CVE-2021-44832
published 2021-12-28CVE-2021-44832: Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when…
PriorityP183medium6.6CVSS 3.1
AVNACHPRHUINSUCHIHAH
ITWVulnCheck KEVRansomware
Exploited in the wild
EPSS
97.91%
99.9th percentile
Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.
Affected
76 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | log4j | — | — |
| apache | log4j | >= 2.0.1 < 2.3.2 | 2.3.2 |
| apache | log4j | >= 2.13.0 < 2.17.1 | 2.17.1 |
| apache | log4j | >= 2.4 < 2.12.4 | 2.12.4 |
| apache | logging | — | — |
| apache | tika | — | — |
| apache_software_foundation | apache_log4j2 | >= log4j-core < 2.17.1 | 2.17.1 |
| cisco | cloudcenter | — | — |
| debian | apache-log4j2 | < apache-log4j2 2.17.1-1 (bookworm) | apache-log4j2 2.17.1-1 (bookworm) |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| oracle | communications_brm_elastic_charging_engine | < 12.0.0.4.6 | 12.0.0.4.6 |
| oracle | communications_brm_elastic_charging_engine | — | — |
| oracle | communications_diameter_signaling_router | 8.0.0.0 – 8.5.1.0 | — |
| oracle | communications_diameter_signaling_router | 8.3.0.0 – 8.5.1.0 | — |
| oracle | communications_interactive_session_recorder | — | — |
| oracle | communications_interactive_session_recorder | — | — |
| oracle | communications_offline_mediation_controller | < 12.0.0.4.4 | 12.0.0.4.4 |
| oracle | communications_offline_mediation_controller | — | — |
| oracle | flexcube_private_banking | — | — |
| oracle | health_sciences_data_management_workbench | — | — |
| oracle | health_sciences_data_management_workbench | — | — |
| oracle | health_sciences_data_management_workbench | — | — |
| oracle | policy_automation | 12.2.0 – 12.2.24 | — |
Detection & IOCsextracted from sources · hover to see the quote
snort↗
SIDs: 58722-58744, 58751, 58784-58790, 58795, 58801, 58811-58814
yara↗
Java.Malware.CVE_2021_44228-9915816-1
yara↗
PUA.Java.Tool.CVE_2021_44228-9916978-0
- →CVE-2021-44832 requires attacker control of the Log4j configuration to use a JDBC Appender with a JNDI LDAP data source URI pointing to an attacker-controlled LDAP server; detection is consistent with Log4Shell (CVE-2021-44228) coverage and previously released signatures apply. ↗
- →Monitor HTTP request headers (X-Api-Version, User-Agent, Referer, X-Druid-Comment, Origin, Location, X-Forwarded-For, Cookie, X-Requested-With, X-Forwarded-Host, Accept, Authentication, Authorization) and POST body fields for JNDI lookup strings starting with ${jndi:protocol://. ↗
- →Detect outbound LDAP/JNDI lookup requests originating from application servers, especially those containing ${jndi: patterns in log data, as indicators of active exploitation attempts. ↗
- →In the AvosLocker campaign exploiting Log4Shell/CVE-2021-44832 on VMware Horizon UAGs, attackers used encoded PowerShell with DownloadString to fetch second-stage payloads; hunt for wmiprvse.exe spawning PowerShell with -enc or -EncodedCommand flags. ↗
- →Hunt for the Sliver C2 payload dropped as 'vmware_kb.exe' and Cobalt Strike beacons distributed via PDQ Deploy in post-exploitation of Log4j-vulnerable VMware Horizon systems. ↗
- ·CVE-2021-44832 is only exploitable when an attacker already has control over the Log4j configuration (e.g., via a JDBC Appender with an attacker-controlled JNDI LDAP data source URI); it is not exploitable in default or unmodified configurations. ↗
- ·The fix for CVE-2021-44832 limits JNDI data source names to the java protocol only; deployments still using Log4j 2.17.0 (without upgrading to 2.17.1, 2.12.4, or 2.3.2) remain vulnerable if an attacker can influence the configuration. ↗
CVSS provenance
nvdv3.16.6MEDIUMCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.08.5HIGHAV:N/AC:M/Au:S/C:C/I:C/A:C
ghsa10.0CRITICAL
osv10.0CRITICAL
vulncheck6.6MEDIUM
vendor_cisco10.0CRITICAL
vendor_apache6.6
vendor_debian6.6MEDIUM
vendor_oracle6.6MEDIUM
vendor_redhat6.6MEDIUM
vendor_ubuntu6.6MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Oracle Hospitality Reporting and Analytics 9.1.0 input validation (Nessus ID 276397)
vuldb·2026-06-01·CVSS 6.6
CVE-2021-44832 [MEDIUM] Oracle Hospitality Reporting and Analytics 9.1.0 input validation (Nessus ID 276397)
A vulnerability has been found in Oracle Hospitality Reporting and Analytics 9.1.0 and classified as critical. The affected element is an unknown function of the component Reporting. Performing a manipulation results in improper input validation.
This vulnerability is reported as CVE-2021-44832. The attack is possible to be carried out remotely. No exploit exists.
VulDB
Oracle Retail Invoice Matching 15.0.3/16.0.3 Security input validation (Nessus ID 276397)
vuldb·2026-06-01·CVSS 6.6
CVE-2021-44832 [MEDIUM] Oracle Retail Invoice Matching 15.0.3/16.0.3 Security input validation (Nessus ID 276397)
A vulnerability was found in Oracle Retail Invoice Matching 15.0.3/16.0.3. It has been classified as critical. This affects an unknown function of the component Security. Performing a manipulation results in improper input validation.
This vulnerability is reported as CVE-2021-44832. The attack is possible to be carried out remotely. No exploit exists.
VulDB
Oracle Demantra Demand Management up to 12.2.12 Security input validation (Nessus ID 276397)
vuldb·2026-06-01·CVSS 6.6
CVE-2021-44832 [MEDIUM] Oracle Demantra Demand Management up to 12.2.12 Security input validation (Nessus ID 276397)
A vulnerability, which was classified as critical, was found in Oracle Demantra Demand Management up to 12.2.12. Affected is an unknown function of the component Security. Such manipulation leads to improper input validation.
This vulnerability is uniquely identified as CVE-2021-44832. The attack can be launched remotely. No exploit exists.
VulDB
Oracle Retail Price Management 14.1.3.2/15.0.3.1/16.0.3 Security input validation (Nessus ID 276397)
vuldb·2026-06-01·CVSS 6.6
CVE-2021-44832 [MEDIUM] Oracle Retail Price Management 14.1.3.2/15.0.3.1/16.0.3 Security input validation (Nessus ID 276397)
A vulnerability was found in Oracle Retail Price Management 14.1.3.2/15.0.3.1/16.0.3. It has been declared as critical. This impacts an unknown function of the component Security. Executing a manipulation can lead to improper input validation.
This vulnerability appears as CVE-2021-44832. The attack may be performed from remote. There is no available exploit.
VulDB
Oracle Hospitality Labor Management 9.1.0 Reporting input validation (Nessus ID 276397)
vuldb·2026-06-01·CVSS 6.6
CVE-2021-44832 [MEDIUM] Oracle Hospitality Labor Management 9.1.0 Reporting input validation (Nessus ID 276397)
A vulnerability, which was classified as critical, was found in Oracle Hospitality Labor Management 9.1.0. Impacted is an unknown function of the component Reporting. Such manipulation leads to improper input validation.
This vulnerability is documented as CVE-2021-44832. The attack can be executed remotely. There is not any exploit available.
VulDB
Oracle Siebel Apps - Marketing up to 22.10 input validation (Nessus ID 276397)
vuldb·2026-06-01·CVSS 6.6
CVE-2021-44832 [MEDIUM] Oracle Siebel Apps - Marketing up to 22.10 input validation (Nessus ID 276397)
A vulnerability labeled as critical has been found in Oracle Siebel Apps - Marketing up to 22.10. This issue affects some unknown processing of the component Marketing. Such manipulation leads to improper input validation.
This vulnerability is documented as CVE-2021-44832. The attack can be executed remotely. There is not any exploit available.
