Severity
7.5HIGH
EPSS
69.3%
top 1.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 14
Latest updateJan 15

Description

JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-44228. Note this issue only affects Log4j 1.2 when specifically configured to use JMSAppender, which is not the default. Apache Log4j 1.2 reached end o

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.6 | Impact: 5.9

Affected Packages39 packages

CVEListV5apache_software_foundation/apache_log4j_1.x1.0.1unspecified+2
Debianapache-log4j1.2< 1.2.17-10+deb11u1+3
NVDapache/log4j1.2
Mavenlog4j:log4j1.2.01.2.17

Also affects: Fedora 35, Enterprise Linux 6.0, 7.0, 8.0, Openshift Container Platform 4.6, 4.7, 4.8

🔴Vulnerability Details

6
GHSA
Deserialization of Untrusted Data in Log4j 1.x2022-01-21
OSV
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data2021-12-14
CVEList
Deserialization of untrusted data in JMSAppender in Apache Log4j 1.22021-12-14
GHSA
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data2021-12-14
OSV
CVE-2021-4104: JMSAppender in Log4j 12021-12-14

💥Exploits & PoCs

1
Nuclei
Flexnet - Remote Code Execution (Apache Log4j)

📋Vendor Advisories

11
Oracle
Oracle Oracle Communications Applications Risk Matrix: Security (Apache Log4j) — CVE-2021-41042024-01-15
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Web Console Design (Apache Log4j) — CVE-2021-41042023-07-15
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: Application Service Level Management (Apache Log4j) — CVE-2021-41042022-10-15
Ubuntu
Apache Log4j 1.2 vulnerability2022-02-08
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Centralized Thirdparty Jars (Apache Log4j) — CVE-2021-41042022-01-15

🕵️Threat Intelligence

2
Sentinelone
Log4j One Month On | Crimeware and Exploitation Roundup2022-01-10
Sentinelone
Log4j One Month On | Crimeware and Exploitation Roundup2022-01-10
CVE-2021-4104 (HIGH CVSS 7.5) | JMSAppender in Log4j 1.2 is vulnera | cvebase.io