CVE-2021-4104
published 2021-12-14CVE-2021-4104: JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can…
PriorityP181high7.5CVSS 3.1
AVNACHPRLUINSUCHIHAH
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
81.15%
99.6th percentile
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-44228. Note this issue only affects Log4j 1.2 when specifically configured to use JMSAppender, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.
Affected
88 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | hadoop | — | — |
| apache | log4j | — | — |
| apache | log4j | 1.0.1 – 1.2.17 | — |
| apache_software_foundation | apache_log4j_1.x | >= 1.0.1 < unspecified | unspecified |
| apache_software_foundation | apache_log4j_1.x | >= unspecified < 2.0-alpha1 | 2.0-alpha1 |
| debian | apache-log4j1.2 | < apache-log4j1.2 1.2.17-11 (bookworm) | apache-log4j1.2 1.2.17-11 (bookworm) |
| fedoraproject | fedora | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_32-bit_systems | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_64-bit_systems | — | — |
| msrc | microsoft_excel_2013_rt_service_pack_1 | — | — |
| msrc | microsoft_excel_2013_service_pack_1 | — | — |
| msrc | microsoft_excel_2016 | — | — |
| msrc | microsoft_office_2013_rt_service_pack_1 | — | — |
| msrc | microsoft_office_2013_service_pack_1 | — | — |
| msrc | microsoft_office_2016 | — | — |
| msrc | microsoft_office_2019_for_32-bit_editions | — | — |
| msrc | microsoft_office_2019_for_64-bit_editions | — | — |
| msrc | microsoft_office_online_server | — | — |
| msrc | microsoft_office_web_apps_server_2013_service_pack_1 | — | — |
| oracle | advanced_supply_chain_planning | — | — |
| oracle | advanced_supply_chain_planning | — | — |
| oracle | business_intelligence | — | — |
| oracle | business_intelligence | — | — |
| oracle | business_intelligence | — | — |
| oracle | business_process_management_suite | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2021-4104 is only exploitable when Log4j 1.2 is explicitly configured to use JMSAppender with attacker-controlled TopicBindingName and TopicConnectionFactoryBindingName configuration values; look for these non-default configuration entries as evidence of exploitation setup. ↗
- →Inject JNDI payloads into HTTP request headers (X-Api-Version, User-Agent, Referer, X-Druid-Comment, Origin, Location, X-Forwarded-For, Cookie, X-Requested-With, X-Forwarded-Host, Accept, Authentication, Authorization) and POST form fields to detect vulnerable Log4j instances via out-of-band DNS callbacks. ↗
- →Monitor for outbound LDAP/LDAPS connections originating from Java application servers, especially those triggered by log message processing — this is the callback mechanism for JNDI-based exploitation. ↗
- →For on-premises scanner detection of Log4Shell (related JNDI attack chain), monitor for LDAP callbacks to the scanner itself (Plugin 155998 approach); for cloud/external detection, monitor DNS callbacks on port 53 for unique tokens embedded in JNDI payloads (Plugin 156014 approach). ↗
- →Use Snort SIDs 58722-58744, 58751, 58784-58790, 58795, 58801, 58811-58814 to detect exploitation attempts related to the Log4j JNDI RCE vulnerability family (CVE-2021-44228/CVE-2021-45046/CVE-2021-45105), which shares the same JNDI attack vector as CVE-2021-4104. ↗
- →Use ClamAV signatures Java.Malware.CVE_2021_44228-9915816-1 and PUA.Java.Tool.CVE_2021_44228-9916978-0 to detect malicious payloads exploiting the Log4j JNDI RCE family, which includes CVE-2021-4104. ↗
- →Scan HTTP headers and POST/GET values, XML, JSON, and cookies for JNDI lookup strings starting with '${jndi:' as an indicator of active exploitation attempts against Log4j. ↗
- ·CVE-2021-4104 only affects Log4j 1.2 when explicitly configured to use JMSAppender — it is NOT exploitable in default configurations. Log4j 1.2 is end-of-life since August 2015. ↗
- ·Exploitation requires the attacker to have write access to the Log4j configuration in order to set malicious TopicBindingName and TopicConnectionFactoryBindingName values. ↗
- ·CVE-2021-4104 was issued specifically to address the JMSAppender flaw in Log4j 1.x, which is a separate component from the JNDILookup plugin flaw in Log4j 2.x (CVE-2021-44228); detection rules targeting Log4j 2.x JNDI lookups may not cover this vector. ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
ghsa10.0CRITICAL
osv10.0CRITICAL
vulncheck7.5HIGH
vendor_apache7.5HIGH
vendor_debian7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
vendor_msrc5.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Communications Applications Risk Matrix: Security (Apache Log4j) — CVE-2021-4104
vendor_oracle·2024-01-15·CVSS 7.5
CVE-2021-4104 [HIGH] Oracle Oracle Communications Applications Risk Matrix: Security (Apache Log4j) — CVE-2021-4104
Oracle Oracle Communications Applications Risk Matrix: Security (Apache Log4j) vulnerability
CVE: CVE-2021-4104
CVSS: 7.5
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujan2024 (JAN 2024)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Web Console Design (Apache Log4j) — CVE-2021-4104
vendor_oracle·2023-07-15·CVSS 7.5
CVE-2021-4104 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: Web Console Design (Apache Log4j) — CVE-2021-4104
Oracle Oracle Fusion Middleware Risk Matrix: Web Console Design (Apache Log4j) vulnerability
CVE: CVE-2021-4104
CVSS: 7.5
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujul2023 (JUL 2023)
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: Application Service Level Management (Apache Log4j) — CVE-2021-4104
vendor_oracle·2022-10-15·CVSS 7.5
CVE-2021-4104 [HIGH] Oracle Oracle Enterprise Manager Risk Matrix: Application Service Level Management (Apache Log4j) — CVE-2021-4104
Oracle Oracle Enterprise Manager Risk Matrix: Application Service Level Management (Apache Log4j) vulnerability
CVE: CVE-2021-4104
CVSS: 7.5
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpuoct2022 (OCT 2022)
Ubuntu
Apache Log4j 1.2 vulnerability
vendor_ubuntu·2022-02-08
CVE-2021-4104 Apache Log4j 1.2 vulnerability
Title: Apache Log4j 1.2 vulnerability
Summary: Apache Log4j 1.2 could be made to crash or run programs if it received specially
crafted input.