VulDB
Oracle Communications ASAP 7.3 SRP input validation (Nessus ID 212487)
vuldb·2026-05-31·CVSS 6.6
CVE-2021-44832 [MEDIUM] Oracle Communications ASAP 7.3 SRP input validation (Nessus ID 212487)
A vulnerability labeled as critical has been found in Oracle Communications ASAP 7.3. Affected is an unknown function of the component SRP. Executing a manipulation can lead to improper input validation.
This vulnerability is handled as CVE-2021-44832. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.
VulDB
Oracle Retail Fiscal Management 14.2 NF Issuing input validation (Nessus ID 212487)
vuldb·2026-05-31·CVSS 6.6
CVE-2021-44832 [MEDIUM] Oracle Retail Fiscal Management 14.2 NF Issuing input validation (Nessus ID 212487)
A vulnerability was found in Oracle Retail Fiscal Management 14.2. It has been declared as critical. This issue affects some unknown processing of the component NF Issuing. Such manipulation leads to improper input validation.
This vulnerability is uniquely identified as CVE-2021-44832. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.
VulDB
Oracle Primavera Unifier 18.8/19.12/20.12/21.12 Logging input validation (Nessus ID 212487)
vuldb·2026-05-31·CVSS 6.6
CVE-2021-44832 [MEDIUM] Oracle Primavera Unifier 18.8/19.12/20.12/21.12 Logging input validation (Nessus ID 212487)
A vulnerability marked as critical has been reported in Oracle Primavera Unifier 18.8/19.12/20.12/21.12. This issue affects some unknown processing of the component Logging. Performing a manipulation results in improper input validation.
This vulnerability is reported as CVE-2021-44832. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.
VulDB
Oracle Communications Convergent Charging Controller 6.0.1.0.0/12.0.4.0.0 Network Gateway input validation (Nessus ID 212487)
vuldb·2026-05-31·CVSS 6.6
CVE-2021-44832 [MEDIUM] Oracle Communications Convergent Charging Controller 6.0.1.0.0/12.0.4.0.0 Network Gateway input validation (Nessus ID 212487)
A vulnerability classified as critical has been found in Oracle Communications Convergent Charging Controller 6.0.1.0.0/12.0.4.0.0. This affects an unknown part of the component Network Gateway. This manipulation causes improper input validation.
The identification of this vulnerability is CVE-2021-44832. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
VulDB
Oracle Retail Assortment Planning 16.0.3 Application Core input validation (Nessus ID 212487)
vuldb·2026-05-31·CVSS 6.6
CVE-2021-44832 [MEDIUM] Oracle Retail Assortment Planning 16.0.3 Application Core input validation (Nessus ID 212487)
A vulnerability was found in Oracle Retail Assortment Planning 16.0.3. It has been classified as critical. This vulnerability affects unknown code of the component Application Core. This manipulation causes improper input validation.
This vulnerability is handled as CVE-2021-44832. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.
VulDB
Oracle SQL Developer up to 21.4.1 Installation input validation (Nessus ID 212487)
vuldb·2026-05-31·CVSS 6.6
CVE-2021-44832 [MEDIUM] Oracle SQL Developer up to 21.4.1 Installation input validation (Nessus ID 212487)
A vulnerability marked as critical has been reported in Oracle SQL Developer up to 21.4.1. Impacted is an unknown function of the component Installation. This manipulation causes improper input validation.
The identification of this vulnerability is CVE-2021-44832. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.
VulDB
Oracle Communications Convergence 3.0.2.2/3.0.3.0 Configuration input validation (Nessus ID 212487)
vuldb·2026-05-31·CVSS 6.6
CVE-2021-44832 [MEDIUM] Oracle Communications Convergence 3.0.2.2/3.0.3.0 Configuration input validation (Nessus ID 212487)
A vulnerability described as critical has been identified in Oracle Communications Convergence 3.0.2.2/3.0.3.0. Affected by this issue is some unknown functionality of the component Configuration. The manipulation results in improper input validation.
This vulnerability was named CVE-2021-44832. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.
VulDB
Oracle WebLogic Server 12.2.1.3.0/12.2.1.4.0/14.1.1.0.0 Centralized Thirdparty Jars input validation (Nessus ID 212487)
vuldb·2026-05-31·CVSS 6.6
CVE-2021-44832 [MEDIUM] Oracle WebLogic Server 12.2.1.3.0/12.2.1.4.0/14.1.1.0.0 Centralized Thirdparty Jars input validation (Nessus ID 212487)
A vulnerability was found in Oracle WebLogic Server 12.2.1.3.0/12.2.1.4.0/14.1.1.0.0. It has been declared as critical. This impacts an unknown function of the component Centralized Thirdparty Jars. The manipulation results in improper input validation.
This vulnerability is known as CVE-2021-44832. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.
VulDB
Oracle Siebel UI Framework up to 21.11 Enterprise Cache input validation (Nessus ID 212487)
vuldb·2026-05-31·CVSS 6.6
CVE-2021-44832 [MEDIUM] Oracle Siebel UI Framework up to 21.11 Enterprise Cache input validation (Nessus ID 212487)
A vulnerability described as critical has been identified in Oracle Siebel UI Framework up to 21.11. This affects an unknown part of the component Enterprise Cache. Executing a manipulation can lead to improper input validation.
This vulnerability is tracked as CVE-2021-44832. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.
VulDB
Oracle Communications Messaging Server 8.1 ISC input validation (Nessus ID 212487)
vuldb·2026-05-31·CVSS 6.6
CVE-2021-44832 [MEDIUM] Oracle Communications Messaging Server 8.1 ISC input validation (Nessus ID 212487)
A vulnerability, which was classified as critical, has been found in Oracle Communications Messaging Server 8.1. This issue affects some unknown processing of the component ISC. Performing a manipulation results in improper input validation.
This vulnerability is identified as CVE-2021-44832. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
VulDB
Oracle Communications Billing and Revenue Management 12.0.0.4/12.0.0.5 Rated Event Manager input validation (Nessus ID 212487)
vuldb·2026-05-31·CVSS 6.6
CVE-2021-44832 [MEDIUM] Oracle Communications Billing and Revenue Management 12.0.0.4/12.0.0.5 Rated Event Manager input validation (Nessus ID 212487)
A vulnerability marked as critical has been reported in Oracle Communications Billing and Revenue Management 12.0.0.4/12.0.0.5. Affected by this vulnerability is an unknown functionality of the component Rated Event Manager/Business Operations Center/Kafka Data Manager. The manipulation leads to improper input validation.
This vulnerability is uniquely identified as CVE-2021-44832. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.
VulDB
Oracle Communications IP Service Activator 7.4.0 Logging input validation (Nessus ID 212487)
vuldb·2026-05-31·CVSS 6.6
CVE-2021-44832 [MEDIUM] Oracle Communications IP Service Activator 7.4.0 Logging input validation (Nessus ID 212487)
A vulnerability classified as critical was found in Oracle Communications IP Service Activator 7.4.0. This vulnerability affects unknown code of the component Logging. Such manipulation leads to improper input validation.
This vulnerability is referenced as CVE-2021-44832. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is advised.
VulDB
Apache Log4j up to 2.17.0 Logging Configuration File injection (LOG4J2-3293 / Nessus ID 212487)
vuldb·2026-05-30·CVSS 6.6
CVE-2021-44832 [MEDIUM] Apache Log4j up to 2.17.0 Logging Configuration File injection (LOG4J2-3293 / Nessus ID 212487)
A vulnerability, which was classified as critical, has been found in Apache Log4j up to 2.17.0. Affected by this issue is some unknown functionality of the component Logging Configuration File Handler. This manipulation causes injection.
This vulnerability is handled as CVE-2021-44832. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
VulDB
Oracle Communications Diameter Signaling Router up to 8.5.1.0 Virtual Network Function Manager/API Gateway input validation (Nessus ID 212487)
vuldb·2026-05-30·CVSS 6.6
CVE-2021-44832 [MEDIUM] Oracle Communications Diameter Signaling Router up to 8.5.1.0 Virtual Network Function Manager/API Gateway input validation (Nessus ID 212487)
A vulnerability identified as critical has been detected in Oracle Communications Diameter Signaling Router up to 8.5.1.0. Affected by this issue is some unknown functionality of the component Virtual Network Function Manager/API Gateway. The manipulation leads to improper input validation.
