CVE-2021-45105
published 2021-12-18CVE-2021-45105: Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This…
PriorityP185medium5.9CVSS 3.1
AVNACHPRNUINSUCNINAH
ITWEXPLOITVulnCheck KEVRansomwareInitial access
Exploited in the wild
EPSS
100.00%
100.0th percentile
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.
Affected
232 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | log4j | >= 2.0 < 2.3.1 | 2.3.1 |
| apache | log4j | 2.13.0 – 2.16.0 | — |
| apache | log4j | >= 2.4 < 2.12.3 | 2.12.3 |
| apache | logging | — | — |
| apache | ofbiz | — | — |
| apache_software_foundation | apache_log4j2 | >= log4j-core < 2.17.0 | 2.17.0 |
| debian | apache-log4j2 | < apache-log4j2 2.17.0-1 (bookworm) | apache-log4j2 2.17.0-1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| oracle | agile_engineering_data_management | — | — |
| oracle | agile_plm | — | — |
| oracle | agile_plm_mcad_connector | — | — |
| oracle | autovue_for_agile_product_lifecycle_management | — | — |
| oracle | banking_deposits_and_lines_of_credit_servicing | — | — |
| oracle | banking_enterprise_default_management | — | — |
| oracle | banking_enterprise_default_management | — | — |
| oracle | banking_loans_servicing | — | — |
| oracle | banking_party_management | — | — |
| oracle | banking_payments | — | — |
| oracle | banking_platform | — | — |
| oracle | banking_platform | — | — |
| oracle | banking_platform | — | — |
| oracle | banking_trade_finance | — | — |
| oracle | banking_treasury_management | — | — |
| oracle | business_intelligence | — | — |
Detection & IOCsextracted from sources · hover to see the quote
snort↗
Snort SIDs: 58722-58744, 58751, 58784-58790, 58795, 58801, 58811-58814
- →CVE-2021-45105 is triggered when a non-default Pattern Layout uses a Context Lookup (e.g., $${ctx:loginId}) and attacker-controlled Thread Context Map (MDC) data contains a recursive lookup string, causing a StackOverflowError. Detect by monitoring for StackOverflowError terminations in Java processes running Log4j 2.0-alpha1 through 2.16.0. ↗
- →JNDIExploit-generated URLs embed Base64-encoded commands in the URL path. Look for log entries or HTTP requests matching the pattern: ${jndi:ldap://HOST:PORT/Basic/Command/Base64/<base64data>} ↗
- →Also watch for jndi:dns:// schema in addition to jndi:ldap:// in log data and HTTP headers, as recent payloads have used DNS-based JNDI lookups. ↗
- →Inspect HTTP User-Agent headers and POST body fields for JNDI lookup strings (${jndi:...}) as the attack vector is commonly injected via these HTTP fields. ↗
- →In the AvosLocker campaign exploiting Log4Shell on VMware Horizon UAGs, initial post-exploitation activity involved wmiprvse.exe spawning encoded PowerShell with DownloadString. Alert on wmiprvse.exe launching PowerShell with -enc or DownloadString parameters. ↗
- →Use Qualys QID 376194 to detect vulnerable log4j jar versions at or below 2.16.0 in running containers and container images for CVE-2021-45105. ↗
- ·CVE-2021-45105 only triggers when a non-default Pattern Layout with a Context Lookup is configured. Default Log4j configurations are NOT vulnerable to this specific DoS. ↗
- ·The mitigations of setting log4j2.formatMsgNoLookups=true or using %m{nolookups} are insufficient for the broader Log4Shell family; they do not protect against CVE-2021-45105. ↗
- ·Log4j may be bundled inside vendor software; organizations cannot self-patch in those cases and must wait for vendor updates. ↗
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
ghsa10.0CRITICAL
osv10.0CRITICAL
vulncheck5.9MEDIUM
vendor_cisco10.0CRITICAL
vendor_ubuntu6.6MEDIUM
vendor_apache5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_oracle5.9MEDIUM
vendor_redhat5.9MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Oracle Utilities Network Management System 2.3.0.2/2.4.0.1/2.5.0.0/2.5.0.2 System Wide denial of service (Nessus ID 276397)
vuldb·2026-05-30·CVSS 5.9
CVE-2021-45105 [MEDIUM] Oracle Utilities Network Management System 2.3.0.2/2.4.0.1/2.5.0.0/2.5.0.2 System Wide denial of service (Nessus ID 276397)
A vulnerability was found in Oracle Utilities Network Management System 2.3.0.2/2.4.0.1/2.5.0.0/2.5.0.2 and classified as critical. This issue affects some unknown processing of the component System Wide. The manipulation results in denial of service.
This vulnerability was named CVE-2021-45105. The attack may be performed from remote. There is no available exploit.
VulDB
Oracle Retail Predictive Application Server 14.1.3.46/15.0.3.115/16.0.3.240 RPAS Server denial of service (Nessus ID 276397)
vuldb·2026-05-30·CVSS 5.9
CVE-2021-45105 [MEDIUM] Oracle Retail Predictive Application Server 14.1.3.46/15.0.3.115/16.0.3.240 RPAS Server denial of service (Nessus ID 276397)
A vulnerability, which was classified as critical, has been found in Oracle Retail Predictive Application Server 14.1.3.46/15.0.3.115/16.0.3.240. This affects an unknown part of the component RPAS Server. The manipulation leads to denial of service.
This vulnerability is documented as CVE-2021-45105. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
VulDB
Oracle Retail Returns Management 14.1 Security denial of service (Nessus ID 276397)
vuldb·2026-05-30·CVSS 5.9
CVE-2021-45105 [MEDIUM] Oracle Retail Returns Management 14.1 Security denial of service (Nessus ID 276397)
A vulnerability has been found in Oracle Retail Returns Management 14.1 and classified as critical. This issue affects some unknown processing of the component Security. This manipulation causes denial of service.
This vulnerability appears as CVE-2021-45105. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.
VulDB
Oracle Retail Point-of-Service 14.1 Administration denial of service (Nessus ID 276397)
vuldb·2026-05-30·CVSS 5.9
CVE-2021-45105 [MEDIUM] Oracle Retail Point-of-Service 14.1 Administration denial of service (Nessus ID 276397)
A vulnerability classified as critical was found in Oracle Retail Point-of-Service 14.1. Affected by this issue is some unknown functionality of the component Administration. Executing a manipulation can lead to denial of service.
This vulnerability is registered as CVE-2021-45105. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is advised.
VulDB
Oracle Retail Order Broker 16.0/18.0/19.1 System Administration denial of service (Nessus ID 276397)
vuldb·2026-05-30·CVSS 5.9
CVE-2021-45105 [MEDIUM] Oracle Retail Order Broker 16.0/18.0/19.1 System Administration denial of service (Nessus ID 276397)
A vulnerability described as critical has been identified in Oracle Retail Order Broker 16.0/18.0/19.1. Affected is an unknown function of the component System Administration. Such manipulation leads to denial of service.
This vulnerability is listed as CVE-2021-45105. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.
VulDB
Oracle Retail Service Backbone up to 19.0.1 RSB Installation denial of service (Nessus ID 276397)
vuldb·2026-05-30·CVSS 5.9
CVE-2021-45105 [MEDIUM] Oracle Retail Service Backbone up to 19.0.1 RSB Installation denial of service (Nessus ID 276397)
A vulnerability was found in Oracle Retail Service Backbone up to 19.0.1 and classified as critical. Impacted is an unknown function of the component RSB Installation. Such manipulation leads to denial of service.
This vulnerability is traded as CVE-2021-45105. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.
VulDB
Oracle Retail Price Management up to 16.0.3 Security denial of service (Nessus ID 276397)
vuldb·2026-05-30·CVSS 5.9
CVE-2021-45105 [MEDIUM] Oracle Retail Price Management up to 16.0.3 Security denial of service (Nessus ID 276397)
A vulnerability, which was classified as critical, was found in Oracle Retail Price Management 13.2/14.0.4/14.1.3/15.0.3/16.0.3. This vulnerability affects unknown code of the component Security. The manipulation results in denial of service.
This vulnerability is reported as CVE-2021-45105. The attack can be launched remotely. No exploit exists.
You should upgrade the affected component.
VulDB
Oracle Retail Order Management System 19.5 Upgrade Install denial of service (Nessus ID 276397)
vuldb·2026-05-30·CVSS 5.9
CVE-2021-45105 [MEDIUM] Oracle Retail Order Management System 19.5 Upgrade Install denial of service (Nessus ID 276397)
A vulnerability classified as critical has been found in Oracle Retail Order Management System 19.5. Affected by this vulnerability is an unknown functionality of the component Upgrade Install. Performing a manipulation results in denial of service.
This vulnerability is cataloged as CVE-2021-45105. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
GHSA
Security Advisory for "Log4Shell"
ghsa·2022-01-21·CVSS 10.0
CVE-2021-44228 [CRITICAL] CWE-20 Security Advisory for "Log4Shell"
Security Advisory for "Log4Shell"
### Impact
A highly critical 0-day exploit (CVE-2021-44228) is found in Apache log4j 2 library on December 9, 2021.
This affects Apache log4j versions from 2.0-beta9 to 2.14.1 (inclusive).
This vulnerability allows a remote attacker to execute code on the server if the system logs an attacker-controlled string value with the attacker's JNDI LDAP server lookup.