USN-5223-1 fixed a vulnerability in Apache Log4j 1.2. This update
provides the corresponding update for Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that Apache Log4j 1.2 was vulnerable to deserialization of
untrusted data if the configuration file was editable. An attacker could use
this vulnerability to cause a DoS or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
log4j: Remote code execution in Log4j 1.x when application is configured to use JMSSink
vendor_redhat·2022-01-18·CVSS 7.5
CVE-2022-23302 [HIGH] CWE-502 log4j: Remote code execution in Log4j 1.x when application is configured to use JMSSink
log4j: Remote code execution in Log4j 1.x when application is configured to use JMSSink
JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a TopicConnectionFactoryBindingName configuration causing JMSSink to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-4104. Note this issue only affects Log4j 1.x when specifically configured to use JMSSink, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.
A flaw was found in the Java
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Centralized Thirdparty Jars (Apache Log4j) — CVE-2021-4104
vendor_oracle·2022-01-15·CVSS 7.5
CVE-2021-4104 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: Centralized Thirdparty Jars (Apache Log4j) — CVE-2021-4104
Oracle Oracle Fusion Middleware Risk Matrix: Centralized Thirdparty Jars (Apache Log4j) vulnerability
CVE: CVE-2021-4104
CVSS: 7.5
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujan2022 (JAN 2022)
Ubuntu
Apache Log4j 1.2 vulnerability
vendor_ubuntu·2022-01-12
CVE-2021-4104 Apache Log4j 1.2 vulnerability
Title: Apache Log4j 1.2 vulnerability
Summary: Apache Log4j 1.2 could be made to crash or run programs if it received specially
crafted input.
It was discovered that Apache Log4j 1.2 was vulnerable to deserialization of
untrusted data if the configuration file was editable. An attacker could use
this vulnerability to cause a DoS or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2022-23302: apache-log4j1.2 - JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrust...
vendor_debian·2022·CVSS 7.5
CVE-2022-23302 [HIGH] CVE-2022-23302: apache-log4j1.2 - JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrust...
JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a TopicConnectionFactoryBindingName configuration causing JMSSink to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-4104. Note this issue only affects Log4j 1.x when specifically configured to use JMSSink, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.
Scope: local
bookworm: resolved (fixed in 1.2.17-11)
bullseye: resolved (fixed in 1.2.17-10+deb11u1)
forky: resolved (
Red Hat
log4j-core: Remote code execution in Log4j 2.x when logs contain an attacker-controlled string value
vendor_redhat·2021-12-10·CVSS 7.5
CVE-2021-44228 [HIGH] CWE-20 log4j-core: Remote code execution in Log4j 2.x when logs contain an attacker-controlled string value
log4j-core: Remote code execution in Log4j 2.x when logs contain an attacker-controlled string value
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Ser
Red Hat
log4j: Remote code execution in Log4j 1.x when application is configured to use JMSAppender
vendor_redhat·2021-12-10·CVSS 7.5
CVE-2021-4104 [HIGH] CWE-20 log4j: Remote code execution in Log4j 1.x when application is configured to use JMSAppender
log4j: Remote code execution in Log4j 1.x when application is configured to use JMSAppender
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-44228. Note this issue only affects Log4j 1.2 when specifically configured to use JMSAppender, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.
A flaw was found in the Java logging library Apache Log4j in version 1.x. JMSAppender
Microsoft
Microsoft Office Information Disclosure Vulnerability
vendor_msrc·2021-05-11·CVSS 5.5
CVE-2021-31178 [MEDIUM] Microsoft Office Information Disclosure Vulnerability
Microsoft Office Information Disclosure Vulnerability
FAQ: What type of information could be disclosed by this vulnerability?
The type of information that could be disclosed if an attacker successfully exploited this vulnerability is uninitialized memory.
FAQ: Is the Preview Pane an attack vector for this vulnerability?
No, the Preview Pane is not an attack vector.
Microsoft Office Excel: Microsoft Office Excel
Microsoft: Microsoft
Impact: Information Disclosure
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Remediation: Click to Run
Reference: https://www.microsoft.com/download/details.aspx?familyid=1fb124f1-cb15-4104-b068-7d040204bdd1
Reference: https://www.microsoft.com/
Microsoft
Microsoft Excel Information Disclosure Vulnerability
vendor_msrc·2021-05-11·CVSS 5.5
CVE-2021-31174 [MEDIUM] Microsoft Excel Information Disclosure Vulnerability
Microsoft Excel Information Disclosure Vulnerability
FAQ: What type of information could be disclosed by this vulnerability?