This vulnerability is traded as CVE-2021-44832. It is possible to initiate the attack remotely. There is no exploit available.
You should upgrade the affected component.
VulDB
Oracle Primavera Gateway up to 21.12.0 Admin input validation (Nessus ID 212487)
vuldb·2026-05-30·CVSS 6.6
CVE-2021-44832 [MEDIUM] Oracle Primavera Gateway up to 21.12.0 Admin input validation (Nessus ID 212487)
A vulnerability identified as critical has been detected in Oracle Primavera Gateway up to 17.12.11/18.8.13/19.12.12/20.12.7/21.12.0. This affects an unknown part of the component Admin. This manipulation causes improper input validation.
This vulnerability is registered as CVE-2021-44832. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.
VulDB
Oracle Communications Interactive Session Recorder 6.3/6.4 RSS input validation (Nessus ID 212487)
vuldb·2026-05-30·CVSS 6.6
CVE-2021-44832 [MEDIUM] Oracle Communications Interactive Session Recorder 6.3/6.4 RSS input validation (Nessus ID 212487)
A vulnerability labeled as critical has been found in Oracle Communications Interactive Session Recorder 6.3/6.4. This affects an unknown part of the component RSS. The manipulation results in improper input validation.
This vulnerability is known as CVE-2021-44832. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.
VulDB
Oracle Primavera P6 Enterprise Project Portfolio Management Web Access input validation (Nessus ID 212487)
vuldb·2026-05-30·CVSS 6.6
CVE-2021-44832 [MEDIUM] Oracle Primavera P6 Enterprise Project Portfolio Management Web Access input validation (Nessus ID 212487)
A vulnerability labeled as critical has been found in Oracle Primavera P6 Enterprise Project Portfolio Management up to 19.12.18.0/20.12.0.0-20.12.12.0/21.12.0.0. This vulnerability affects unknown code of the component Web Access. Such manipulation leads to improper input validation.
This vulnerability is documented as CVE-2021-44832. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.
GHSA
Security Advisory for "Log4Shell"
ghsa·2022-01-21·CVSS 10.0
CVE-2021-44228 [CRITICAL] CWE-20 Security Advisory for "Log4Shell"
Security Advisory for "Log4Shell"
### Impact
A highly critical 0-day exploit (CVE-2021-44228) is found in Apache log4j 2 library on December 9, 2021.
This affects Apache log4j versions from 2.0-beta9 to 2.14.1 (inclusive).
This vulnerability allows a remote attacker to execute code on the server if the system logs an attacker-controlled string value with the attacker's JNDI LDAP server lookup.
Another vulnerability related to the same library, which was discovered on 12/14/2021 (CVE-2021-45046) and revealed another Remote Code Execution vulnerability, has been investigated by Hazelcast team as well and it is found that it does not affect Hazelcast Products under default configurations.
The finding of CVE-2021-45105 on 12/14/2021, which can cause a Denial of Service attack, was investi
OSV
Security Advisory for "Log4Shell"
osv·2022-01-21·CVSS 10.0
CVE-2021-44228 [CRITICAL] Security Advisory for "Log4Shell"
Security Advisory for "Log4Shell"
### Impact
A highly critical 0-day exploit (CVE-2021-44228) is found in Apache log4j 2 library on December 9, 2021.
This affects Apache log4j versions from 2.0-beta9 to 2.14.1 (inclusive).
This vulnerability allows a remote attacker to execute code on the server if the system logs an attacker-controlled string value with the attacker's JNDI LDAP server lookup.
Another vulnerability related to the same library, which was discovered on 12/14/2021 (CVE-2021-45046) and revealed another Remote Code Execution vulnerability, has been investigated by Hazelcast team as well and it is found that it does not affect Hazelcast Products under default configurations.
The finding of CVE-2021-45105 on 12/14/2021, which can cause a Denial of Service attack, was investi
OSV
apache-log4j2 vulnerabilities
osv·2022-01-11·CVSS 6.6
CVE-2021-44832 [MEDIUM] apache-log4j2 vulnerabilities
apache-log4j2 vulnerabilities
It was discovered that Apache Log4j 2 was vulnerable to remote code
execution (RCE) attack when configured to use a JDBC Appender with a
JNDI LDAP data source URI. A remote attacker could possibly use this issue to
cause a crash, leading to a denial of service. (CVE-2021-44832)
Hideki Okamoto and Guy Lederfein discovered that Apache Log4j 2 did not
protect against infinite recursion in lookup evaluation. A remote attacker
could possibly use this issue to cause Apache Log4j 2 to crash, leading to
a denial of service. This issue only affected Ubuntu 18.04 LTS.
(CVE-2021-45105)
OSV
Improper Input Validation and Injection in Apache Log4j2
osv·2022-01-04
CVE-2021-44832 [MEDIUM] Improper Input Validation and Injection in Apache Log4j2
Improper Input Validation and Injection in Apache Log4j2
Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to an attack where an attacker with permission to modify the logging configuration file can construct a malicious configuration using a JDBC Appender with a data source referencing a JNDI URI which can execute remote code. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.
# Affected packages
Only the `org.apache.logging.log4j:log4j-core` package is directly affected by this vulnerability. The `org.apache.logging.log4j:log4j-api` should be kept at the same version as the `org.apache.logging.log4j:log4j-core` package to ensure compatability if in use
GHSA
Improper Input Validation and Injection in Apache Log4j2
ghsa·2022-01-04
CVE-2021-44832 [MEDIUM] CWE-20 Improper Input Validation and Injection in Apache Log4j2
Improper Input Validation and Injection in Apache Log4j2
Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to an attack where an attacker with permission to modify the logging configuration file can construct a malicious configuration using a JDBC Appender with a data source referencing a JNDI URI which can execute remote code. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.
# Affected packages
Only the `org.apache.logging.log4j:log4j-core` package is directly affected by this vulnerability. The `org.apache.logging.log4j:log4j-api` should be kept at the same version as the `org.apache.logging.log4j:log4j-core` package to ensure compatability if in use
OSV
CVE-2021-44832: Apache Log4j2 versions 2
osv·2021-12-28·CVSS 6.6
CVE-2021-44832 [MEDIUM] CVE-2021-44832: Apache Log4j2 versions 2
Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.
VulnCheck
Apache log4j Improper Input Validation
vulncheck·2021·CVSS 6.6
CVE-2021-44832 [MEDIUM] Apache log4j Improper Input Validation
Apache log4j Improper Input Validation
Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.