Another vulnerability related to the same library, which was discovered on 12/14/2021 (CVE-2021-45046) and revealed another Remote Code Execution vulnerability, has been investigated by Hazelcast team as well and it is found that it does not affect Hazelcast Products under default configurations.
The finding of CVE-2021-45105 on 12/14/2021, which can cause a Denial of Service attack, was investi
OSV
Security Advisory for "Log4Shell"
osv·2022-01-21·CVSS 10.0
CVE-2021-44228 [CRITICAL] Security Advisory for "Log4Shell"
Security Advisory for "Log4Shell"
### Impact
A highly critical 0-day exploit (CVE-2021-44228) is found in Apache log4j 2 library on December 9, 2021.
This affects Apache log4j versions from 2.0-beta9 to 2.14.1 (inclusive).
This vulnerability allows a remote attacker to execute code on the server if the system logs an attacker-controlled string value with the attacker's JNDI LDAP server lookup.
Another vulnerability related to the same library, which was discovered on 12/14/2021 (CVE-2021-45046) and revealed another Remote Code Execution vulnerability, has been investigated by Hazelcast team as well and it is found that it does not affect Hazelcast Products under default configurations.
The finding of CVE-2021-45105 on 12/14/2021, which can cause a Denial of Service attack, was investi
OSV
apache-log4j2 vulnerabilities
osv·2022-01-11·CVSS 6.6
CVE-2021-44832 [MEDIUM] apache-log4j2 vulnerabilities
apache-log4j2 vulnerabilities
It was discovered that Apache Log4j 2 was vulnerable to remote code
execution (RCE) attack when configured to use a JDBC Appender with a
JNDI LDAP data source URI. A remote attacker could possibly use this issue to
cause a crash, leading to a denial of service. (CVE-2021-44832)
Hideki Okamoto and Guy Lederfein discovered that Apache Log4j 2 did not
protect against infinite recursion in lookup evaluation. A remote attacker
could possibly use this issue to cause Apache Log4j 2 to crash, leading to
a denial of service. This issue only affected Ubuntu 18.04 LTS.
(CVE-2021-45105)
GHSA
Remote code injection, Improper Input Validation and Uncontrolled Recursion in Log4j library
ghsa·2022-01-06·CVSS 10.0
CVE-2021-44228 [CRITICAL] CWE-20 Remote code injection, Improper Input Validation and Uncontrolled Recursion in Log4j library
Remote code injection, Improper Input Validation and Uncontrolled Recursion in Log4j library
### Summary
The version used of Log4j, the library used for logging by PowerNukkit, is subject to a remote code execution vulnerability via the ldap JNDI parser.
It's well detailed at [CVE-2021-44228](https://github.com/advisories/GHSA-jfh8-c2jp-5v3q) and CVE-2021-45105(https://github.com/advisories/GHSA-p6xc-xr62-6r2g).
### Impact
Malicious client code could be used to send messages and cause remote code execution on the server.
### Patches
PowerNukkit `1.5.2.1` is a patch-release that only updates the Log4j version to `2.17.0` and should be used instead of `1.5.2.0`.
All versions prior to `1.5.2.1` are affected and are not patched.
### Workarounds
If you can't upgrade, you can use the `-Dlog4
OSV
Remote code injection, Improper Input Validation and Uncontrolled Recursion in Log4j library
osv·2022-01-06·CVSS 10.0
CVE-2021-44228 [CRITICAL] Remote code injection, Improper Input Validation and Uncontrolled Recursion in Log4j library
Remote code injection, Improper Input Validation and Uncontrolled Recursion in Log4j library
### Summary
The version used of Log4j, the library used for logging by PowerNukkit, is subject to a remote code execution vulnerability via the ldap JNDI parser.
It's well detailed at [CVE-2021-44228](https://github.com/advisories/GHSA-jfh8-c2jp-5v3q) and CVE-2021-45105(https://github.com/advisories/GHSA-p6xc-xr62-6r2g).
### Impact
Malicious client code could be used to send messages and cause remote code execution on the server.
### Patches
PowerNukkit `1.5.2.1` is a patch-release that only updates the Log4j version to `2.17.0` and should be used instead of `1.5.2.0`.
All versions prior to `1.5.2.1` are affected and are not patched.
### Workarounds
If you can't upgrade, you can use the `-Dlog4
OSV
CVE-2021-45105: Apache Log4j2 versions 2
osv·2021-12-18·CVSS 5.9
CVE-2021-45105 [MEDIUM] CVE-2021-45105: Apache Log4j2 versions 2
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.
OSV
Apache Log4j2 vulnerable to Improper Input Validation and Uncontrolled Recursion
osv·2021-12-18
CVE-2021-45105 [HIGH] Apache Log4j2 vulnerable to Improper Input Validation and Uncontrolled Recursion
Apache Log4j2 vulnerable to Improper Input Validation and Uncontrolled Recursion
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0 and 2.12.3.
# Affected packages
Only the `org.apache.logging.log4j:log4j-core` package is directly affected by this vulnerability. The `org.apache.logging.log4j:log4j-api` should be kept at the same version as the `org.apache.logging.log4j:log4j-core` package to ensure compatability if in use.
GHSA
Apache Log4j2 vulnerable to Improper Input Validation and Uncontrolled Recursion
ghsa·2021-12-18
CVE-2021-45105 [HIGH] CWE-20 Apache Log4j2 vulnerable to Improper Input Validation and Uncontrolled Recursion
Apache Log4j2 vulnerable to Improper Input Validation and Uncontrolled Recursion
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0 and 2.12.3.
# Affected packages
Only the `org.apache.logging.log4j:log4j-core` package is directly affected by this vulnerability. The `org.apache.logging.log4j:log4j-api` should be kept at the same version as the `org.apache.logging.log4j:log4j-core` package to ensure compatability if in use.
VulnCheck
Apache log4j Improper Input Validation
vulncheck·2021·CVSS 5.9
CVE-2021-45105 [MEDIUM] Apache log4j Improper Input Validation
Apache log4j Improper Input Validation
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.
Affected: Apache log4j
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Known Ransomware Campaign Use: Known
Exploitation References: https://cisa.gov/news-events/alerts/2021/12/22/mitigating-log4shell-and-other-log4j-related-vulnerabilities; https://cisa.gov/news-events/cybersecurity-advisories/aa21-356a
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Core (Apache Log4j) — CVE-2021-45105
vendor_oracle·2026-01-15·CVSS 5.9
CVE-2021-45105 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: Core (Apache Log4j) — CVE-2021-45105
Oracle Oracle Fusion Middleware Risk Matrix: Core (Apache Log4j) vulnerability
CVE: CVE-2021-45105
CVSS: 5.9
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2026 (JAN 2026)
Oracle
Oracle Oracle Utilities Applications Risk Matrix: System Wide (Apache Log4j) — CVE-2021-45105
vendor_oracle·2023-01-15·CVSS 5.9
CVE-2021-45105 [MEDIUM] Oracle Oracle Utilities Applications Risk Matrix: System Wide (Apache Log4j) — CVE-2021-45105
Oracle Oracle Utilities Applications Risk Matrix: System Wide (Apache Log4j) vulnerability
CVE: CVE-2021-45105
CVSS: 5.9
Protocol: Multiple
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2023 (JAN 2023)
Oracle
Oracle Oracle Communications Risk Matrix: Integration (Apache Log4j) — CVE-2021-45105
vendor_oracle·2022-01-15·CVSS 5.9
CVE-2021-45105 [MEDIUM] Oracle Oracle Communications Risk Matrix: Integration (Apache Log4j) — CVE-2021-45105
Oracle Oracle Communications Risk Matrix: Integration (Apache Log4j) vulnerability
CVE: CVE-2021-45105
CVSS: 5.9
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2022 (JAN 2022)
Ubuntu
Apache Log4j 2 vulnerabilities
vendor_ubuntu·2022-01-11·CVSS 6.6
CVE-2021-44832 [MEDIUM] Apache Log4j 2 vulnerabilities
Title: Apache Log4j 2 vulnerabilities
Summary: Several security issues were fixed in Apache Log4j 2.
It was discovered that Apache Log4j 2 was vulnerable to remote code
execution (RCE) attack when configured to use a JDBC Appender with a
JNDI LDAP data source URI. A remote attacker could possibly use this issue to
cause a crash, leading to a denial of service. (CVE-2021-44832)
Hideki Okamoto and Guy Lederfein discovered that Apache Log4j 2 did not
protect against infinite recursion in lookup evaluation. A remote attacker
could possibly use this issue to cause Apache Log4j 2 to crash, leading to
a denial of service. This issue only affected Ubuntu 18.04 LTS.
(CVE-2021-45105)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Apache Log4j 2 vulnerability
vendor_ubuntu·2021-12-19
CVE-2021-45105 Apache Log4j 2 vulnerability
Title: Apache Log4j 2 vulnerability
Summary: Apache Log4j 2 could be made to crash if it received specially crafted
input.
Hideki Okamoto and Guy Lederfein discovered that Apache Log4j 2 did not
protect against infinite recursion in lookup evaluation. A remote attacker
could possibly use this issue to cause Apache Log4j 2 to crash, leading to
a denial of service.
Please see the following link for more information:
https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/Log4Shell
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
log4j-core: DoS in log4j 2.x with Thread Context Map (MDC) input data contains a recursive lookup and context lookup pattern
vendor_redhat·2021-12-18·CVSS 5.9
CVE-2021-45105 [MEDIUM] CWE-835 log4j-core: DoS in log4j 2.x with Thread Context Map (MDC) input data contains a recursive lookup and context lookup pattern
log4j-core: DoS in log4j 2.x with Thread Context Map (MDC) input data contains a recursive lookup and context lookup pattern
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.