The type of information that could be disclosed if an attacker successfully exploited this vulnerability is uninitialized memory.
FAQ: Is the Preview Pane an attack vector for this vulnerability?
No, the Preview Pane is not an attack vector.
Microsoft Office Excel: Microsoft Office Excel
Microsoft: Microsoft
Impact: Information Disclosure
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Remediation: Click to Run
Reference: https://www.microsoft.com/download/details.aspx?familyid=1fb124f1-cb15-4104-b068-7d040204bdd1
Reference: https://www.microsoft.com/d
Debian
CVE-2021-4104: apache-log4j1.2 - JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when...
vendor_debian·2021·CVSS 7.5
CVE-2021-4104 [HIGH] CVE-2021-4104: apache-log4j1.2 - JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when...
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-44228. Note this issue only affects Log4j 1.2 when specifically configured to use JMSAppender, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.
Scope: local
bookworm: resolved (fixed in 1.2.17-11)
bullseye: resolved (fixed in 1.2.17-10+deb11u1)
forky: resolved (fixed in 1.2.17-11)
sid: resolved (fixed in 1.2.17-11)
trixie
Apache
Apache hadoop: CVE-2021-4104
vendor_apache·CVSS 7.5
CVE-2021-4104 [HIGH] Apache hadoop: CVE-2021-4104
Apache hadoop: CVE-2021-4104
JMSAppender in Log4j 1.2, used by all versions of Apache Hadoop, is vulnerable to the Log4Shell attack in a similar fashion to CVE-2021-44228. However, the JMSAppender is not the default configuration shipped in Hadoop. When JMSAppender is not enabled, Hadoop is not vulnerable to the attack. To mitigate the risk, you can remove JMSAppender from the log4j-1.2.17.jar artifact yourself following the instructions in this link .
GHSA
Deserialization of Untrusted Data in Log4j 1.x
ghsa·2022-01-21·CVSS 7.5
CVE-2022-23302 [HIGH] CWE-502 Deserialization of Untrusted Data in Log4j 1.x
Deserialization of Untrusted Data in Log4j 1.x
JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a TopicConnectionFactoryBindingName configuration causing JMSSink to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-4104. Note this issue only affects Log4j 1.x when specifically configured to use JMSSink, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.
OSV
Deserialization of Untrusted Data in Log4j 1.x
osv·2022-01-21·CVSS 7.5
CVE-2022-23302 [HIGH] Deserialization of Untrusted Data in Log4j 1.x
Deserialization of Untrusted Data in Log4j 1.x
JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a TopicConnectionFactoryBindingName configuration causing JMSSink to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-4104. Note this issue only affects Log4j 1.x when specifically configured to use JMSSink, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.
OSV
CVE-2022-23302: JMSSink in all versions of Log4j 1
osv·2022-01-18·CVSS 7.5
CVE-2022-23302 [HIGH] CVE-2022-23302: JMSSink in all versions of Log4j 1
JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a TopicConnectionFactoryBindingName configuration causing JMSSink to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-4104. Note this issue only affects Log4j 1.x when specifically configured to use JMSSink, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.
OSV
Using JMSAppender in log4j configuration may lead to deserialization of untrusted data
osv·2021-12-17·CVSS 7.5
[HIGH] Using JMSAppender in log4j configuration may lead to deserialization of untrusted data
Using JMSAppender in log4j configuration may lead to deserialization of untrusted data
### Impact
ClickHouse JDBC Bridge uses [slf4j-log4j12 1.7.32](https://repo1.maven.org/maven2/org/slf4j/slf4j-log4j12/1.7.32/), which depends on [log4j 1.2.17](https://repo1.maven.org/maven2/log4j/log4j/1.2.17/). It allows a remote attacker to execute code on the server, if you changed default log4j configuration by adding JMSAppender and an insecure JMS broker.
### Patches
The patch version `2.0.7` removed log4j dependency by replacing `slf4j-log4j12` to `slf4j-jdk14`. Logging configuration is also changed from `log4j.properties` to `logging.properties`.
### Workarounds
1. Do NOT change log4j configuration to use JMSAppender along with insecure JMS broker
2. Alternatively, you can issue below comma
GHSA
Using JMSAppender in log4j configuration may lead to deserialization of untrusted data
ghsa·2021-12-17·CVSS 7.5
[HIGH] CWE-502 Using JMSAppender in log4j configuration may lead to deserialization of untrusted data
Using JMSAppender in log4j configuration may lead to deserialization of untrusted data
### Impact
ClickHouse JDBC Bridge uses [slf4j-log4j12 1.7.32](https://repo1.maven.org/maven2/org/slf4j/slf4j-log4j12/1.7.32/), which depends on [log4j 1.2.17](https://repo1.maven.org/maven2/log4j/log4j/1.2.17/). It allows a remote attacker to execute code on the server, if you changed default log4j configuration by adding JMSAppender and an insecure JMS broker.
### Patches
The patch version `2.0.7` removed log4j dependency by replacing `slf4j-log4j12` to `slf4j-jdk14`. Logging configuration is also changed from `log4j.properties` to `logging.properties`.
### Workarounds
1. Do NOT change log4j configuration to use JMSAppender along with insecure JMS broker
2. Alternatively, you can issue below comma
OSV
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data
osv·2021-12-14·CVSS 10.0
CVE-2021-4104 [CRITICAL] JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-44228. Note this issue only affects Log4j 1.2 when specifically configured to use JMSAppender, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.