Affected: Apache log4j
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Known Ransomware Campaign Use: Known
Exploitation References: https://info.securin.io/hubfs/Securin%20Ransomware%20Report%202023.pdf; https://www.securin.io/wp-content/up
Oracle
Oracle Oracle Retail Applications Risk Matrix: Security (Apache Log4j) — CVE-2021-44832
vendor_oracle·2023-04-15·CVSS 6.6
CVE-2021-44832 [MEDIUM] Oracle Oracle Retail Applications Risk Matrix: Security (Apache Log4j) — CVE-2021-44832
Oracle Oracle Retail Applications Risk Matrix: Security (Apache Log4j) vulnerability
CVE: CVE-2021-44832
CVSS: 6.6
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Oracle
Oracle Oracle Food and Beverage Applications Risk Matrix: Reporting (Apache Log4j) — CVE-2021-44832
vendor_oracle·2023-01-15·CVSS 6.6
CVE-2021-44832 [MEDIUM] Oracle Oracle Food and Beverage Applications Risk Matrix: Reporting (Apache Log4j) — CVE-2021-44832
Oracle Oracle Food and Beverage Applications Risk Matrix: Reporting (Apache Log4j) vulnerability
CVE: CVE-2021-44832
CVSS: 6.6
Protocol: HTTPS
Remote exploit: No
Affected versions: Network
Advisory: cpujan2023 (JAN 2023)
Oracle
Oracle Oracle Essbase Risk Matrix: Essbase Web Platform (Apache Log4j) — CVE-2021-44832
vendor_oracle·2022-10-15·CVSS 6.6
CVE-2021-44832 [MEDIUM] Oracle Oracle Essbase Risk Matrix: Essbase Web Platform (Apache Log4j) — CVE-2021-44832
Oracle Oracle Essbase Risk Matrix: Essbase Web Platform (Apache Log4j) vulnerability
CVE: CVE-2021-44832
CVSS: 6.6
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpuoct2022 (OCT 2022)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Charging Server (Apache Log4j) — CVE-2021-44832
vendor_oracle·2022-07-15·CVSS 6.6
CVE-2021-44832 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Charging Server (Apache Log4j) — CVE-2021-44832
Oracle Oracle Communications Applications Risk Matrix: Charging Server (Apache Log4j) vulnerability
CVE: CVE-2021-44832
CVSS: 6.6
Protocol: TCP
Remote exploit: No
Affected versions: Network
Advisory: cpujul2022 (JUL 2022)
Oracle
Oracle Oracle SQL Developer Risk Matrix: Installation (Apache Log4j) — CVE-2021-44832
vendor_oracle·2022-04-15·CVSS 6.6
CVE-2021-44832 [MEDIUM] Oracle Oracle SQL Developer Risk Matrix: Installation (Apache Log4j) — CVE-2021-44832
Oracle Oracle SQL Developer Risk Matrix: Installation (Apache Log4j) vulnerability
CVE: CVE-2021-44832
CVSS: 6.6
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
Oracle
Oracle Oracle Communications Risk Matrix: Virtual Network Function Manager, API Gateway (Apache Log4j) — CVE-2021-44832
vendor_oracle·2022-01-15·CVSS 6.6
CVE-2021-44832 [MEDIUM] Oracle Oracle Communications Risk Matrix: Virtual Network Function Manager, API Gateway (Apache Log4j) — CVE-2021-44832
Oracle Oracle Communications Risk Matrix: Virtual Network Function Manager, API Gateway (Apache Log4j) vulnerability
CVE: CVE-2021-44832
CVSS: 6.6
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujan2022 (JAN 2022)
Ubuntu
Apache Log4j 2 vulnerabilities
vendor_ubuntu·2022-01-11·CVSS 6.6
CVE-2021-44832 [MEDIUM] Apache Log4j 2 vulnerabilities
Title: Apache Log4j 2 vulnerabilities
Summary: Several security issues were fixed in Apache Log4j 2.
It was discovered that Apache Log4j 2 was vulnerable to remote code
execution (RCE) attack when configured to use a JDBC Appender with a
JNDI LDAP data source URI. A remote attacker could possibly use this issue to
cause a crash, leading to a denial of service. (CVE-2021-44832)
Hideki Okamoto and Guy Lederfein discovered that Apache Log4j 2 did not
protect against infinite recursion in lookup evaluation. A remote attacker
could possibly use this issue to cause Apache Log4j 2 to crash, leading to
a denial of service. This issue only affected Ubuntu 18.04 LTS.
(CVE-2021-45105)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
log4j-core: remote code execution via JDBC Appender
vendor_redhat·2021-12-28·CVSS 6.6
CVE-2021-44832 [MEDIUM] CWE-20 log4j-core: remote code execution via JDBC Appender
log4j-core: remote code execution via JDBC Appender
Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.
Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack where an attacker with permission to modify the logging configuration file can construct a malicious configuration using a JDBC Appender with a data source referencing a JNDI URI which
VMware
VMware Response to Apache Log4j Remote Code Execution Vulnerabilities (CVE-2021-44228, CVE-2021-45046)
vendor_vmware·2021-12-10·CVSS 10.0
CVE-2021-44228 [CRITICAL] VMware Response to Apache Log4j Remote Code Execution Vulnerabilities (CVE-2021-44228, CVE-2021-45046)
VMSA-2021-0028: VMware Response to Apache Log4j Remote Code Execution Vulnerabilities (CVE-2021-44228, CVE-2021-45046)
Description Multiple products impacted by remote code execution vulnerabilities via Apache Log4j (CVE-2021-44228, CVE-2021-45046).
CVEs: CVE-2021-44228, CVE-2021-44832, CVE-2021-45046, CVE-2021-45105
Affected products: ESXi, NSX Data Center, NSX-T, VMware Aria, VMware Carbon Black, VMware Cloud Foundation, VMware HCX, VMware Horizon, VMware Identity Manager, VMware NSX, VMware SD-WAN, VMware Tanzu, VMware VeloCloud, VMware Workspace ONE, VMware vCenter Server, VMware vRealize, VMware vSphere
Cisco
Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
vendor_cisco·2021-12-10·CVSS 10.0
CVE-2021-44228 [CRITICAL] CWE-20 Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
Critical Vulnerabilities in Apache Log4j Java Logging Library
On December 9, 2021, the following critical vulnerability in the Apache Log4j Java logging library affecting all Log4j2 versions earlier than 2.15.0 was disclosed:
CVE-2021-44228: Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
On December 14, 2021, the following critical vulnerability, which affects certain Apache Log4j use cases in versions 2.15.0 and earlier, was disclosed:
CVE-2021-45046: Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
On December 18, 2021, a vulnerability in the Apache Log4j component affecting vers
Palo Alto
Impact of Log4j Vulnerabilities CVE-2021-44228, CVE-2021-45046, CVE-2021-45105, and CVE-2021-44832
vendor_paloalto·2021-12-10·CVSS 10.0
CVE-2021-44228 [CRITICAL] CWE-94 Impact of Log4j Vulnerabilities CVE-2021-44228, CVE-2021-45046, CVE-2021-45105, and CVE-2021-44832
Impact of Log4j Vulnerabilities CVE-2021-44228, CVE-2021-45046, CVE-2021-45105, and CVE-2021-44832
Apache Log4j Java library is vulnerable to a remote code execution vulnerability CVE-2021-44228, known as Log4Shell, and related vulnerabilities CVE-2021-45046, CVE-2021-45105, and CVE-2021-44832. Log4Shell allows remote unauthenticated attackers with the ability to inject text into log messages to execute arbitrary code loaded from malicious servers with the privileges of the process utilizing Log4j.
These products and services are not affected by Log4Shell: Bridgecrew, Cortex Data Lake, Cortex XDR agents, Cortex XSOAR, Cortex Xpanse, Enterprise Data Loss Prevention (DLP), Expedition, the GlobalProtect app, IoT Security, Okyo Garde, PAN-DB Private Cloud, PAN-OS software running on firewall
Debian
CVE-2021-44832: apache-log4j2 - Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases...
vendor_debian·2021·CVSS 6.6
CVE-2021-44832 [MEDIUM] CVE-2021-44832: apache-log4j2 - Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases...
Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.