A flaw was found in the Apache Log4j logging library 2.x. when the logging configuration uses a non-default Pattern Layout with a Context Lookup. Attackers with control over Thread Context Map (MDC) input data can craft malicious input data that contains a recursive lookup and can cause Denial of Service.
Statement: Red Hat Pro
VMware
VMware Response to Apache Log4j Remote Code Execution Vulnerabilities (CVE-2021-44228, CVE-2021-45046)
vendor_vmware·2021-12-10·CVSS 10.0
CVE-2021-44228 [CRITICAL] VMware Response to Apache Log4j Remote Code Execution Vulnerabilities (CVE-2021-44228, CVE-2021-45046)
VMSA-2021-0028: VMware Response to Apache Log4j Remote Code Execution Vulnerabilities (CVE-2021-44228, CVE-2021-45046)
Description Multiple products impacted by remote code execution vulnerabilities via Apache Log4j (CVE-2021-44228, CVE-2021-45046).
CVEs: CVE-2021-44228, CVE-2021-44832, CVE-2021-45046, CVE-2021-45105
Affected products: ESXi, NSX Data Center, NSX-T, VMware Aria, VMware Carbon Black, VMware Cloud Foundation, VMware HCX, VMware Horizon, VMware Identity Manager, VMware NSX, VMware SD-WAN, VMware Tanzu, VMware VeloCloud, VMware Workspace ONE, VMware vCenter Server, VMware vRealize, VMware vSphere
Cisco
Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
vendor_cisco·2021-12-10·CVSS 10.0
CVE-2021-44228 [CRITICAL] CWE-20 Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
Critical Vulnerabilities in Apache Log4j Java Logging Library
On December 9, 2021, the following critical vulnerability in the Apache Log4j Java logging library affecting all Log4j2 versions earlier than 2.15.0 was disclosed:
CVE-2021-44228: Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
On December 14, 2021, the following critical vulnerability, which affects certain Apache Log4j use cases in versions 2.15.0 and earlier, was disclosed:
CVE-2021-45046: Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
On December 18, 2021, a vulnerability in the Apache Log4j component affecting vers
Palo Alto
Impact of Log4j Vulnerabilities CVE-2021-44228, CVE-2021-45046, CVE-2021-45105, and CVE-2021-44832
vendor_paloalto·2021-12-10·CVSS 10.0
CVE-2021-44228 [CRITICAL] CWE-94 Impact of Log4j Vulnerabilities CVE-2021-44228, CVE-2021-45046, CVE-2021-45105, and CVE-2021-44832
Impact of Log4j Vulnerabilities CVE-2021-44228, CVE-2021-45046, CVE-2021-45105, and CVE-2021-44832
Apache Log4j Java library is vulnerable to a remote code execution vulnerability CVE-2021-44228, known as Log4Shell, and related vulnerabilities CVE-2021-45046, CVE-2021-45105, and CVE-2021-44832. Log4Shell allows remote unauthenticated attackers with the ability to inject text into log messages to execute arbitrary code loaded from malicious servers with the privileges of the process utilizing Log4j.
These products and services are not affected by Log4Shell: Bridgecrew, Cortex Data Lake, Cortex XDR agents, Cortex XSOAR, Cortex Xpanse, Enterprise Data Loss Prevention (DLP), Expedition, the GlobalProtect app, IoT Security, Okyo Garde, PAN-DB Private Cloud, PAN-OS software running on firewall
Debian
CVE-2021-45105: apache-log4j2 - Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) di...
vendor_debian·2021·CVSS 5.9
CVE-2021-45105 [MEDIUM] CVE-2021-45105: apache-log4j2 - Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) di...
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.
Scope: local
bookworm: resolved (fixed in 2.17.0-1)
bullseye: resolved (fixed in 2.17.0-1~deb11u1)
forky: resolved (fixed in 2.17.0-1)
sid: resolved (fixed in 2.17.0-1)
trixie: resolved (fixed in 2.17.0-1)
Cisco
Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
vendor_cisco·CVSS 3.1
CVE-2021-45105 Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
CVE-2021-45105: Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
Critical Vulnerabilities in Apache Log4j Java Logging Library On December 9, 2021, the following critical vulnerability in the Apache Log4j Java logging library affecting all Log4j2 versions earlier than 2.15.0 was disclosed: CVE-2021-44228: Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints On December 14, 2021, the following critical vulnerability, which affects certain Apache Log4j use cases in versions 2.15.0 and earlier, was disclosed: CVE-2021-45046: Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack On December 18, 2021, a vulnerability in the Apache Log4j component affe
Cisco
Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
vendor_cisco·CVSS 3.1
CVE-2021-44228 Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
CVE-2021-44228: Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
Critical Vulnerabilities in Apache Log4j Java Logging Library On December 9, 2021, the following critical vulnerability in the Apache Log4j Java logging library affecting all Log4j2 versions earlier than 2.15.0 was disclosed: CVE-2021-44228: Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints On December 14, 2021, the following critical vulnerability, which affects certain Apache Log4j use cases in versions 2.15.0 and earlier, was disclosed: CVE-2021-45046: Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack On December 18, 2021, a vulnerability in the Apache Log4j component affe
Cisco
Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
vendor_cisco·CVSS 3.1
CVE-2021-44832 Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
CVE-2021-44832: Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
Critical Vulnerabilities in Apache Log4j Java Logging Library On December 9, 2021, the following critical vulnerability in the Apache Log4j Java logging library affecting all Log4j2 versions earlier than 2.15.0 was disclosed: CVE-2021-44228: Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints On December 14, 2021, the following critical vulnerability, which affects certain Apache Log4j use cases in versions 2.15.0 and earlier, was disclosed: CVE-2021-45046: Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack On December 18, 2021, a vulnerability in the Apache Log4j component affe
Cisco
Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
vendor_cisco·CVSS 3.1
CVE-2021-45046 Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
CVE-2021-45046: Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
Critical Vulnerabilities in Apache Log4j Java Logging Library On December 9, 2021, the following critical vulnerability in the Apache Log4j Java logging library affecting all Log4j2 versions earlier than 2.15.0 was disclosed: CVE-2021-44228: Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints On December 14, 2021, the following critical vulnerability, which affects certain Apache Log4j use cases in versions 2.15.0 and earlier, was disclosed: CVE-2021-45046: Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack On December 18, 2021, a vulnerability in the Apache Log4j component affe
Apache
Apache logging: CVE-2021-45105
vendor_apache
CVE-2021-45105 Apache logging: CVE-2021-45105
Apache logging: CVE-2021-45105
Summary Infinite recursion in lookup evaluation CVSS 3.x Score & Vector 5.9 MEDIUM (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H) Components affected log4j-core Versions affected [2.0-alpha1, 2.3.1) ∪ [2.4, 2.12.3) ∪ [2.13.0, 2.17.0) Versions fixed 2.3.1 (for Java 6), 2.12.3 (for Java 7), and 2.17.0 (for Java 8 and later)
Severity: moderate
Affected versions: 2.3.1
Apache
Apache ofbiz: CVE-2021-45105
vendor_apache·CVSS 5.9
CVE-2021-45105 [MEDIUM] Apache ofbiz: CVE-2021-45105
Apache ofbiz: CVE-2021-45105
; affected all releases before 17.12.09 and 18.12.04; fixed in 17.12.09 and 18.12.04 with commits 00896e7 , c69bc8f , 4442c2a
Suricata
ET EXPLOIT Possible Apache log4j Uncontrolled Recursion Lookup (CVE-2021-45105)
suricata·2021-12-22·CVSS 5.9
CVE-2021-45105 [MEDIUM] ET EXPLOIT Possible Apache log4j Uncontrolled Recursion Lookup (CVE-2021-45105)
ET EXPLOIT Possible Apache log4j Uncontrolled Recursion Lookup (CVE-2021-45105)
Rule: alert tcp any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Possible Apache log4j Uncontrolled Recursion Lookup (CVE-2021-45105)"; flow:established,to_server; stream_size:client,<,10000; content:"|24 7b 24 7b 3a 3a 2d 24 7b 3a 3a 2d 24 24 7b 3a 3a 2d|"; fast_pattern; content:"|7d 7d 7d 7d|"; within:6; reference:cve,2021-45105; classtype:attempted-admin; sid:2034839; rev:2; metadata:created_at 2021_12_22, cve CVE_2021_45105, confidence Medium, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_08, reviewed_at 2024_05_07;)
No public exploits indexed.
Tenable
Frequently Asked Questions About Iranian Cyber Operations
blogs_tenable·2025-06-27
Frequently Asked Questions About Iranian Cyber Operations
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Tenable Research Advisories: Urgent Action
blogs_tenable·2023-11-20
Tenable Research Advisories: Urgent Action
by Cesar Navas November 20, 2023
Tenable Research delivers world class exposure intelligence, data science insights, zero day research and security advisories. Our Security Response Team (SRT) in Tenable Research tracks threat and vulnerability intelligence feeds to make sure our research teams can deliver sensor coverage to our products as quickly as possible. The SRT also works to dig into technical details and author white papers, blogs, and additional communications to ensure stakeholders are fully informed of the latest cyber risks and threats. The SRT provides breakdowns for the latest critical vulnerabilities on the Tenable blog.