GHSA
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data
ghsa·2021-12-14·CVSS 10.0
CVE-2021-4104 [CRITICAL] CWE-502 JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-44228. Note this issue only affects Log4j 1.2 when specifically configured to use JMSAppender, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.
OSV
CVE-2021-4104: JMSAppender in Log4j 1
osv·2021-12-14·CVSS 7.5
CVE-2021-4104 [HIGH] CVE-2021-4104: JMSAppender in Log4j 1
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-44228. Note this issue only affects Log4j 1.2 when specifically configured to use JMSAppender, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.
VulnCheck
Apache log4j Deserialization of Untrusted Data
vulncheck·2021·CVSS 7.5
CVE-2021-4104 [HIGH] Apache log4j Deserialization of Untrusted Data
Apache log4j Deserialization of Untrusted Data
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-44228. Note this issue only affects Log4j 1.2 when specifically configured to use JMSAppender, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.
Affected: Apache log4j
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the produ
No detection rules found.
Nuclei
Flexnet - Remote Code Execution (Apache Log4j)
nuclei·CVSS 7.5
CVE-2021-44228 [HIGH] Flexnet - Remote Code Execution (Apache Log4j)
Flexnet - Remote Code Execution (Apache Log4j)
Flexnet is susceptible to Log4j JNDI remote code execution.
Template:
id: flexnet-log4j-rce
info:
name: Flexnet - Remote Code Execution (Apache Log4j)
author: shaikhyaser
severity: critical
description: |
Flexnet is susceptible to Log4j JNDI remote code execution.
reference:
- https://community.flexera.com/t5/Revenera-Company-News/Security-Advisory-Log4j-Java-Vulnerability-CVE-2021-4104-CVE/ba-p/216905
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
cvss-score: 10
cve-id: CVE-2021-44228
cwe-id: CWE-77,CWE-502
cpe: cpe:2.3:a:flexera:flexnet_publisher:*:*:*:*:*:*:*:*
metadata:
max-request: 1
shodan-query: title:"Flexnet"
product: flexnet_publisher
vendor: flexera
tags: cve,cve2021,rce,jndi,log4j,flexnet,oast,kev,vu
Tenable
Tenable Research Advisories: Urgent Action
blogs_tenable·2023-11-20
Tenable Research Advisories: Urgent Action
by Cesar Navas November 20, 2023
Tenable Research delivers world class exposure intelligence, data science insights, zero day research and security advisories. Our Security Response Team (SRT) in Tenable Research tracks threat and vulnerability intelligence feeds to make sure our research teams can deliver sensor coverage to our products as quickly as possible. The SRT also works to dig into technical details and author white papers, blogs, and additional communications to ensure stakeholders are fully informed of the latest cyber risks and threats. The SRT provides breakdowns for the latest critical vulnerabilities on the Tenable blog.
When security events rise to the level of taking immediate action, Tenable - leveraging SRT intelligence - notifies customers proactively to provide expo
Tenable
AA23-215A: 2022's Top Routinely Exploited Vulnerabilities
blogs_tenable·2023-08-03
AA23-215A: 2022's Top Routinely Exploited Vulnerabilities
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
log4shell Critical Vulnerability
blogs_tenable·2022-11-02·CVSS 10.0
CVE-2021-44228 [CRITICAL] log4shell Critical Vulnerability
by Cesar Navas November 2, 2022
On December 9, 2021, researchers published proof-of-concept (PoC) exploit code for a critical vulnerability in Apache Log4j, a Java logging library used by a number of applications and services. This vulnerability, identified as CVE-2021-44228, is a Remote Code Execution (RCE) vulnerability in Apache Log4j. This dashboard is designed to help organizations determine what assets may contain vulnerabilities susceptible to the Apache Log4j exploit.
The Log4j vulnerability impacts a number of services and applications used widely across the internet, and is actively being exploited with multiple proofs of concept on GitHub.
According to the published CVE, all Apache Log4j versions 2.14.1 or less are vulnerable. An unauthenticated remote attacker could exploit
Tenable
Defending Against Ransomware (ACT)
blogs_tenable·2022-11-01
Defending Against Ransomware (ACT)
by Josef Weiss November 1, 2022
Ransomware attacks leverage well-known and established software vulnerabilities and poor cyber hygiene. Successful ransomware attacks can cripple an organization with increased costs and lost revenue. This dashboard highlights a path forward with an in-depth focus on cyber hygiene by enabling IT staff to focus on vulnerabilities that could have the most impact to the organization in the event of a ransomware attack.
There are many contributing factors to the upward trend of ransomware. The most important is the large number of software vulnerabilities and misconfigurations, along with Active Directory (AD) weaknesses that enable attackers to escalate privileges. Threat actors leverage poor cyber hygiene to their advantage to gain a foothold and propagate a
Tenable
Oracle October 2022 Critical Patch Update Addresses 179 CVEs
blogs_tenable·2022-10-19
Oracle October 2022 Critical Patch Update Addresses 179 CVEs
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Qualys
Mitigating the Risk of Zero-Day Vulnerabilities by using Compensating Controls
blogs_qualys·2022-08-23
Mitigating the Risk of Zero-Day Vulnerabilities by using Compensating Controls
## Table of Contents
Why Are Zero-Day Attacks/Exploits so Dangerous?