Scope: local
bookworm: resolved (fixed in 2.17.1-1)
bullseye: resolved (fixed in 2.17.1-1~deb11u1)
forky: resolved (fixed in 2.17.1-1)
sid: resolved (fixed in 2.17.1-1)
trixie: resolved (fixed in 2.17.1-1)
Apache
Apache logging: CVE-2021-44832
vendor_apache·CVSS 6.6
CVE-2021-44832 Apache logging: CVE-2021-44832
Apache logging: CVE-2021-44832
Summary JDBC appender is vulnerable to remote code execution in certain configurations CVSS 3.x Score & Vector 6.6 MEDIUM (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H) Components affected log4j-core Versions affected [2.0-beta7, 2.3.1) ∪ [2.4, 2.12.3) ∪ [2.13.0, 2.17.0) Versions fixed 2.3.1 (for Java 6), 2.12.3 (for Java 7), or 2.17.0 (for Java 8 and later)
Severity: moderate
Affected versions: 2.3.1
Cisco
Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
vendor_cisco·CVSS 3.1
CVE-2021-45105 Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
CVE-2021-45105: Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
Critical Vulnerabilities in Apache Log4j Java Logging Library On December 9, 2021, the following critical vulnerability in the Apache Log4j Java logging library affecting all Log4j2 versions earlier than 2.15.0 was disclosed: CVE-2021-44228: Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints On December 14, 2021, the following critical vulnerability, which affects certain Apache Log4j use cases in versions 2.15.0 and earlier, was disclosed: CVE-2021-45046: Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack On December 18, 2021, a vulnerability in the Apache Log4j component affe
Cisco
Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
vendor_cisco·CVSS 3.1
CVE-2021-44228 Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
CVE-2021-44228: Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
Critical Vulnerabilities in Apache Log4j Java Logging Library On December 9, 2021, the following critical vulnerability in the Apache Log4j Java logging library affecting all Log4j2 versions earlier than 2.15.0 was disclosed: CVE-2021-44228: Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints On December 14, 2021, the following critical vulnerability, which affects certain Apache Log4j use cases in versions 2.15.0 and earlier, was disclosed: CVE-2021-45046: Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack On December 18, 2021, a vulnerability in the Apache Log4j component affe
Cisco
Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
vendor_cisco·CVSS 3.1
CVE-2021-44832 Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
CVE-2021-44832: Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
Critical Vulnerabilities in Apache Log4j Java Logging Library On December 9, 2021, the following critical vulnerability in the Apache Log4j Java logging library affecting all Log4j2 versions earlier than 2.15.0 was disclosed: CVE-2021-44228: Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints On December 14, 2021, the following critical vulnerability, which affects certain Apache Log4j use cases in versions 2.15.0 and earlier, was disclosed: CVE-2021-45046: Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack On December 18, 2021, a vulnerability in the Apache Log4j component affe
Apache
Apache tika: CVE-2021-44832
vendor_apache
CVE-2021-44832 Apache tika: CVE-2021-44832
Apache tika: CVE-2021-44832
Remote Code Execution via JDBC Appender in log4j2 ??? 2.0.0-BETA-2.2.1
Cisco
Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
vendor_cisco·CVSS 3.1
CVE-2021-45046 Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
CVE-2021-45046: Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
Critical Vulnerabilities in Apache Log4j Java Logging Library On December 9, 2021, the following critical vulnerability in the Apache Log4j Java logging library affecting all Log4j2 versions earlier than 2.15.0 was disclosed: CVE-2021-44228: Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints On December 14, 2021, the following critical vulnerability, which affects certain Apache Log4j use cases in versions 2.15.0 and earlier, was disclosed: CVE-2021-45046: Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack On December 18, 2021, a vulnerability in the Apache Log4j component affe
No detection rules found.
No public exploits indexed.
Bleepingcomputer
Over 30% of Log4J apps use a vulnerable version of the library
blogs_bleepingcomputer·2023-12-10·CVSS 10.0
CVE-2021-44228 [CRITICAL] Over 30% of Log4J apps use a vulnerable version of the library
## Over 30% of Log4J apps use a vulnerable version of the library
## Bill Toulas
Roughly 38% of applications using the Apache Log4j library are using a version vulnerable to security issues, including Log4Shell, a critical vulnerability identified as CVE-2021-44228 that carries the maximum severity rating, despite patches being available for more than two years.
Log4Shell is an unauthenticated remote code execution (RCE) flaw that allows taking complete control over systems with Log4j 2.0-beta9 and up to 2.15.0.
The flaw was discovered as an actively exploited zero-day on December 10, 2021, and its widespread impact, ease of exploitation, and massive security implications acted as an open invitation to threat actors.
The circumstance prompted an extensive campaign to notify affected p
Tenable
Tenable Research Advisories: Urgent Action
blogs_tenable·2023-11-20
Tenable Research Advisories: Urgent Action
by Cesar Navas November 20, 2023
Tenable Research delivers world class exposure intelligence, data science insights, zero day research and security advisories. Our Security Response Team (SRT) in Tenable Research tracks threat and vulnerability intelligence feeds to make sure our research teams can deliver sensor coverage to our products as quickly as possible. The SRT also works to dig into technical details and author white papers, blogs, and additional communications to ensure stakeholders are fully informed of the latest cyber risks and threats. The SRT provides breakdowns for the latest critical vulnerabilities on the Tenable blog.
When security events rise to the level of taking immediate action, Tenable - leveraging SRT intelligence - notifies customers proactively to provide expo
Tenable
Oracle January 2023 Critical Patch Update Addresses 183 CVEs
blogs_tenable·2023-01-19
Oracle January 2023 Critical Patch Update Addresses 183 CVEs
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Securelist
IT threat evolution in Q3 2022. Non-mobile statistics
blogs_securelist·2022-11-18
IT threat evolution in Q3 2022. Non-mobile statistics
Table of Contents
Quarterly figures
Financial threats
Number of users attacked by banking malware
TOP 10 banking malware families
Geography of financial malware attacks
Ransomware programs
Quarterly trends and highlights
Number of new modifications
Number of users attacked by ransomware Trojans
Geography of attacked users
TOP 10 most common families of ransomware Trojans
Miners
Number of new miner modifications
Number of users attacked by miners
Geography of miner attacks
Vulnerable applications used by criminals during cyberattacks
Quarterly highlights
Vulnerability statistics
Attacks on macOS
TOP 20 threats for macOS
Geography of threats for macOS
IoT attacks
IoT threat statistics
Attacks via web resources
Countries and territories that serve as sources of web-ba
Securelist
PC malware statistics, Q3 2022
blogs_securelist·2022-11-18
PC malware statistics, Q3 2022
Table of Contents
- Quarterly figures
- Financial threats
- Ransomware programs
- Miners
- Vulnerable applications used by criminals during cyberattacks
- Attacks on macOS
- IoT attacks
- Attacks via web resources
- Local threats
Authors
- AMR
- IT threat evolution in Q3 2022
- IT threat evolution in Q3 2022. Non-mobile statistics
- IT threat evolution in Q3 2022. Mobile statistics
These statistics are based on detection verdicts of Kaspersky products and services received from users who consented to providing statistical data.
## Quarterly figures
According to Kaspersky Security Network, in Q3 2022:
- Kaspersky solutions blocked 956,074,958 attacks from online resources across the globe.
- Web Anti-Virus recognized 251,288,987 unique URLs as malicious.
- Attempts to run malware fo
Tenable
log4shell Critical Vulnerability
blogs_tenable·2022-11-02·CVSS 10.0
CVE-2021-44228 [CRITICAL] log4shell Critical Vulnerability
by Cesar Navas November 2, 2022
On December 9, 2021, researchers published proof-of-concept (PoC) exploit code for a critical vulnerability in Apache Log4j, a Java logging library used by a number of applications and services. This vulnerability, identified as CVE-2021-44228, is a Remote Code Execution (RCE) vulnerability in Apache Log4j. This dashboard is designed to help organizations determine what assets may contain vulnerabilities susceptible to the Apache Log4j exploit.
The Log4j vulnerability impacts a number of services and applications used widely across the internet, and is actively being exploited with multiple proofs of concept on GitHub.
According to the published CVE, all Apache Log4j versions 2.14.1 or less are vulnerable. An unauthenticated remote attacker could exploit
Tenable
Defending Against Ransomware (ACT)
blogs_tenable·2022-11-01
Defending Against Ransomware (ACT)
by Josef Weiss November 1, 2022
Ransomware attacks leverage well-known and established software vulnerabilities and poor cyber hygiene. Successful ransomware attacks can cripple an organization with increased costs and lost revenue. This dashboard highlights a path forward with an in-depth focus on cyber hygiene by enabling IT staff to focus on vulnerabilities that could have the most impact to the organization in the event of a ransomware attack.
There are many contributing factors to the upward trend of ransomware. The most important is the large number of software vulnerabilities and misconfigurations, along with Active Directory (AD) weaknesses that enable attackers to escalate privileges. Threat actors leverage poor cyber hygiene to their advantage to gain a foothold and propagate a
Checkpoint
29th August – Threat Intelligence Report
blogs_checkpoint·2022-08-29
CVE-2021-44228 29th August – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 29th August – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 29th August, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Montenegro has suffered a large-scale cyber attack, affecting multiple government services . According to some sources, it potentially affected critical infrastructure , transportation and telecommunications . Montenegro’s security agency has claimed that the attack was coordinated and persistent, and has concluded with cer
Talos
Avos ransomware group expands with new attack arsenal
blogs_talos·2022-06-21
Avos ransomware group expands with new attack arsenal
## Avos ransomware group expands with new attack arsenal
By Flavio Costa ,
In a recent customer engagement, we observed a month-long AvosLocker campaign.