When security events rise to the level of taking immediate action, Tenable - leveraging SRT intelligence - notifies customers proactively to provide expo
Securelist
IT threat evolution in Q3 2022. Non-mobile statistics
blogs_securelist·2022-11-18
IT threat evolution in Q3 2022. Non-mobile statistics
Table of Contents
Quarterly figures
Financial threats
Number of users attacked by banking malware
TOP 10 banking malware families
Geography of financial malware attacks
Ransomware programs
Quarterly trends and highlights
Number of new modifications
Number of users attacked by ransomware Trojans
Geography of attacked users
TOP 10 most common families of ransomware Trojans
Miners
Number of new miner modifications
Number of users attacked by miners
Geography of miner attacks
Vulnerable applications used by criminals during cyberattacks
Quarterly highlights
Vulnerability statistics
Attacks on macOS
TOP 20 threats for macOS
Geography of threats for macOS
IoT attacks
IoT threat statistics
Attacks via web resources
Countries and territories that serve as sources of web-ba
Securelist
PC malware statistics, Q3 2022
blogs_securelist·2022-11-18
PC malware statistics, Q3 2022
Table of Contents
- Quarterly figures
- Financial threats
- Ransomware programs
- Miners
- Vulnerable applications used by criminals during cyberattacks
- Attacks on macOS
- IoT attacks
- Attacks via web resources
- Local threats
Authors
- AMR
- IT threat evolution in Q3 2022
- IT threat evolution in Q3 2022. Non-mobile statistics
- IT threat evolution in Q3 2022. Mobile statistics
These statistics are based on detection verdicts of Kaspersky products and services received from users who consented to providing statistical data.
## Quarterly figures
According to Kaspersky Security Network, in Q3 2022:
- Kaspersky solutions blocked 956,074,958 attacks from online resources across the globe.
- Web Anti-Virus recognized 251,288,987 unique URLs as malicious.
- Attempts to run malware fo
Tenable
log4shell Critical Vulnerability
blogs_tenable·2022-11-02·CVSS 10.0
CVE-2021-44228 [CRITICAL] log4shell Critical Vulnerability
by Cesar Navas November 2, 2022
On December 9, 2021, researchers published proof-of-concept (PoC) exploit code for a critical vulnerability in Apache Log4j, a Java logging library used by a number of applications and services. This vulnerability, identified as CVE-2021-44228, is a Remote Code Execution (RCE) vulnerability in Apache Log4j. This dashboard is designed to help organizations determine what assets may contain vulnerabilities susceptible to the Apache Log4j exploit.
The Log4j vulnerability impacts a number of services and applications used widely across the internet, and is actively being exploited with multiple proofs of concept on GitHub.
According to the published CVE, all Apache Log4j versions 2.14.1 or less are vulnerable. An unauthenticated remote attacker could exploit
Tenable
Defending Against Ransomware (ACT)
blogs_tenable·2022-11-01
Defending Against Ransomware (ACT)
by Josef Weiss November 1, 2022
Ransomware attacks leverage well-known and established software vulnerabilities and poor cyber hygiene. Successful ransomware attacks can cripple an organization with increased costs and lost revenue. This dashboard highlights a path forward with an in-depth focus on cyber hygiene by enabling IT staff to focus on vulnerabilities that could have the most impact to the organization in the event of a ransomware attack.
There are many contributing factors to the upward trend of ransomware. The most important is the large number of software vulnerabilities and misconfigurations, along with Active Directory (AD) weaknesses that enable attackers to escalate privileges. Threat actors leverage poor cyber hygiene to their advantage to gain a foothold and propagate a
Tenable
AA22-257A: Cybersecurity Agencies Issue Joint Advisory on Iranian Islamic Revolutionary Guard Corps-Affiliated Attacks
blogs_tenable·2022-09-15
AA22-257A: Cybersecurity Agencies Issue Joint Advisory on Iranian Islamic Revolutionary Guard Corps-Affiliated Attacks
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Qualys
Mitigating the Risk of Zero-Day Vulnerabilities by using Compensating Controls
blogs_qualys·2022-08-23
Mitigating the Risk of Zero-Day Vulnerabilities by using Compensating Controls
## Table of Contents
Why Are Zero-Day Attacks/Exploits so Dangerous?
How Qualys Policy Compliance Helps Combat Zero-Day Threats
Benefit of Qualys Policy Compliance for Zero-Day Threats
Summary
Getting Started
Contributors
Zero-day vulnerability attacks have emerged as a major cybersecurity threat in the last few years. Organizations most often targeted include large enterprises and government/Federal agencies. However, any organization, regardless of its size, business, or industry, is a potential target for zero-day threats.
Most notably, already publicly disclosed. This means that one out of every four zero-day exploits detected could potentially have been avoided if a more thorough investigation and patching effort had been pursued. In 2021, around 58 zero-day vulnerabilities we
Talos
Avos ransomware group expands with new attack arsenal
blogs_talos·2022-06-21
Avos ransomware group expands with new attack arsenal
## Avos ransomware group expands with new attack arsenal
By Flavio Costa ,
In a recent customer engagement, we observed a month-long AvosLocker campaign.
The attackers utilized several different tools, including Cobalt Strike , Sliver and multiple commercial network scanners.
The initial ingress point in this incident was a pair of VMWare Horizon Unified Access Gateways that were vulnerable to Log4Shell . While Cisco products were deployed on the network, the appliances were never configured, allowing the attacker to gain access to internal servers and maintain a foothold.
During the time the attacker was active in the network, several security events were detected by the security products but were not reviewed by the security team, which could have prevented the ransomware activity.
Talos
Avos ransomware group expands with new attack arsenal
blogs_talos·2022-06-21
Avos ransomware group expands with new attack arsenal
By Flavio Costa,
- In a recent customer engagement, we observed a month-long AvosLocker campaign.
- The attackers utilized several different tools, including Cobalt Strike, Sliver and multiple commercial network scanners.
- The initial ingress point in this incident was a pair of VMWare Horizon Unified Access Gateways that were vulnerable to Log4Shell. While Cisco products were deployed on the network, the appliances were never configured, allowing the attacker to gain access to internal servers and maintain a foothold.
- During the time the attacker was active in the network, several security events were detected by the security products but were not reviewed by the security team, which could have prevented the ransomware activity.
## Threat Actor Profile: Avos
Avos is a ransomware gro
Trendmicro
How to Detect Apache Log4j Vulnerabilities
blogs_trendmicro·2022-01-27·CVSS 10.0
[CRITICAL] How to Detect Apache Log4j Vulnerabilities
Network
## How to detect Apache Log4j vulnerabilities
Explore how to detect Apache Log4j (Log4Shell) vulnerabilities using cloud-native security tools.
By: Nitesh Surana Jan 27, 2022 Read time: ( words)
Save to Folio
In my previous blog, I reviewed how to detect Apache HTTP server exploitation from vulnerabilities in October. Weirdly enough, I wrote that article before the Apache Log4j (Log4Shell) news broke in December 2021 . So I’m back to write about how to detect the infamous Log4j vulnerability ( CVE-2021-44228 ) that allows attackers to achieve remote code execution on the victim servers using the vulnerable versions of the popular library in exposed web applications/services.
Source: Trend Micro
The above depicts a vulnerable public facing web service that logs the User-Agent
Trendmicro
How to Detect Apache Log4j Vulnerabilities
blogs_trendmicro·2022-01-27·CVSS 10.0
[CRITICAL] How to Detect Apache Log4j Vulnerabilities
Network
# How to detect Apache Log4j vulnerabilities
Explore how to detect Apache Log4j (Log4Shell) vulnerabilities using cloud-native security tools.
By: Nitesh Surana
2022/01/27
Read time: ( words)
Save to Folio
In my previous blog, I reviewed how to detect Apache HTTP server exploitation from vulnerabilities in October. Weirdly enough, I wrote that article before the Apache Log4j (Log4Shell) news broke in December 2021. So I’m back to write about how to detect the infamous Log4j vulnerability (CVE-2021-44228) that allows attackers to achieve remote code execution on the victim servers using the vulnerable versions of the popular library in exposed web applications/services.
Stages of Log4j attack
Before diving straight into detection/prevention, let’s first take a look at the di
Trendmicro
How to Detect Apache Log4j Vulnerabilities
blogs_trendmicro·2022-01-27·CVSS 10.0
[CRITICAL] How to Detect Apache Log4j Vulnerabilities
Network
## How to detect Apache Log4j vulnerabilities
Explore how to detect Apache Log4j (Log4Shell) vulnerabilities using cloud-native security tools.
By: Nitesh Surana 2022/01/27 Read time: ( words)
Save to Folio
In my previous blog, I reviewed how to detect Apache HTTP server exploitation from vulnerabilities in October. Weirdly enough, I wrote that article before the Apache Log4j (Log4Shell) news broke in December 2021 . So I’m back to write about how to detect the infamous Log4j vulnerability ( CVE-2021-44228 ) that allows attackers to achieve remote code execution on the victim servers using the vulnerable versions of the popular library in exposed web applications/services.
Source: Trend Micro
The above depicts a vulnerable public facing web service that logs the User-Agent f
Trendmicro
How to Detect Apache Log4j Vulnerabilities
blogs_trendmicro·2022-01-27·CVSS 10.0
[CRITICAL] How to Detect Apache Log4j Vulnerabilities
Red
## How to detect Apache Log4j vulnerabilities
Explore how to detect Apache Log4j (Log4Shell) vulnerabilities using cloud-native security tools.