How Qualys Policy Compliance Helps Combat Zero-Day Threats
Benefit of Qualys Policy Compliance for Zero-Day Threats
Summary
Getting Started
Contributors
Zero-day vulnerability attacks have emerged as a major cybersecurity threat in the last few years. Organizations most often targeted include large enterprises and government/Federal agencies. However, any organization, regardless of its size, business, or industry, is a potential target for zero-day threats.
Most notably, already publicly disclosed. This means that one out of every four zero-day exploits detected could potentially have been avoided if a more thorough investigation and patching effort had been pursued. In 2021, around 58 zero-day vulnerabilities we
Tenable
Oracle July 2022 Critical Patch Update Addresses 188 CVEs
blogs_tenable·2022-07-20
Oracle July 2022 Critical Patch Update Addresses 188 CVEs
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Oracle January 2022 Critical Patch Update Addresses 266 CVEs
blogs_tenable·2022-01-19
Oracle January 2022 Critical Patch Update Addresses 266 CVEs
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Sentinelone
Log4j One Month On | Crimeware and Exploitation Roundup
blogs_sentinelone·2022-01-10·CVSS 7.5
CVE-2021-44228 [HIGH] Log4j One Month On | Crimeware and Exploitation Roundup
It has been 31 days since the initial public disclosure of a critical remote code execution (RCE) vulnerability in the Apache Log4j logging library that upended enterprise security at the close of 2021. In that time, since the initial CVE-2021-44228 (critical), we’ve already seen five more related CVEs
CVE-2021-45046 (critical)
CVE-2021-4104 (high)
CVE-2021-42550 (moderate)
CVE-2021-45105 (moderate)
CVE-2021-44832 (moderate))
and several updates to the library from 2.15.01 on December 9th to 2.17.1 on December 28th.
The importance of this class of vulnerabilities in such a ubiquitous library must not be forgotten with the next spin of the cyber news cycle: with millions of vulnerable devices, attacks are likely to continue for as long as such devices running unpatched software can b
Sentinelone
Log4j One Month On | Crimeware and Exploitation Roundup
blogs_sentinelone·2022-01-10·CVSS 7.5
CVE-2021-44228 [HIGH] Log4j One Month On | Crimeware and Exploitation Roundup
It has been 31 days since the initial public disclosure of a critical remote code execution (RCE) vulnerability in the Apache Log4j logging library that upended enterprise security at the close of 2021. In that time, since the initial CVE-2021-44228 (critical), we’ve already seen five more related CVEs
- CVE-2021-45046 (critical)
- CVE-2021-4104 (high)
- CVE-2021-42550 (moderate)
- CVE-2021-45105 (moderate)
- CVE-2021-44832 (moderate))
and several updates to the library from 2.15.01 on December 9th to 2.17.1 on December 28th.
The importance of this class of vulnerabilities in such a ubiquitous library must not be forgotten with the next spin of the cyber news cycle: with millions of vulnerable devices, attacks are likely to continue for as long as such devices running unpatched software
Tenable
Assess Log4Shell Like an Attacker With Tenable’s Dynamic Detections
blogs_tenable·2021-12-21
Assess Log4Shell Like an Attacker With Tenable’s Dynamic Detections
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Wiz
Log4Shell: Wrap all your Log4j fixes before the holidays | Wiz Blog
blogs_wiz·2021-12-21·CVSS 10.0
CVE-2021-44832 [CRITICAL] Log4Shell: Wrap all your Log4j fixes before the holidays | Wiz Blog
December 28, 2021 update - CVE-2021-44832, a new Log4j vulnerability
On December 28, 2021, Apache released new log4j version 2.17.1 to address CVE-2021-44832, a new remote code execution vulnerability affecting log4j 2.0-alpha7 - 2.17.0 excluding 2.3.2 and 2.12.4 versions. Wiz detects CVE-2021-44832.
The vulnerability severity is 6.6 as the exploit applies only if the attacker can modify the log4j configuration file.
Therefore, Wiz recommends focusing on patching workloads vulnerable to CVE-2021-44228 (the original log4shell) first , as it's easier to exploit and heavily exploited in the wild.
Ever since Log4Shell came into our lives, the internet has been flooded with daily Log4Shell CVEs updates, Log4j releases, as well as outdated recommendations and discredited mitigations. With all
Fortinet
Critical Apache Log4j Vulnerability Updates | FortiGuard Labs
blogs_fortinet·2021-12-21·CVSS 10.0
CVE-2021-44228 [CRITICAL] Critical Apache Log4j Vulnerability Updates | FortiGuard Labs
FORTIGUARD LABS THREAT RESEARCH
Critical Apache Log4j Vulnerability Updates
By Shunichi Imano, James Slaughter, and Geri Revay | December 21, 2021
Beginning December 9th, most of the internet-connected world was forced to reckon with a critical new vulnerability discovered in the Apache Log4j framework deployed in countless servers. Officially labeled CVE-2021-44228, but colloquially known as “Log4Shell”, this vulnerability is both trivial to exploit and allows for full remote code execution on a target system. This has earned the vulnerability a CVSS score of 10 – the maximum.