The attackers utilized several different tools, including Cobalt Strike , Sliver and multiple commercial network scanners.
The initial ingress point in this incident was a pair of VMWare Horizon Unified Access Gateways that were vulnerable to Log4Shell . While Cisco products were deployed on the network, the appliances were never configured, allowing the attacker to gain access to internal servers and maintain a foothold.
During the time the attacker was active in the network, several security events were detected by the security products but were not reviewed by the security team, which could have prevented the ransomware activity.
Talos
Avos ransomware group expands with new attack arsenal
blogs_talos·2022-06-21
Avos ransomware group expands with new attack arsenal
By Flavio Costa,
- In a recent customer engagement, we observed a month-long AvosLocker campaign.
- The attackers utilized several different tools, including Cobalt Strike, Sliver and multiple commercial network scanners.
- The initial ingress point in this incident was a pair of VMWare Horizon Unified Access Gateways that were vulnerable to Log4Shell. While Cisco products were deployed on the network, the appliances were never configured, allowing the attacker to gain access to internal servers and maintain a foothold.
- During the time the attacker was active in the network, several security events were detected by the security products but were not reviewed by the security team, which could have prevented the ransomware activity.
## Threat Actor Profile: Avos
Avos is a ransomware gro
Tenable
Oracle April 2022 Critical Patch Update Addresses 221 CVEs
blogs_tenable·2022-04-20
Oracle April 2022 Critical Patch Update Addresses 221 CVEs
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Oracle January 2022 Critical Patch Update Addresses 266 CVEs
blogs_tenable·2022-01-19
Oracle January 2022 Critical Patch Update Addresses 266 CVEs
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Sentinelone
Log4j One Month On | Crimeware and Exploitation Roundup
blogs_sentinelone·2022-01-10·CVSS 7.5
CVE-2021-44228 [HIGH] Log4j One Month On | Crimeware and Exploitation Roundup
It has been 31 days since the initial public disclosure of a critical remote code execution (RCE) vulnerability in the Apache Log4j logging library that upended enterprise security at the close of 2021. In that time, since the initial CVE-2021-44228 (critical), we’ve already seen five more related CVEs
CVE-2021-45046 (critical)
CVE-2021-4104 (high)
CVE-2021-42550 (moderate)
CVE-2021-45105 (moderate)
CVE-2021-44832 (moderate))
and several updates to the library from 2.15.01 on December 9th to 2.17.1 on December 28th.
The importance of this class of vulnerabilities in such a ubiquitous library must not be forgotten with the next spin of the cyber news cycle: with millions of vulnerable devices, attacks are likely to continue for as long as such devices running unpatched software can b
Sentinelone
Log4j One Month On | Crimeware and Exploitation Roundup
blogs_sentinelone·2022-01-10·CVSS 7.5
CVE-2021-44228 [HIGH] Log4j One Month On | Crimeware and Exploitation Roundup
It has been 31 days since the initial public disclosure of a critical remote code execution (RCE) vulnerability in the Apache Log4j logging library that upended enterprise security at the close of 2021. In that time, since the initial CVE-2021-44228 (critical), we’ve already seen five more related CVEs
- CVE-2021-45046 (critical)
- CVE-2021-4104 (high)
- CVE-2021-42550 (moderate)
- CVE-2021-45105 (moderate)
- CVE-2021-44832 (moderate))
and several updates to the library from 2.15.01 on December 9th to 2.17.1 on December 28th.
The importance of this class of vulnerabilities in such a ubiquitous library must not be forgotten with the next spin of the cyber news cycle: with millions of vulnerable devices, attacks are likely to continue for as long as such devices running unpatched software
Checkpoint
3rd January– Threat Intelligence Report
blogs_checkpoint·2022-01-03·CVSS 10.0
CVE-2021-44228 [CRITICAL] 3rd January– Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 3rd January– Threat Intelligence Report
For the latest discoveries in cyber research for the week of 3rd January, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
The Vietnamese trading platform ONUS was victim of a ransomware attack leveraging the Log4j flaw on its payment system. Cyber criminals demanded a $5 million ransom in a double extortion scheme. ONUS refused to pay, so threat actors published for sale records of 2 million ONUS costumers.
Check Point IPS provides protection
Wiz
Log4Shell: Wrap all your Log4j fixes before the holidays | Wiz Blog
blogs_wiz·2021-12-21·CVSS 10.0
CVE-2021-44832 [CRITICAL] Log4Shell: Wrap all your Log4j fixes before the holidays | Wiz Blog
December 28, 2021 update - CVE-2021-44832, a new Log4j vulnerability
On December 28, 2021, Apache released new log4j version 2.17.1 to address CVE-2021-44832, a new remote code execution vulnerability affecting log4j 2.0-alpha7 - 2.17.0 excluding 2.3.2 and 2.12.4 versions. Wiz detects CVE-2021-44832.
The vulnerability severity is 6.6 as the exploit applies only if the attacker can modify the log4j configuration file.
Therefore, Wiz recommends focusing on patching workloads vulnerable to CVE-2021-44228 (the original log4shell) first , as it's easier to exploit and heavily exploited in the wild.
Ever since Log4Shell came into our lives, the internet has been flooded with daily Log4Shell CVEs updates, Log4j releases, as well as outdated recommendations and discredited mitigations. With all
Wiz
Log4Shell: Wrap all your Log4j fixes before the holidays | Wiz Blog
blogs_wiz·2021-12-21·CVSS 10.0
CVE-2021-44832 [CRITICAL] Log4Shell: Wrap all your Log4j fixes before the holidays | Wiz Blog
December 28, 2021 update - CVE-2021-44832, a new Log4j vulnerability
On December 28, 2021, Apache released new log4j version 2.17.1 to address CVE-2021-44832, a new remote code execution vulnerability affecting log4j 2.0-alpha7 - 2.17.0 excluding 2.3.2 and 2.12.4 versions. Wiz detects CVE-2021-44832.
The vulnerability severity is 6.6 as the exploit applies only if the attacker can modify the log4j configuration file.
Therefore, Wiz recommends focusing on patching workloads vulnerable to CVE-2021-44228 (the original log4shell) first, as it's easier to exploit and heavily exploited in the wild.
Ever since Log4Shell came into our lives, the internet has been flooded with daily Log4Shell CVEs updates, Log4j releases, as well as outdated recommendations and discredited mitigations. With all t
Tenable
CVE-2021-44228, CVE-2021-45046, CVE-2021-4104: Frequently Asked Questions About Log4Shell and Associated Vulnerabilities
blogs_tenable·2021-12-17·CVSS 7.5
[HIGH] CVE-2021-44228, CVE-2021-45046, CVE-2021-4104: Frequently Asked Questions About Log4Shell and Associated Vulnerabilities
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Management (CSPM)
Compliance
Cyber insurance
Data Security Posture Management (DSPM)
Google Cloud security
Infrastructure as Code (IaC) security
Kubernetes Security Pos
Qualys
Log4Shell Log4j Vulnerability Test | CVE-2021-45046 Detection | Qualys
blogs_qualys·2021-12-15·CVSS 10.0
CVE-2021-44228 [CRITICAL] Log4Shell Log4j Vulnerability Test | CVE-2021-45046 Detection | Qualys
#### Table of Contents
- About CVE-2021-44228
- Detecting the Vulnerability with Qualys WAS
- WAS Log4Shell Detection Methodology with Qualys Periscope
- Scan Configurations :
- About CVE-2021-45046
- About CVE-2021-44832
- Solution
- Credits
- References:
- Contributors
On December 09, 2021, a critical remote code execution vulnerability was identified in Apache Log4j2 after proof-of-concepts were leaked publicly, affecting Apache Log4j 2.x <= 2.15.0-rc1. The vulnerability is being tracked as CVE-2021-44228 with CVSSv3 10 score and affects numerous applications which are using the Log4j2 library.
#### Free Trial
### Quickly Identify Your Vulnerable Web Applications Using Our Cloud Platform
Get the Free Trial
Successful exploitation of this vulnerability could allow a remote attacker
Qualys
Is Your Web Application Exploitable By Log4Shell Vulnerability?
blogs_qualys·2021-12-15·CVSS 10.0
CVE-2021-44228 [CRITICAL] Is Your Web Application Exploitable By Log4Shell Vulnerability?