By: Nitesh Surana Jan 27, 2022 Read time: ( words)
Save to Folio
In my previous blog, I reviewed how to detect Apache HTTP server exploitation from vulnerabilities in October. Weirdly enough, I wrote that article before the Apache Log4j (Log4Shell) news broke in December 2021 . So I’m back to write about how to detect the infamous Log4j vulnerability ( CVE-2021-44228 ) that allows attackers to achieve remote code execution on the victim servers using the vulnerable versions of the popular library in exposed web applications/services.
Source: Trend Micro
The above depicts a vulnerable public facing web service that logs the User-Agent fie
Tenable
Oracle January 2022 Critical Patch Update Addresses 266 CVEs
blogs_tenable·2022-01-19
Oracle January 2022 Critical Patch Update Addresses 266 CVEs
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Sentinelone
Log4j One Month On | Crimeware and Exploitation Roundup
blogs_sentinelone·2022-01-10·CVSS 7.5
CVE-2021-44228 [HIGH] Log4j One Month On | Crimeware and Exploitation Roundup
It has been 31 days since the initial public disclosure of a critical remote code execution (RCE) vulnerability in the Apache Log4j logging library that upended enterprise security at the close of 2021. In that time, since the initial CVE-2021-44228 (critical), we’ve already seen five more related CVEs
CVE-2021-45046 (critical)
CVE-2021-4104 (high)
CVE-2021-42550 (moderate)
CVE-2021-45105 (moderate)
CVE-2021-44832 (moderate))
and several updates to the library from 2.15.01 on December 9th to 2.17.1 on December 28th.
The importance of this class of vulnerabilities in such a ubiquitous library must not be forgotten with the next spin of the cyber news cycle: with millions of vulnerable devices, attacks are likely to continue for as long as such devices running unpatched software can b
Sentinelone
Log4j One Month On | Crimeware and Exploitation Roundup
blogs_sentinelone·2022-01-10·CVSS 7.5
CVE-2021-44228 [HIGH] Log4j One Month On | Crimeware and Exploitation Roundup
It has been 31 days since the initial public disclosure of a critical remote code execution (RCE) vulnerability in the Apache Log4j logging library that upended enterprise security at the close of 2021. In that time, since the initial CVE-2021-44228 (critical), we’ve already seen five more related CVEs
- CVE-2021-45046 (critical)
- CVE-2021-4104 (high)
- CVE-2021-42550 (moderate)
- CVE-2021-45105 (moderate)
- CVE-2021-44832 (moderate))
and several updates to the library from 2.15.01 on December 9th to 2.17.1 on December 28th.
The importance of this class of vulnerabilities in such a ubiquitous library must not be forgotten with the next spin of the cyber news cycle: with millions of vulnerable devices, attacks are likely to continue for as long as such devices running unpatched software
Qualys
How to Discover Log4Shell Vulnerabilities in Running Containers & Images
blogs_qualys·2021-12-27·CVSS 10.0
CVE-2021-44228 [CRITICAL] How to Discover Log4Shell Vulnerabilities in Running Containers & Images
If you run Java applications in containers, then it is critical that you check for Log4Shell vulnerabilities, given the high severity of this potential exploit. Qualys Container Security offers multiple methods to help you detect Log4Shell in your container environment. The Container Security sensor checks both running containers and container images for the following vulnerabilities:
QID 376157/ CVE-2021-44228 – Detect venerable log4 jar for versions at or below 2.14
QID 376178/ CVE-2021-45046 – Detect venerable log4 jar for versions at or below 2.15
QID 376194/ CVE-2021-45105 – Detect venerable log4 jar for versions at or below 2.16
Qualys highly recommends running a vulnerability scan against all your running containers because Java applications running the container are susceptible
Qualys
How to Discover Log4Shell Vulnerabilities in Running Containers & Images | Qualys
blogs_qualys·2021-12-27·CVSS 10.0
CVE-2021-44228 [CRITICAL] How to Discover Log4Shell Vulnerabilities in Running Containers & Images | Qualys
If you run Java applications in containers, then it is critical that you check for Log4Shell vulnerabilities, given the high severity of this potential exploit. Qualys Container Security offers multiple methods to help you detect Log4Shell in your container environment. The Container Security sensor checks both running containers and container images for the following vulnerabilities:
- QID 376157/CVE-2021-44228 – Detect venerable log4 jar for versions at or below 2.14
- QID 376178/CVE-2021-45046 – Detect venerable log4 jar for versions at or below 2.15
- QID 376194/CVE-2021-45105 – Detect venerable log4 jar for versions at or below 2.16
Qualys highly recommends running a vulnerability scan against all your running containers because Java applications running the container are susceptibl
Trendmicro
Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
blogs_trendmicro·2021-12-23
Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
Exploits & Vulnerabilities
## Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
In this entry we look into how Log4j vulnerabilities affect devices or properties embedded in or used for connected cars, specifically chargers, in-vehicle infotainment systems, and digital remotes for opening cars.
By: Sébastien Dudek 2021/12/23 Read time: ( words)
Save to Folio
Since its disclosure on Dec. 9, a vast number of articles have been written on the remote code execution (RCE) vulnerability in the library Apache Log4j — a reflection of its impact. The library is used by innumerable programs to easily release log statements without modifying the code. This means that it has an expansive attack surface, with Amazon, Apple, Cloudflare, Google, Tencent, Twitter, and many other
Trendmicro
Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
blogs_trendmicro·2021-12-23
Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
Sfruttamento vulnerabilità
## Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
In this entry we look into how Log4j vulnerabilities affect devices or properties embedded in or used for connected cars, specifically chargers, in-vehicle infotainment systems, and digital remotes for opening cars.
By: Sébastien Dudek Dec 23, 2021 Read time: ( words)
Save to Folio
Since its disclosure on Dec. 9, a vast number of articles have been written on the remote code execution (RCE) vulnerability in the library Apache Log4j — a reflection of its impact. The library is used by innumerable programs to easily release log statements without modifying the code. This means that it has an expansive attack surface, with Amazon, Apple, Cloudflare, Google, Tencent, Twitter, and many oth
Trendmicro
Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
blogs_trendmicro·2021-12-23
Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
Exploits y vulnerabilidades
## Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
In this entry we look into how Log4j vulnerabilities affect devices or properties embedded in or used for connected cars, specifically chargers, in-vehicle infotainment systems, and digital remotes for opening cars.
By: Sébastien Dudek Dec 23, 2021 Read time: ( words)
Save to Folio
Since its disclosure on Dec. 9, a vast number of articles have been written on the remote code execution (RCE) vulnerability in the library Apache Log4j — a reflection of its impact. The library is used by innumerable programs to easily release log statements without modifying the code. This means that it has an expansive attack surface, with Amazon, Apple, Cloudflare, Google, Tencent, Twitter, and many ot
Trendmicro
Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
blogs_trendmicro·2021-12-23
Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
Exploits & Vulnerabilities
# Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
In this entry we look into how Log4j vulnerabilities affect devices or properties embedded in or used for connected cars, specifically chargers, in-vehicle infotainment systems, and digital remotes for opening cars.
By: Sébastien Dudek
2021/12/23
Read time: ( words)
Save to Folio
Since its disclosure on Dec. 9, a vast number of articles have been written on the remote code execution (RCE) vulnerability in the library Apache Log4j — a reflection of its impact. The library is used by innumerable programs to easily release log statements without modifying the code. This means that it has an expansive attack surface, with Amazon, Apple, Cloudflare, Google, Tencent, Twitter, and many other
Trendmicro
Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
blogs_trendmicro·2021-12-23
Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
Exploits & Vulnerabilities
## Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
In this entry we look into how Log4j vulnerabilities affect devices or properties embedded in or used for connected cars, specifically chargers, in-vehicle infotainment systems, and digital remotes for opening cars.
By: Sébastien Dudek Dec 23, 2021 Read time: ( words)
Save to Folio
Since its disclosure on Dec. 9, a vast number of articles have been written on the remote code execution (RCE) vulnerability in the library Apache Log4j — a reflection of its impact. The library is used by innumerable programs to easily release log statements without modifying the code. This means that it has an expansive attack surface, with Amazon, Apple, Cloudflare, Google, Tencent, Twitter, and many oth
Trendmicro
Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
blogs_trendmicro·2021-12-23
Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
Ausnutzung von Schwachstellen
## Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
In this entry we look into how Log4j vulnerabilities affect devices or properties embedded in or used for connected cars, specifically chargers, in-vehicle infotainment systems, and digital remotes for opening cars.
By: Sébastien Dudek Dec 23, 2021 Read time: ( words)
Save to Folio
Since its disclosure on Dec. 9, a vast number of articles have been written on the remote code execution (RCE) vulnerability in the library Apache Log4j — a reflection of its impact. The library is used by innumerable programs to easily release log statements without modifying the code. This means that it has an expansive attack surface, with Amazon, Apple, Cloudflare, Google, Tencent, Twitter, and many
Fortinet
Critical Apache Log4j Vulnerability Updates | FortiGuard Labs
blogs_fortinet·2021-12-21·CVSS 10.0
CVE-2021-44228 [CRITICAL] Critical Apache Log4j Vulnerability Updates | FortiGuard Labs
FORTIGUARD LABS THREAT RESEARCH
Critical Apache Log4j Vulnerability Updates
By Shunichi Imano, James Slaughter, and Geri Revay | December 21, 2021
Beginning December 9th, most of the internet-connected world was forced to reckon with a critical new vulnerability discovered in the Apache Log4j framework deployed in countless servers. Officially labeled CVE-2021-44228, but colloquially known as “Log4Shell”, this vulnerability is both trivial to exploit and allows for full remote code execution on a target system. This has earned the vulnerability a CVSS score of 10 – the maximum.