On December 14th, the Apache Software Foundation revealed a second Log4j vulnerability (CVE-2021-45046). It was initially identified as a Denial-of-Service (DoS) vulnerability with a CVSS score of 3.7 and modera
Wiz
Log4Shell: Wrap all your Log4j fixes before the holidays | Wiz Blog
blogs_wiz·2021-12-21·CVSS 10.0
CVE-2021-44832 [CRITICAL] Log4Shell: Wrap all your Log4j fixes before the holidays | Wiz Blog
December 28, 2021 update - CVE-2021-44832, a new Log4j vulnerability
On December 28, 2021, Apache released new log4j version 2.17.1 to address CVE-2021-44832, a new remote code execution vulnerability affecting log4j 2.0-alpha7 - 2.17.0 excluding 2.3.2 and 2.12.4 versions. Wiz detects CVE-2021-44832.
The vulnerability severity is 6.6 as the exploit applies only if the attacker can modify the log4j configuration file.
Therefore, Wiz recommends focusing on patching workloads vulnerable to CVE-2021-44228 (the original log4shell) first, as it's easier to exploit and heavily exploited in the wild.
Ever since Log4Shell came into our lives, the internet has been flooded with daily Log4Shell CVEs updates, Log4j releases, as well as outdated recommendations and discredited mitigations. With all t
Qualys
New Options Profiles for Log4Shell Detection | Qualys
blogs_qualys·2021-12-20
New Options Profiles for Log4Shell Detection | Qualys
#### Table of Contents
- Importing Option Profiles
- Search Lists
We have now added two new option profiles to our library for Log4Shell vulnerabilities. Option profiles define the settings you want to use for your scan. These new option profiles are tuned to quickly detect the Log4Shell vulnerability on assets in your environment.
The following two pre-configured option profiles are now available in the library to help you get started:
1. Log4Shell – Authenticated Scan
2. Log4Shell – Unauthenticated Scan
You can import these profiles into your account and use them as-is or edit them as needed.
## Importing Option Profiles
To import our option profiles, go to Scans > Option Profiles > New and select Import from Library.
Choose from the Log4Shell – Authenticated Scan or Log4Shell –
Qualys
New Options Profiles for Log4Shell Detection
blogs_qualys·2021-12-20
New Options Profiles for Log4Shell Detection
## Table of Contents
Importing Option Profiles
Search Lists
We have now added two new option profiles to our library for Log4Shell vulnerabilities. Option profiles define the settings you want to use for your scan. These new option profiles are tuned to quickly detect the Log4Shell vulnerability on assets in your environment.
The following two pre-configured option profiles are now available in the library to help you get started:
Log4Shell – Authenticated Scan
Log4Shell – Unauthenticated Scan
You can import these profiles into your account and use them as-is or edit them as needed.
## Importing Option Profiles
To import our option profiles, go to Scans > Option Profiles > New and select Import from Library .
Choose from the Log4Shell – Authenticated Scan or Log4Shell – Unauthent
Tenable
CVE-2021-44228, CVE-2021-45046, CVE-2021-4104: Frequently Asked Questions About Log4Shell and Associated Vulnerabilities
blogs_tenable·2021-12-17·CVSS 7.5
[HIGH] CVE-2021-44228, CVE-2021-45046, CVE-2021-4104: Frequently Asked Questions About Log4Shell and Associated Vulnerabilities
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Management (CSPM)
Compliance
Cyber insurance
Data Security Posture Management (DSPM)
Google Cloud security
Infrastructure as Code (IaC) security
Kubernetes Security Pos
Qualys
Log4Shell Log4j Vulnerability Test | CVE-2021-45046 Detection | Qualys
blogs_qualys·2021-12-15·CVSS 10.0
CVE-2021-44228 [CRITICAL] Log4Shell Log4j Vulnerability Test | CVE-2021-45046 Detection | Qualys
#### Table of Contents
- About CVE-2021-44228
- Detecting the Vulnerability with Qualys WAS
- WAS Log4Shell Detection Methodology with Qualys Periscope
- Scan Configurations :
- About CVE-2021-45046
- About CVE-2021-44832
- Solution
- Credits
- References:
- Contributors
On December 09, 2021, a critical remote code execution vulnerability was identified in Apache Log4j2 after proof-of-concepts were leaked publicly, affecting Apache Log4j 2.x <= 2.15.0-rc1. The vulnerability is being tracked as CVE-2021-44228 with CVSSv3 10 score and affects numerous applications which are using the Log4j2 library.
#### Free Trial
### Quickly Identify Your Vulnerable Web Applications Using Our Cloud Platform
Get the Free Trial
Successful exploitation of this vulnerability could allow a remote attacker
Qualys
Is Your Web Application Exploitable By Log4Shell Vulnerability?
blogs_qualys·2021-12-15·CVSS 10.0
CVE-2021-44228 [CRITICAL] Is Your Web Application Exploitable By Log4Shell Vulnerability?
## Table of Contents
About CVE-2021-44228
Detecting the Vulnerability with Qualys WAS
WAS Log4Shell Detection Methodology with Qualys Periscope
Scan Configurations :
About CVE-2021-45046
About CVE-2021-44832
Solution
Credits
References:
Contributors
On December 09, 2021, a critical remote code execution vulnerability was identified in Apache Log4j2 after proof-of-concepts were leaked publicly, affecting Apache Log4j 2.x <= 2.15.0-rc1. The vulnerability is being tracked as CVE-2021-44228 with CVSSv3 10 score and affects numerous applications which are using the Log4j2 library.