## Table of Contents
About CVE-2021-44228
Detecting the Vulnerability with Qualys WAS
WAS Log4Shell Detection Methodology with Qualys Periscope
Scan Configurations :
About CVE-2021-45046
About CVE-2021-44832
Solution
Credits
References:
Contributors
On December 09, 2021, a critical remote code execution vulnerability was identified in Apache Log4j2 after proof-of-concepts were leaked publicly, affecting Apache Log4j 2.x <= 2.15.0-rc1. The vulnerability is being tracked as CVE-2021-44228 with CVSSv3 10 score and affects numerous applications which are using the Log4j2 library.
## Free Trial
## Quickly Identify Your Vulnerable Web Applications Using Our Cloud Platform
Successful exploitation of this vulnerability could allow a remote attacker to download and execute arbitrary c
Trendmicro
Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
blogs_trendmicro·2021-12-13·CVSS 10.0
CVE-2021-44228 [CRITICAL] Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
Exploits y vulnerabilidades
## Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
Log4Shell, also known as CVE-2021-44228, was first reported privately to Apache on November 24 and was patched on December 9. It affects Apache Struts, Apache Solr, Apache Druid, Elasticsearch, Apache Dubbo, and VMware vCenter.
By: Ranga Duraisamy, Ashish Verma, Miguel Carlo Ang Dec 13, 2021 Read time: ( words)
Save to Folio
Update as of Dec 28, 2021: The latest Log4j vulnerability, CVE-2021-44832, has now been addressed in the Log4j 2.17.1 release .
Update as of Dec 22, 2021: The Impact section has been updated with information on the various payloads discovered after the start of the Log4Shell attacks.
Update as of Dec. 19, 2021: Our researchers at Zero Day Initiative published
Trendmicro
Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
blogs_trendmicro·2021-12-13·CVSS 10.0
CVE-2021-44228 [CRITICAL] Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
Exploits & Vulnerabilities
## Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
Log4Shell, also known as CVE-2021-44228, was first reported privately to Apache on November 24 and was patched on December 9. It affects Apache Struts, Apache Solr, Apache Druid, Elasticsearch, Apache Dubbo, and VMware vCenter.
By: Ranga Duraisamy, Ashish Verma, Miguel Carlo Ang 2021/12/13 Read time: ( words)
Save to Folio
Update as of Dec 28, 2021: The latest Log4j vulnerability, CVE-2021-44832, has now been addressed in the Log4j 2.17.1 release .
Update as of Dec 22, 2021: The Impact section has been updated with information on the various payloads discovered after the start of the Log4Shell attacks.
Update as of Dec. 19, 2021: Our researchers at Zero Day Initiative published a
Trendmicro
Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
blogs_trendmicro·2021-12-13·CVSS 10.0
CVE-2021-44228 [CRITICAL] Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
Sfruttamento vulnerabilità
## Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
Log4Shell, also known as CVE-2021-44228, was first reported privately to Apache on November 24 and was patched on December 9. It affects Apache Struts, Apache Solr, Apache Druid, Elasticsearch, Apache Dubbo, and VMware vCenter.
By: Ranga Duraisamy, Ashish Verma, Miguel Carlo Ang Dec 13, 2021 Read time: ( words)
Save to Folio
Update as of Dec 28, 2021: The latest Log4j vulnerability, CVE-2021-44832, has now been addressed in the Log4j 2.17.1 release .
Update as of Dec 22, 2021: The Impact section has been updated with information on the various payloads discovered after the start of the Log4Shell attacks.
Update as of Dec. 19, 2021: Our researchers at Zero Day Initiative published
Trendmicro
Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
blogs_trendmicro·2021-12-13·CVSS 10.0
CVE-2021-44228 [CRITICAL] Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
Exploits & Vulnerabilities
## Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
Log4Shell, also known as CVE-2021-44228, was first reported privately to Apache on November 24 and was patched on December 9. It affects Apache Struts, Apache Solr, Apache Druid, Elasticsearch, Apache Dubbo, and VMware vCenter.
By: Ranga Duraisamy, Ashish Verma, Miguel Carlo Ang Dec 13, 2021 Read time: ( words)
Save to Folio
Update as of Dec 28, 2021: The latest Log4j vulnerability, CVE-2021-44832, has now been addressed in the Log4j 2.17.1 release .
Update as of Dec 22, 2021: The Impact section has been updated with information on the various payloads discovered after the start of the Log4Shell attacks.
Update as of Dec. 19, 2021: Our researchers at Zero Day Initiative published
Trendmicro
Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
blogs_trendmicro·2021-12-13·CVSS 10.0
CVE-2021-44228 [CRITICAL] Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
Exploits & Vulnerabilities
# Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
Log4Shell, also known as CVE-2021-44228, was first reported privately to Apache on November 24 and was patched on December 9. It affects Apache Struts, Apache Solr, Apache Druid, Elasticsearch, Apache Dubbo, and VMware vCenter.
By: Ranga Duraisamy, Ashish Verma, Miguel Carlo Ang
2021/12/13
Read time: ( words)
Save to Folio
Update as of Dec 28, 2021: The latest Log4j vulnerability, CVE-2021-44832, has now been addressed in the Log4j 2.17.1 release.
Update as of Dec 22, 2021: The Impact section has been updated with information on the various payloads discovered after the start of the Log4Shell attacks.
Update as of Dec. 19, 2021: Our researchers at Zero Day Initiative published a g
Sentinelone
CVE-2021-44228: Apache Log4j Vulnerability
blogs_sentinelone·2021-12-11·CVSS 10.0
CVE-2021-44228 [CRITICAL] CVE-2021-44228: Apache Log4j Vulnerability
## Executive Summary
- A new critical remote code execution vulnerability in Apache Log4j2, a Java-based logging tool, is being tracked as CVE-2021-44228.
- Further vulnerabilities in the Log4j library, including CVE-2021-44832 and CVE-2021-45046, have since come to light, as detailed here.
- Major services and applications globally are impacted by these vulnerabilities due to the prevalence of Log4j2’s use in many web apps.
- Exploit proof-of-concept code is widely available and internet-wide scanning suggests active exploitation.
- Exploit attempts have led to commodity cryptominer, ransomware and other payloads. SentinelOne expects further opportunistic abuse by a wide variety of attackers, including further ransomware and nation-state actors.
- Due to the ease and rate of exploitation
Sentinelone
CVE-2021-44228: Apache Log4j Vulnerability
blogs_sentinelone·2021-12-11·CVSS 10.0
CVE-2021-44228 [CRITICAL] CVE-2021-44228: Apache Log4j Vulnerability
## Executive Summary
A new critical remote code execution vulnerability in Apache Log4j2 , a Java-based logging tool, is being tracked as CVE-2021-44228.
Further vulnerabilities in the Log4j library, including CVE-2021-44832 and CVE-2021-45046, have since come to light, as detailed here .
Major services and applications globally are impacted by these vulnerabilities due to the prevalence of Log4j2’s use in many web apps.
Exploit proof-of-concept code is widely available and internet-wide scanning suggests active exploitation.
Exploit attempts have led to commodity cryptominer, ransomware and other payloads. SentinelOne expects further opportunistic abuse by a wide variety of attackers, including further ransomware and nation-state actors.
Due to the ease and rate of exploitation atte
Talos
Threat Advisory: Critical Apache Log4j vulnerability being exploited in the wild
blogs_talos·2021-12-10·CVSS 10.0
[CRITICAL] Threat Advisory: Critical Apache Log4j vulnerability being exploited in the wild
## Update History
DateDescription of UpdatesDec. 20, 2021
Additional coverage and IOCs; additional detection capabilities for customers via Cisco Global Threat Alerts.
Dec. 18, 2021
Additional mitigation guidance; updated coverage information.
Dec. 17, 2021
Added additional vulnerability and mitigation information; added section on guidance for developers; timeline.
Dec. 16, 2021
Added additional vulnerability and mitigation information; added event timeline; relevant advisory information.
Dec. 15, 2021
Added observations on exploitation activity; updated coverage information. Additional IOCs.
