Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
| AND |
|
Configuration 6 (hide)
| AND |
|
Configuration 7 (hide)
| AND |
|
Configuration 8 (hide)
| AND |
|
Configuration 9 (hide)
| AND |
|
Configuration 10 (hide)
|
Information
Published : 2021-12-18 12:15
Updated : 2022-07-25 18:18
NVD link : CVE-2021-45105
Mitre link : CVE-2021-45105
JSON object : View
Products Affected
oracle
- webcenter_portal
- retail_predictive_application_server
- communications_services_gatekeeper
- retail_price_management
- retail_invoice_matching
- primavera_p6_enterprise_project_portfolio_management
- retail_service_backbone
- retail_order_broker
- financial_services_analytical_applications_infrastructure
- retail_back_office
- weblogic_server
- instantis_enterprisetrack
- communications_diameter_signaling_router
- retail_returns_management
- financial_services_model_management_and_governance
- business_intelligence
- retail_order_management_system
- siebel_ui_framework
- primavera_unifier
- retail_eftlink
- retail_central_office
- retail_integration_bus
- communications_interactive_session_recorder
- communications_webrtc_session_controller
- retail_point-of-service
- communications_service_broker
- primavera_gateway
- managed_file_transfer
sonicwall
- 6bk1602-0aa12-0tp0_firmware
- network_security_manager
- 6bk1602-0aa22-0tp0_firmware
- 6bk1602-0aa52-0tp0
- 6bk1602-0aa32-0tp0
- 6bk1602-0aa52-0tp0_firmware
- web_application_firewall
- 6bk1602-0aa22-0tp0
- 6bk1602-0aa32-0tp0_firmware
- email_security
- 6bk1602-0aa12-0tp0
- 6bk1602-0aa42-0tp0_firmware
- 6bk1602-0aa42-0tp0
debian
- debian_linux
netapp
- cloud_manager
apache
- log4j