## Free Trial
## Quickly Identify Your Vulnerable Web Applications Using Our Cloud Platform
Successful exploitation of this vulnerability could allow a remote attacker to download and execute arbitrary c
Tenable
Log4Shell: 5 Steps The OT Community Should Take Right Now
blogs_tenable·2021-12-14
Log4Shell: 5 Steps The OT Community Should Take Right Now
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Management (CSPM)
Compliance
Cyber insurance
Data Security Posture Management (DSPM)
Google Cloud security
Infrastructure as Code (IaC) security
Kubernetes Security Pos
Tenable
Apache Log4j Flaw: A Fukushima Moment for the Cybersecurity Industry
blogs_tenable·2021-12-13
Apache Log4j Flaw: A Fukushima Moment for the Cybersecurity Industry
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Apache Log4j Flaw Puts Third-Party Software in the Spotlight
blogs_tenable·2021-12-12
Apache Log4j Flaw Puts Third-Party Software in the Spotlight
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Management (CSPM)
Compliance
Cyber insurance
Data Security Posture Management (DSPM)
Google Cloud security
Infrastructure as Code (IaC) security
Kubernetes Security Pos
Talos
Threat Advisory: Critical Apache Log4j vulnerability being exploited in the wild
blogs_talos·2021-12-10·CVSS 10.0
[CRITICAL] Threat Advisory: Critical Apache Log4j vulnerability being exploited in the wild
## Update History
DateDescription of UpdatesDec. 20, 2021
Additional coverage and IOCs; additional detection capabilities for customers via Cisco Global Threat Alerts.
Dec. 18, 2021
Additional mitigation guidance; updated coverage information.
Dec. 17, 2021
Added additional vulnerability and mitigation information; added section on guidance for developers; timeline.
Dec. 16, 2021
Added additional vulnerability and mitigation information; added event timeline; relevant advisory information.
Dec. 15, 2021
Added observations on exploitation activity; updated coverage information. Additional IOCs.
Dec. 14, 2021
Added new CVE details; updated coverage information; additional mitigation guidance; additional threat vectors; Additional IOCs.
Dec. 13, 2021
Added additional vulnerability informatio
Tenable
CVE-2021-44228: Proof-of-Concept for Critical Apache Log4j Remote Code Execution Vulnerability Available (Log4Shell)
blogs_tenable·2021-12-10·CVSS 10.0
[CRITICAL] CVE-2021-44228: Proof-of-Concept for Critical Apache Log4j Remote Code Execution Vulnerability Available (Log4Shell)
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Management (CSPM)
Compliance
Cyber insurance
Data Security Posture Management (DSPM)
Google Cloud security
Infrastructure as Code (IaC) security
Kubernetes Security Pos
Talos
Threat Advisory: Critical Apache Log4j vulnerability being exploited in the wild
blogs_talos·2021-12-10·CVSS 10.0
[CRITICAL] Threat Advisory: Critical Apache Log4j vulnerability being exploited in the wild
## Threat Advisory: Critical Apache Log4j vulnerability being exploited in the wild
## Update History
Dec. 20, 2021
Additional coverage and IOCs; additional detection capabilities for customers via Cisco Global Threat Alerts.
Dec. 18, 2021
Additional mitigation guidance; updated coverage information.
Dec. 17, 2021
Added additional vulnerability and mitigation information; added section on guidance for developers; timeline.
Dec. 16, 2021
Added additional vulnerability and mitigation information; added event timeline; relevant advisory information.
Dec. 15, 2021
Added observations on exploitation activity; updated coverage information. Additional IOCs.
Dec. 14, 2021
Added new CVE details; updated coverage information; additional mitigation guidance; additional threat vectors; Ad
Qualys
CVE-2021-44228: Log4Shell Apache Log4j2 Zero-Day Flaw | Qualys
blogs_qualys·2021-12-10·CVSS 10.0
[CRITICAL] CVE-2021-44228: Log4Shell Apache Log4j2 Zero-Day Flaw | Qualys
#### Table of Contents
- Apache Log4j2/ Log4Shell Vulnerability Updates and Timeline
- Qualys Released QIDs for Log4Shell Detection
- Detecting Apache Log4j2/ Log4Shell and Mitigation Status
- Discover Log4j Vulnerabilities with Qualys CSAM
- Detect Log4j Vulnerabilities Across Your Environment with Qualys VMDR
- Prioritize Log4j Remediation with Real Time Indicators
- Identify Log4j Impact with Threat Protection
- Patch and Fix Log4j Using Qualys Management
- Monitor Log4j Status on VMDR Dashboard
- Free 30-Day VMDR Service
- Web Application Scanning for Log4j Using Qualys WAS
- Qualys EDR Detects Log4j Exploits and Malware
- Detect Exploitation Attempts with Qualys XDR (beta)
- Update February 10, 2022 3:00 PM ET
- Update February 16, 2022 3:00 PM ET
- Webinar: Qualys Response to the Lo
Crowdstrike
December 2021 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] December 2021 Patch Tuesday: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Crowdstrike
Java Logging Guide: The Basics
blogs_crowdstrike
Java Logging Guide: The Basics
Upcoming events
Conference
CrowdTour
Find a city near you
Summit
Day Zero 2026
Las Vegas, NV
Login
Your Cart
Added to Cart
There's nothing in your cart
per endpoint / per year
per endpoint / per month
Login
Experienced a breach?
Blog
Contact us
Careers
Latest Innovations
Logging helps you understand how an application performs or what went wrong when something fails. This information can be critical for debugging and auditing purposes. Logs maintain a trail of every event during a program’s execution, making those records available for later analysis.