Dec. 14, 2021
Added new CVE details; updated coverage information; additional mitigation guidance; additional threat vectors; Additional IOCs.
Dec. 13, 2021
Added additional vulnerability informatio
Talos
Threat Advisory: Critical Apache Log4j vulnerability being exploited in the wild
blogs_talos·2021-12-10·CVSS 10.0
[CRITICAL] Threat Advisory: Critical Apache Log4j vulnerability being exploited in the wild
## Threat Advisory: Critical Apache Log4j vulnerability being exploited in the wild
## Update History
Dec. 20, 2021
Additional coverage and IOCs; additional detection capabilities for customers via Cisco Global Threat Alerts.
Dec. 18, 2021
Additional mitigation guidance; updated coverage information.
Dec. 17, 2021
Added additional vulnerability and mitigation information; added section on guidance for developers; timeline.
Dec. 16, 2021
Added additional vulnerability and mitigation information; added event timeline; relevant advisory information.
Dec. 15, 2021
Added observations on exploitation activity; updated coverage information. Additional IOCs.
Dec. 14, 2021
Added new CVE details; updated coverage information; additional mitigation guidance; additional threat vectors; Ad
Unit42
Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021-44228) (Updated)
blogs_unit42·2021-12-10·CVSS 10.0
CVE-2021-44228 [CRITICAL] Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021-44228) (Updated)
## Executive Summary
On Dec. 9, 2021, a remote code execution (RCE) vulnerability in Apache Log4j 2 was identified being exploited in the wild. Public proof of concept (PoC) code was released and subsequent investigation revealed that exploitation was incredibly easy to perform. By submitting a specially crafted request to a vulnerable system, depending on how the system is configured, an attacker is able to instruct that system to download and subsequently execute a malicious payload. Due to the discovery of this exploit being so recent, there are still many servers, both on-premises and within cloud environments, that have yet to be patched. Like many high severity RCE exploits, thus far, massive scanning activity for CVE-2021-44228 has begun on the internet with the intent of seeking o
Unit42
Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021-44228) (Updated)
blogs_unit42·2021-12-10·CVSS 9.8
CVE-2021-44228 [CRITICAL] Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021-44228) (Updated)
Threat Research Center
Threat Research
Vulnerabilities
## Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021-44228) (Updated)
Tao Yan
Qi Deng
Haozhe Zhang
Yu Fu
Josh Grunzweig
Mike Harbison
Robert Falcone
Published: December 10, 2021
Threat Research
Vulnerabilities
Apache Log4j
CVE-2017-5645
CVE-2019-17571
CVE-2021-44228
CVE-2021-44832
CVE-2021-45046
CVE-2021-45105
Denial of service
Exploit
Log4j
Log4j 2
RCE
## Executive Summary
On Dec. 9, 2021, a remote code execution (RCE) vulnerability in Apache Log4j 2 was identified being exploited in the wild. Public proof of concept (PoC) code was released and subsequent investigation revealed that exploitation was incredibly easy to perform. By submitting a specially crafted request to a vu
Greynoiseio
Log4j Analysis: What to Do
blogs_greynoiseio·CVSS 10.0
[CRITICAL] Log4j Analysis: What to Do
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
arXiv
The Road of Adaptive AI for Precision in Cybersecurity
arxiv_fulltext·2025-12-05
The Road of Adaptive AI for Precision in Cybersecurity
## Abstract
Cybersecurity's evolving complexity presents unique challenges and opportunities for AI research and practice. This paper shares key lessons and insights from designing, building, and operating production-grade GenAI pipelines in cybersecurity, with a focus on the continual adaptation required to keep pace with ever-shifting knowledge bases, tooling, and threats.
Our goal is to provide an actionable perspective for AI practitioners and industry stakeholders navigating the frontier of GenAI for cybersecurity, with particular attention to how different adaptation mechanisms complement each other in end-to-end systems.
We present practical guidance derived from real-world deployments, propose best practices for leveraging retrieval- and model-level adaptation, and highlight ope
arXiv
Threat Assessment in Machine Learning based Systems
arxiv_fulltext·2022-06-30
Threat Assessment in Machine Learning based Systems
Threat Assessment in Machine Learning based Systems
Lionel Nganyewou Tidjon and Foutse Khomh, Senior Member, IEEE
The authors are with Polytechnique Montréal, Montréal, QC H3C 3A7, Canada.
E-mail: \lionel.tidjon, foutse.khomh\@polymtl.ca
## Abstract
Machine learning is a field of artificial intelligence (AI) that is becoming essential for several critical systems, making it a good target for threat actors. Threat actors exploit different Tactics, Techniques, and Procedures (TTPs) against the confidentiality, integrity, and availability of Machine Learning (ML) systems.
During the ML
cycle, they exploit adversarial TTPs to poison data and fool ML-based systems. In recent years, multiple security practices have been proposed for traditional systems but they are not enough to cope with th
arXiv
Attack Techniques and Threat Identification for Vulnerabilities
arxiv_fulltext·2022-06-22
Attack Techniques and Threat Identification for Vulnerabilities
Attack Techniques and Threat Identification for Vulnerabilities
Constantin Adam
Muhammed Fatih Bulut
Daby Sow
cmadam, mfbulut, [email protected]
IBM T.J. Watson Research Center
Yorktown Heights
NY
USA
Steven Ocepek
Chris Bedell
steve.ocepek, [email protected]
IBM Security X-Force Red
USA
Lilian Ngweta
[email protected]
Rensselaer Polytechnic Institute
Troy
NY
USA
Adam and Bulut, et al.
## Abstract
Modern organizations struggle with what is often considered an insurmountable number of vulnerabilities that are discovered and reported by their network and application vulnerability scanners. Therefore, prioritization and focus become critical, to spend their limited time on the highest risk vulnerabilities. In doing this, it is important for these organizations not only to
arXiv
The Race to the Vulnerable: Measuring the Log4j Shell Incident
arxiv_fulltext·2022-06-07
The Race to the Vulnerable: Measuring the Log4j Shell Incident
IEEEexample:BSTcontrolNew
5pt
textblock0.8(0.1,0.02)
If you cite this paper, please use the TMA reference:
R. Hiesgen, M. Nawrocki, T. C. Schmidt, and M. Wählisch.
2022. The Race to the Vulnerable: Measuring the Log4j Shell Incident.
In Proc. of Network Traffic Measurement and Analysis Conference (TMA ’22).
IFIP, 9 pages.
textblock
The Race to the Vulnerable:
Measuring the Log4j Shell Incident
Raphael Hiesgen
HAW Hamburg\ [email protected]
Marcin Nawrocki
Freie Universit\"at Berlin\ [email protected]
Thomas C. Schmidt
HAW Hamburg\ [email protected]
Matthias W\"ahlisch
Freie Universit\"at Berlin\ [email protected]
## Abstract
The critical remote-code-execution (RCE) Log4Shell is a severe vulnerability that was disclosed to the public on December 10, 2021. It
http://www.openwall.com/lists/oss-security/2021/12/28/1https://cert-portal.siemens.com/productcert/pdf/ssa-784507.pdfhttps://issues.apache.org/jira/browse/LOG4J2-3293https://lists.apache.org/thread/s1o5vlo78ypqxnzn6p8zf6t9shtq5143https://lists.debian.org/debian-lts-announce/2021/12/msg00036.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EVV25FXL4FU5X6X5BSL7RLQ7T6F65MRA/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T57MPJUW3MA6QGWZRTMCHHMMPQNVKGFC/https://security.netapp.com/advisory/ntap-20220104-0001/https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbdhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttp://www.openwall.com/lists/oss-security/2021/12/28/1https://cert-portal.siemens.com/productcert/pdf/ssa-784507.pdfhttps://issues.apache.org/jira/browse/LOG4J2-3293https://lists.apache.org/thread/s1o5vlo78ypqxnzn6p8zf6t9shtq5143https://lists.debian.org/debian-lts-announce/2021/12/msg00036.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EVV25FXL4FU5X6X5BSL7RLQ7T6F65MRA/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T57MPJUW3MA6QGWZRTMCHHMMPQNVKGFC/https://security.netapp.com/advisory/ntap-20220104-0001/https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbdhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.html
2021-12-28
Published
Exploited in the wild