql_developer
- communications_interactive_session_recorder
- instantis_enterprisetrack
- communications_webrtc_session_controller
- enterprise_manager_ops_center
- banking_enterprise_default_management
- health_sciences_information_manager
- flexcube_universal_banking
- retail_price_management
- communications_convergence
- retail_merchandising_system
- retail_returns_management
- insurance_data_gateway
- communications_services_gatekeeper
- agile_engineering_data_management
- hyperion_tax_provision
- management_cloud_engine
- communications_service_broker
- banking_payments
- primavera_p6_enterprise_project_portfolio_management
- retail_point-of-service
- agile_plm
- retail_eftlink
- retail_store_inventory_management
- communications_convergent_charging_controller
- banking_trade_finance
- hyperion_profitability_and_cost_management
- weblogic_server
- retail_back_office
- retail_central_office
- data_integrator
- retail_invoice_matching
- webcenter_sites
- banking_deposits_and_lines_of_credit_servicing
- retail_integration_bus
- retail_predictive_application_server
- taleo_platform
- communications_unified_inventory_management
sonicwall
- 6bk1602-0aa12-0tp0
- 6bk1602-0aa22-0tp0_firmware
- email_security
- 6bk1602-0aa22-0tp0
- web_application_firewall
- 6bk1602-0aa32-0tp0_firmware
- 6bk1602-0aa12-0tp0_firmware
- 6bk1602-0aa42-0tp0
- network_security_manager
- 6bk1602-0aa52-0tp0_firmware
- 6bk1602-0aa42-0tp0_firmware
- 6bk1602-0aa32-0tp0
- 6bk1602-0aa52-0tp0
netapp
- cloud_manager
apache
- log4j
debian
- debian_linux