On December 14th, the Apache Software Foundation revealed a second Log4j vulnerability (CVE-2021-45046). It was initially identified as a Denial-of-Service (DoS) vulnerability with a CVSS score of 3.7 and modera
Wiz
Log4Shell 10 days later: Enterprises halfway through patching | Wiz Blog
blogs_wiz·2021-12-20·CVSS 10.0
CVE-2021-44228 [CRITICAL] Log4Shell 10 days later: Enterprises halfway through patching | Wiz Blog
Ten days after the critical vulnerability called Log4Shell (CVE-2021-44228) first set the Internet ablaze, organizations are almost halfway through remediating the issue in their cloud environments. See the full technical details here .
Wiz and EY (Ernest & Young) analyzed more than 200 enterprise cloud environments with thousands of cloud accounts. The results were striking: While 93% of all cloud environments are at risk from Log4Shell, on average organizations have patched 45% of their vulnerable cloud resources by Day 10 (December 20, 2021). Note that while our data only accounts for Log4Shell in cloud environments, this vulnerability also affects on-premise networks.
To give organizations a benchmark for their own efforts, we calculated the average patch rate of organizations in eac
Securelist
Answering Log4Shell-related questions
blogs_securelist·2021-12-20·CVSS 10.0
CVE-2021-44228 [CRITICAL] Answering Log4Shell-related questions
Table of Contents
Important notice
A summary of the Log4Shell situation
The Log4Shell vulnerability webinar FAQ
Authors
Kaspersky
## Important notice
On December 18th, Log4j version 2.17.0 was released to address open vulnerabilities. It is highly recommended to update your systems as soon as possible.
History of the Log4j library vulnerabilities
CVE-2021-44228 (initial vulnerability) – partially fixed in 2.15.0
CVE-2021-45046 (present in Log4j 2.15.0) – fixed in 2.16.0
CVE-2021-45105 (present in Log4j 2.16.0) – fixed in 2.17.0
## A summary of the Log4Shell situation
On December 9th, a Chinese researcher posted his now-monumental discovery on Twitter: there was a Remote Code Execution vulnerability in the popular Apache Log4j library. This library is used in millions of commer
Securelist
Answering Log4Shell-related questions
blogs_securelist·2021-12-20·CVSS 10.0
CVE-2021-44228 [CRITICAL] Answering Log4Shell-related questions
Table of Contents
- Important notice
- A summary of the Log4Shell situation
- The Log4Shell vulnerability webinar FAQ
Authors
- Kaspersky
## Important notice
On December 18th, Log4j version 2.17.0 was released to address open vulnerabilities. It is highly recommended to update your systems as soon as possible.
History of the Log4j library vulnerabilities
- CVE-2021-44228 (initial vulnerability) – partially fixed in 2.15.0
- CVE-2021-45046 (present in Log4j 2.15.0) – fixed in 2.16.0
- CVE-2021-45105 (present in Log4j 2.16.0) – fixed in 2.17.0
## A summary of the Log4Shell situation
On December 9th, a Chinese researcher posted his now-monumental discovery on Twitter: there was a Remote Code Execution vulnerability in the popular Apache Log4j library. This library is used in million
Wiz
Log4Shell 10 days later: Enterprises halfway through patching | Wiz Blog
blogs_wiz·2021-12-20·CVSS 10.0
CVE-2021-44228 [CRITICAL] Log4Shell 10 days later: Enterprises halfway through patching | Wiz Blog
Ten days after the critical vulnerability called Log4Shell (CVE-2021-44228) first set the Internet ablaze, organizations are almost halfway through remediating the issue in their cloud environments. See the full technical details here.
Wiz and EY (Ernest & Young) analyzed more than 200 enterprise cloud environments with thousands of cloud accounts. The results were striking: While 93% of all cloud environments are at risk from Log4Shell, on average organizations have patched 45% of their vulnerable cloud resources by Day 10 (December 20, 2021). Note that while our data only accounts for Log4Shell in cloud environments, this vulnerability also affects on-premise networks.
To give organizations a benchmark for their own efforts, we calculated the average patch rate of organizations in each
Qualys
New Options Profiles for Log4Shell Detection | Qualys
blogs_qualys·2021-12-20
New Options Profiles for Log4Shell Detection | Qualys
#### Table of Contents
- Importing Option Profiles
- Search Lists
We have now added two new option profiles to our library for Log4Shell vulnerabilities. Option profiles define the settings you want to use for your scan. These new option profiles are tuned to quickly detect the Log4Shell vulnerability on assets in your environment.
The following two pre-configured option profiles are now available in the library to help you get started:
1. Log4Shell – Authenticated Scan
2. Log4Shell – Unauthenticated Scan
You can import these profiles into your account and use them as-is or edit them as needed.
## Importing Option Profiles
To import our option profiles, go to Scans > Option Profiles > New and select Import from Library.
Choose from the Log4Shell – Authenticated Scan or Log4Shell –
Qualys
New Options Profiles for Log4Shell Detection
blogs_qualys·2021-12-20
New Options Profiles for Log4Shell Detection
## Table of Contents
Importing Option Profiles
Search Lists
We have now added two new option profiles to our library for Log4Shell vulnerabilities. Option profiles define the settings you want to use for your scan. These new option profiles are tuned to quickly detect the Log4Shell vulnerability on assets in your environment.
The following two pre-configured option profiles are now available in the library to help you get started:
Log4Shell – Authenticated Scan
Log4Shell – Unauthenticated Scan
You can import these profiles into your account and use them as-is or edit them as needed.
## Importing Option Profiles
To import our option profiles, go to Scans > Option Profiles > New and select Import from Library .
Choose from the Log4Shell – Authenticated Scan or Log4Shell – Unauthent
Tenable
CVE-2021-44228, CVE-2021-45046, CVE-2021-4104: Frequently Asked Questions About Log4Shell and Associated Vulnerabilities
blogs_tenable·2021-12-17·CVSS 7.5
[HIGH] CVE-2021-44228, CVE-2021-45046, CVE-2021-4104: Frequently Asked Questions About Log4Shell and Associated Vulnerabilities
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Management (CSPM)
Compliance
Cyber insurance
Data Security Posture Management (DSPM)
Google Cloud security
Infrastructure as Code (IaC) security
Kubernetes Security Pos
Qualys
Log4Shell Log4j Vulnerability Test | CVE-2021-45046 Detection | Qualys
blogs_qualys·2021-12-15·CVSS 10.0
CVE-2021-44228 [CRITICAL] Log4Shell Log4j Vulnerability Test | CVE-2021-45046 Detection | Qualys
#### Table of Contents
- About CVE-2021-44228
- Detecting the Vulnerability with Qualys WAS
- WAS Log4Shell Detection Methodology with Qualys Periscope
- Scan Configurations :
- About CVE-2021-45046
- About CVE-2021-44832
- Solution
- Credits
- References:
- Contributors
On December 09, 2021, a critical remote code execution vulnerability was identified in Apache Log4j2 after proof-of-concepts were leaked publicly, affecting Apache Log4j 2.x <= 2.15.0-rc1. The vulnerability is being tracked as CVE-2021-44228 with CVSSv3 10 score and affects numerous applications which are using the Log4j2 library.
#### Free Trial
### Quickly Identify Your Vulnerable Web Applications Using Our Cloud Platform
Get the Free Trial
Successful exploitation of this vulnerability could allow a remote attacker
Qualys
Is Your Web Application Exploitable By Log4Shell Vulnerability?
blogs_qualys·2021-12-15·CVSS 10.0
CVE-2021-44228 [CRITICAL] Is Your Web Application Exploitable By Log4Shell Vulnerability?
## Table of Contents
About CVE-2021-44228
Detecting the Vulnerability with Qualys WAS
WAS Log4Shell Detection Methodology with Qualys Periscope
Scan Configurations :
About CVE-2021-45046
About CVE-2021-44832
Solution
Credits
References:
Contributors
On December 09, 2021, a critical remote code execution vulnerability was identified in Apache Log4j2 after proof-of-concepts were leaked publicly, affecting Apache Log4j 2.x <= 2.15.0-rc1. The vulnerability is being tracked as CVE-2021-44228 with CVSSv3 10 score and affects numerous applications which are using the Log4j2 library.
## Free Trial
## Quickly Identify Your Vulnerable Web Applications Using Our Cloud Platform
Successful exploitation of this vulnerability could allow a remote attacker to download and execute arbitrary c
Trendmicro
Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
blogs_trendmicro·2021-12-13·CVSS 10.0
CVE-2021-44228 [CRITICAL] Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
Exploits y vulnerabilidades
## Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
Log4Shell, also known as CVE-2021-44228, was first reported privately to Apache on November 24 and was patched on December 9. It affects Apache Struts, Apache Solr, Apache Druid, Elasticsearch, Apache Dubbo, and VMware vCenter.
By: Ranga Duraisamy, Ashish Verma, Miguel Carlo Ang Dec 13, 2021 Read time: ( words)
Save to Folio
Update as of Dec 28, 2021: The latest Log4j vulnerability, CVE-2021-44832, has now been addressed in the Log4j 2.17.1 release .