However, effective logging does not happen automatically. Application developers need to ensure an application is systematically logging important details in an easy-to-process format.
The most rudimentary approach to log
arXiv
The Road of Adaptive AI for Precision in Cybersecurity
arxiv_fulltext·2025-12-05
The Road of Adaptive AI for Precision in Cybersecurity
## Abstract
Cybersecurity's evolving complexity presents unique challenges and opportunities for AI research and practice. This paper shares key lessons and insights from designing, building, and operating production-grade GenAI pipelines in cybersecurity, with a focus on the continual adaptation required to keep pace with ever-shifting knowledge bases, tooling, and threats.
Our goal is to provide an actionable perspective for AI practitioners and industry stakeholders navigating the frontier of GenAI for cybersecurity, with particular attention to how different adaptation mechanisms complement each other in end-to-end systems.
We present practical guidance derived from real-world deployments, propose best practices for leveraging retrieval- and model-level adaptation, and highlight ope
arXiv
Today's Cat Is Tomorrow's Dog: Accounting for Time-Based Changes in the Labels of ML Vulnerability Detection Approaches
arxiv_fulltext·2025-06-13
Today's Cat Is Tomorrow's Dog: Accounting for Time-Based Changes in the Labels of ML Vulnerability Detection Approaches
project[1]
wrapfigurel[0pt]1in
-5pt
[width=1in,clip,keepaspectratio]#1
-25pt
wrapfigure
bio[1]
wrapfigurel[0pt]0.5in
[width=0.5in,clip,keepaspectratio]#1
-25pt
wrapfigure
bio2[1]
wrapfigurel[0pt]0.5in
-15pt
[width=0.5in,clip,keepaspectratio]#1
-25pt
wrapfigure
bio3[1]
wrapfigurel[0pt]0.5in
-10pt
[width=0.5in,clip,keepaspectratio]#1
-25pt
wrapfigure
2
2
center
Today’s Cat Is Tomorrow’s Dog: Accounting for Time-Based Changes in the Labels of ML Vulnerability Detection Approaches
center
Authors:
- : Ranindya Paramitha, University of Trento (Italy)
- : Yuan Feng, University of Trento (Italy)
- : Fabio Massacci, University of Trento (Italy), Vrije Universiteit Amsterdam (The Netherlands)
This work was partly funded by the EU under the H2020 Program AssureMOSS (Grant n. 952647) an
arXiv
Attack Techniques and Threat Identification for Vulnerabilities
arxiv_fulltext·2022-06-22
Attack Techniques and Threat Identification for Vulnerabilities
Attack Techniques and Threat Identification for Vulnerabilities
Constantin Adam
Muhammed Fatih Bulut
Daby Sow
cmadam, mfbulut, [email protected]
IBM T.J. Watson Research Center
Yorktown Heights
NY
USA
Steven Ocepek
Chris Bedell
steve.ocepek, [email protected]
IBM Security X-Force Red
USA
Lilian Ngweta
[email protected]
Rensselaer Polytechnic Institute
Troy
NY
USA
Adam and Bulut, et al.
## Abstract
Modern organizations struggle with what is often considered an insurmountable number of vulnerabilities that are discovered and reported by their network and application vulnerability scanners. Therefore, prioritization and focus become critical, to spend their limited time on the highest risk vulnerabilities. In doing this, it is important for these organizations not only to
Bugzilla
CVE-2022-23302 log4j: Remote code execution in Log4j 1.x when application is configured to use JMSSink
bugzilla·2022-01-18·CVSS 7.5
CVE-2022-23302 [HIGH] CVE-2022-23302 log4j: Remote code execution in Log4j 1.x when application is configured to use JMSSink
CVE-2022-23302 log4j: Remote code execution in Log4j 1.x when application is configured to use JMSSink
JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a TopicConnectionFactoryBindingName configuration causing JMSSink to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-4104.
Note this issue only affects Log4j 1.x when specifically configured to use JMSSink, which is not the default.
References:
https://www.openwall.com/lists/oss-security/2022/01/18/3
Discussion:
Marking /services "notaffected" per previous analysis/remediation.
---
This i
http://www.openwall.com/lists/oss-security/2022/01/18/3https://access.redhat.com/security/cve/CVE-2021-4104https://github.com/apache/logging-log4j2/pull/608#issuecomment-990494126https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0033https://security.gentoo.org/glsa/202209-02https://security.gentoo.org/glsa/202310-16https://security.gentoo.org/glsa/202312-02https://security.gentoo.org/glsa/202312-04https://security.netapp.com/advisory/ntap-20211223-0007/https://www.cve.org/CVERecord?id=CVE-2021-44228https://www.kb.cert.org/vuls/id/930724https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttp://www.openwall.com/lists/oss-security/2022/01/18/3https://access.redhat.com/security/cve/CVE-2021-4104https://github.com/apache/logging-log4j2/pull/608#issuecomment-990494126https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0033https://security.gentoo.org/glsa/202209-02https://security.gentoo.org/glsa/202310-16https://security.gentoo.org/glsa/202312-02https://security.gentoo.org/glsa/202312-04https://security.netapp.com/advisory/ntap-20211223-0007/https://www.cve.org/CVERecord?id=CVE-2021-44228https://www.kb.cert.org/vuls/id/930724https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.html
2021-12-14
Published
Exploited in the wild