Update as of Dec 22, 2021: The Impact section has been updated with information on the various payloads discovered after the start of the Log4Shell attacks.
Update as of Dec. 19, 2021: Our researchers at Zero Day Initiative published
Trendmicro
Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
blogs_trendmicro·2021-12-13·CVSS 10.0
CVE-2021-44228 [CRITICAL] Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
Exploits & Vulnerabilities
## Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
Log4Shell, also known as CVE-2021-44228, was first reported privately to Apache on November 24 and was patched on December 9. It affects Apache Struts, Apache Solr, Apache Druid, Elasticsearch, Apache Dubbo, and VMware vCenter.
By: Ranga Duraisamy, Ashish Verma, Miguel Carlo Ang 2021/12/13 Read time: ( words)
Save to Folio
Update as of Dec 28, 2021: The latest Log4j vulnerability, CVE-2021-44832, has now been addressed in the Log4j 2.17.1 release .
Update as of Dec 22, 2021: The Impact section has been updated with information on the various payloads discovered after the start of the Log4Shell attacks.
Update as of Dec. 19, 2021: Our researchers at Zero Day Initiative published a
Trendmicro
Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
blogs_trendmicro·2021-12-13·CVSS 10.0
CVE-2021-44228 [CRITICAL] Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
Sfruttamento vulnerabilità
## Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
Log4Shell, also known as CVE-2021-44228, was first reported privately to Apache on November 24 and was patched on December 9. It affects Apache Struts, Apache Solr, Apache Druid, Elasticsearch, Apache Dubbo, and VMware vCenter.
By: Ranga Duraisamy, Ashish Verma, Miguel Carlo Ang Dec 13, 2021 Read time: ( words)
Save to Folio
Update as of Dec 28, 2021: The latest Log4j vulnerability, CVE-2021-44832, has now been addressed in the Log4j 2.17.1 release .
Update as of Dec 22, 2021: The Impact section has been updated with information on the various payloads discovered after the start of the Log4Shell attacks.
Update as of Dec. 19, 2021: Our researchers at Zero Day Initiative published
Trendmicro
Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
blogs_trendmicro·2021-12-13·CVSS 10.0
CVE-2021-44228 [CRITICAL] Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
Exploits & Vulnerabilities
## Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
Log4Shell, also known as CVE-2021-44228, was first reported privately to Apache on November 24 and was patched on December 9. It affects Apache Struts, Apache Solr, Apache Druid, Elasticsearch, Apache Dubbo, and VMware vCenter.
By: Ranga Duraisamy, Ashish Verma, Miguel Carlo Ang Dec 13, 2021 Read time: ( words)
Save to Folio
Update as of Dec 28, 2021: The latest Log4j vulnerability, CVE-2021-44832, has now been addressed in the Log4j 2.17.1 release .
Update as of Dec 22, 2021: The Impact section has been updated with information on the various payloads discovered after the start of the Log4Shell attacks.
Update as of Dec. 19, 2021: Our researchers at Zero Day Initiative published
Trendmicro
Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
blogs_trendmicro·2021-12-13·CVSS 10.0
CVE-2021-44228 [CRITICAL] Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
Exploits & Vulnerabilities
# Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
Log4Shell, also known as CVE-2021-44228, was first reported privately to Apache on November 24 and was patched on December 9. It affects Apache Struts, Apache Solr, Apache Druid, Elasticsearch, Apache Dubbo, and VMware vCenter.
By: Ranga Duraisamy, Ashish Verma, Miguel Carlo Ang
2021/12/13
Read time: ( words)
Save to Folio
Update as of Dec 28, 2021: The latest Log4j vulnerability, CVE-2021-44832, has now been addressed in the Log4j 2.17.1 release.
Update as of Dec 22, 2021: The Impact section has been updated with information on the various payloads discovered after the start of the Log4Shell attacks.
Update as of Dec. 19, 2021: Our researchers at Zero Day Initiative published a g
Fortinet
Apache Log4j Vulnerability | Fortinet Blog
blogs_fortinet·2021-12-12
Apache Log4j Vulnerability | Fortinet Blog
PSIRT BLOGS
Apache Log4j Vulnerability
By Carl Windsor | December 12, 2021
Apache Log4j Vulnerability Defined
Apache Log4j is a Java-based logging audit framework and Apache Log4j2 1.14.1 and below are susceptible to a remote code execution vulnerability where an attacker can leverage this vulnerability to take full control of a machine.
This module is a prerequisite for other software which means it can be found in many products and is trivial to exploit. It is critical that organizations take immediate action to inventory their systems and prioritize remediation.
Impacted Versions
Apache Log4j 2.x <= 2.15.0-rc1
CVSS: 10 (CRITICAL)
Apache Log4j Vulnerability Overview
Until a few days ago, most people would not have had any knowledge of the Log4j2 software. However, this little-know
Huntress
Critical RCE Vulnerability: log4j - CVE-2021-44228 | Huntress
blogs_huntress·2021-12-10·CVSS 10.0
CVE-2021-44228 [CRITICAL] Critical RCE Vulnerability: log4j - CVE-2021-44228 | Huntress
Our team is investigating CVE-2021-44228, a critical vulnerability that’s affecting a Java logging package log4j which is used in a significant amount of software, including Apache, Apple iCloud, Steam, Minecraft and others. Huntress is actively uncovering the effects of this vulnerability and will be frequently updating this page.
At this point, we have not identified an impact to The Huntress Security Platform, but our teams are diligently checking to ensure all instances of our back-end are safe and will be taking appropriate action as needed.
If your organization uses the log4j library, you should upgrade to log4j 2.17.1 immediately. Be sure that your Java instance is up-to-date; however, it’s worth noting that this isn’t an across-the-board solution. You may need to wait until your
Talos
Threat Advisory: Critical Apache Log4j vulnerability being exploited in the wild
blogs_talos·2021-12-10·CVSS 10.0
[CRITICAL] Threat Advisory: Critical Apache Log4j vulnerability being exploited in the wild
## Update History
DateDescription of UpdatesDec. 20, 2021
Additional coverage and IOCs; additional detection capabilities for customers via Cisco Global Threat Alerts.
Dec. 18, 2021
Additional mitigation guidance; updated coverage information.
Dec. 17, 2021
Added additional vulnerability and mitigation information; added section on guidance for developers; timeline.
Dec. 16, 2021
Added additional vulnerability and mitigation information; added event timeline; relevant advisory information.
Dec. 15, 2021
Added observations on exploitation activity; updated coverage information. Additional IOCs.
Dec. 14, 2021
Added new CVE details; updated coverage information; additional mitigation guidance; additional threat vectors; Additional IOCs.
Dec. 13, 2021
Added additional vulnerability informatio
Talos
Threat Advisory: Critical Apache Log4j vulnerability being exploited in the wild
blogs_talos·2021-12-10·CVSS 10.0
[CRITICAL] Threat Advisory: Critical Apache Log4j vulnerability being exploited in the wild
## Threat Advisory: Critical Apache Log4j vulnerability being exploited in the wild
## Update History
Dec. 20, 2021
Additional coverage and IOCs; additional detection capabilities for customers via Cisco Global Threat Alerts.
Dec. 18, 2021
Additional mitigation guidance; updated coverage information.
Dec. 17, 2021
Added additional vulnerability and mitigation information; added section on guidance for developers; timeline.
Dec. 16, 2021
Added additional vulnerability and mitigation information; added event timeline; relevant advisory information.
Dec. 15, 2021
Added observations on exploitation activity; updated coverage information. Additional IOCs.
Dec. 14, 2021
Added new CVE details; updated coverage information; additional mitigation guidance; additional threat vectors; Ad
Unit42
Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021-44228) (Updated)
blogs_unit42·2021-12-10·CVSS 10.0
CVE-2021-44228 [CRITICAL] Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021-44228) (Updated)
## Executive Summary
On Dec. 9, 2021, a remote code execution (RCE) vulnerability in Apache Log4j 2 was identified being exploited in the wild. Public proof of concept (PoC) code was released and subsequent investigation revealed that exploitation was incredibly easy to perform. By submitting a specially crafted request to a vulnerable system, depending on how the system is configured, an attacker is able to instruct that system to download and subsequently execute a malicious payload. Due to the discovery of this exploit being so recent, there are still many servers, both on-premises and within cloud environments, that have yet to be patched. Like many high severity RCE exploits, thus far, massive scanning activity for CVE-2021-44228 has begun on the internet with the intent of seeking o
Huntress
Critical RCE Vulnerability Updates (log4j - CVE-2021-44228) | Huntress
blogs_huntress·2021-12-10·CVSS 10.0
CVE-2021-44228 [CRITICAL] Critical RCE Vulnerability Updates (log4j - CVE-2021-44228) | Huntress
Our team is investigating CVE-2021-44228, a critical vulnerability that’s affecting a Java logging package log4j which is used in a significant amount of software, including Apache, Apple iCloud, Steam, Minecraft and others. Huntress is actively uncovering the effects of this vulnerability and will be frequently updating this page.
At this point, we have not identified an impact to The Huntress Security Platform, but our teams are diligently checking to ensure all instances of our back-end are safe and will be taking appropriate action as needed.
If your organization uses the log4j library, you should upgrade to log4j 2.17.1 immediately. Be sure that your Java instance is up-to-date; however, it’s worth noting that this isn’t an across-the-board solution. You may need to wait until your
Unit42
Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021-44228) (Updated)
blogs_unit42·2021-12-10·CVSS 9.8
CVE-2021-44228 [CRITICAL] Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021-44228) (Updated)
Threat Research Center
Threat Research
Vulnerabilities
## Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021-44228) (Updated)
Tao Yan
Qi Deng
Haozhe Zhang
Yu Fu
Josh Grunzweig
Mike Harbison
Robert Falcone
Published: December 10, 2021
Threat Research
Vulnerabilities
Apache Log4j
CVE-2017-5645
CVE-2019-17571
CVE-2021-44228
CVE-2021-44832
CVE-2021-45046
CVE-2021-45105
Denial of service
Exploit
Log4j
Log4j 2
RCE
## Executive Summary
On Dec. 9, 2021, a remote code execution (RCE) vulnerability in Apache Log4j 2 was identified being exploited in the wild. Public proof of concept (PoC) code was released and subsequent investigation revealed that exploitation was incredibly easy to perform. By submitting a specially crafted request to a vu
Huntress
Critical RCE Vulnerability Updates (log4j - CVE-2021-44228) | Huntress
blogs_huntress·CVSS 10.0
CVE-2021-44228 [CRITICAL] Critical RCE Vulnerability Updates (log4j - CVE-2021-44228) | Huntress
Our team is investigating CVE-2021-44228, a critical vulnerability that’s affecting a Java logging package log4j which is used in a significant amount of software, including Apache, Apple iCloud, Steam, Minecraft and others. Huntress is actively uncovering the effects of this vulnerability and will be frequently updating this page.
At this point, we have not identified an impact to The Huntress Security Platform, but our teams are diligently checking to ensure all instances of our back-end are safe and will be taking appropriate action as needed.
If your organization uses the log4j library, you should upgrade to log4j 2.17.1 immediately. Be sure that your Java instance is up-to-date; however, it’s worth noting that this isn’t an across-the-board solution. You may need to wait until your
Trendmicro
Cos'è la vulnerability Apache Log4J (Log4Shell)?
blogs_trendmicro
Cos'è la vulnerability Apache Log4J (Log4Shell)?
Collega la protezione dalle minacce e la gestione del rischio informatico
Scopri le soluzioni dei partner approvate da Trend per la nostra piattaforma leader
Il leader nella gestione dell'esposizione: trasformare la visibilità del rischio informatico in una sicurezza decisiva e proattiva
Blocca gli aggressori con una visibilità ineguagliabile, basata sull'intelligenza di XDR, Agentic SIEM e Agentic SOAR, che non lascia agli aggressori alcun posto dove nascondersi.
La piattaforma di sicurezza cloud più affidabile per sviluppatori, team di sicurezza e aziende
Estensione della visibilità al cloud e semplificazione delle indagini SOC
Semplifica la sicurezza delle applicazioni native per il cloud con scansione avanzata delle immagini dei container, controllo dell'accesso basato su criteri
Trendmicro
Was ist die Apache Log4j/Log4Shell vulnerability?
blogs_trendmicro
Was ist die Apache Log4j/Log4Shell vulnerability?
Verbindet den Schutz vor Bedrohungen und das Management des Cyberrisikos
Spitzenreiter im Bereich Exposure Management – macht Cyberrisiken transparent und sorgt für entschlossene, proaktive Sicherheit
Stoppen Sie Angreifer mit unübertroffener Transparenz, unterstützt durch XDR, agentenbasiertes SIEM und SOAR – damit Angreifer sich nirgendwo mehr verstecken können
Nutzen Sie die bewährte Cloud-Sicherheitsplattform für Entwickler, Sicherheitsteams und Unternehmen.
Erweiterung der Transparenz auf die Cloud und Optimierung von SOC-Untersuchungen
Vereinfachen Sie die Sicherheit für Ihre Cloud-nativen Anwendungen durch erweitertes Container-Image-Scanning, richtlinienbasierte Zugriffssteuerung und Container-Laufzeitschutz.
Schützen Sie Anwendungsworkflows und Cloud-Speicher vor neuen und k
Huntress
Critical RCE Vulnerability: log4j - CVE-2021-44228 | Huntress
blogs_huntress·CVSS 10.0
CVE-2021-44228 [CRITICAL] Critical RCE Vulnerability: log4j - CVE-2021-44228 | Huntress
Our team is investigating CVE-2021-44228, a critical vulnerability that’s affecting a Java logging package log4j which is used in a significant amount of software, including Apache, Apple iCloud, Steam, Minecraft and others. Huntress is actively uncovering the effects of this vulnerability and will be frequently updating this page.
At this point, we have not identified an impact to The Huntress Security Platform, but our teams are diligently checking to ensure all instances of our back-end are safe and will be taking appropriate action as needed.
If your organization uses the log4j library, you should upgrade to log4j 2.17.1 immediately. Be sure that your Java instance is up-to-date; however, it’s worth noting that this isn’t an across-the-board solution. You may need to wait until your
Trendmicro
What Is Apache Log4J (Log4Shell) Vulnerability?
blogs_trendmicro
What Is Apache Log4J (Log4Shell) Vulnerability?
Bridge threat protection and cyber risk management
Browse Trend-approved partner solutions for our leading platform
Your environment, your choice – deploy Trend Vision One™ as SaaS or customer hosted
The leader in Exposure Management – turning cyber risk visibility into decisive, proactive security
Stop adversaries with unrivaled visibility, powered by the intelligence of XDR, Agentic SIEM, and Agentic SOAR to leave attackers with nowhere left to hide
The most trusted cloud security platform for developers, security teams, and businesses
Extend visibility to the cloud and streamline SOC investigations
Secure your data center, cloud, and containers without compromising performance by leveraging a cloud security platform with CNAPP capabilities
Simplify security for your cloud-native
Trendmicro
¿Qué es la vulnerabilidad de Apache Log4J (Log4Shell)?
blogs_trendmicro
¿Qué es la vulnerabilidad de Apache Log4J (Log4Shell)?
Elimine la separación entre la protección frente a amenazas y la gestión del riesgo cibernético
El líder en gestión de exposiciones: convirtiendo la visibilidad de los ciberriesgos en una seguridad proactiva y decisiva
Detenga a los adversarios con una visibilidad sin igual, impulsada por la inteligencia de XDR, SIEM agente y SOAR agente para dejar a los atacantes en ningún lugar
La plataforma de seguridad en la nube más fiable para desarrolladores, equipos de seguridad y empresas
Amplíe la visibilidad de la nube y optimice las investigaciones del SOC
Simplifique la seguridad de sus aplicaciones nativas en la nube con un avanzado análisis de imágenes de contenedor, control de admisión con base en política y protección de tiempo de ejecución del contenedor
Proteja el flujo de trabajo
Trendmicro
What Is Apache Log4J (Log4Shell) Vulnerability?
blogs_trendmicro
What Is Apache Log4J (Log4Shell) Vulnerability?
Bridge threat protection and cyber risk management
Browse Trend-approved partner solutions for our leading platform
Your environment, your choice – deploy Trend Vision One™ as SaaS or customer hosted
The leader in Exposure Management – turning cyber risk visibility into decisive, proactive security
Stop adversaries with unrivaled visibility, powered by the intelligence of XDR, Agentic SIEM, and Agentic SOAR to leave attackers with nowhere left to hide
The most trusted cloud security platform for developers, security teams, and businesses
Extend visibility to the cloud and streamline SOC investigations
Secure your data center, cloud, and containers without compromising performance by leveraging a cloud security platform with CNAPP capabilities
Simplify security for your cloud-native
Trendmicro
What Is Apache Log4J (Log4Shell) Vulnerability?
blogs_trendmicro
What Is Apache Log4J (Log4Shell) Vulnerability?
Bridge threat protection and cyber risk management
Browse Trend-approved partner solutions for our leading platform
Your environment, your choice – deploy Trend Vision One™ as SaaS or customer hosted
The leader in Exposure Management – turning cyber risk visibility into decisive, proactive security
Stop adversaries with unrivaled visibility, powered by the intelligence of XDR, Agentic SIEM, and Agentic SOAR to leave attackers with nowhere left to hide
The most trusted cloud security platform for developers, security teams, and businesses
Extend visibility to the cloud and streamline SOC investigations
Secure your data centre, cloud, and containers without compromising performance by leveraging a cloud security platform with CNAPP capabilities
Simplify security for your cloud-native
Greynoiseio
Log4j Analysis: What to Do
blogs_greynoiseio·CVSS 10.0
[CRITICAL] Log4j Analysis: What to Do
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Bugzilla
CVE-2021-45105 log4j-core: DoS in log4j 2.x with Thread Context Map (MDC) input data contains a recursive lookup and context lookup pattern
bugzilla·2021-12-20·CVSS 5.9
CVE-2021-45105 [MEDIUM] CVE-2021-45105 log4j-core: DoS in log4j 2.x with Thread Context Map (MDC) input data contains a recursive lookup and context lookup pattern
CVE-2021-45105 log4j-core: DoS in log4j 2.x with Thread Context Map (MDC) input data contains a recursive lookup and context lookup pattern
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 did not protect from uncontrolled recursion from self-referential lookups. When the logging configuration uses a non-default Pattern Layout with a Context Lookup (for example, $${ctx:loginId}), attackers with control over Thread Context Map (MDC) input data can craft malicious input data that contains a recursive lookup, resulting in a StackOverflowError that will terminate the process. This is also known as a DOS (Denial of Service) attack.
This issue is being tracked as LOG4J2-3230
Mitigation:
Implement one of the following mitigation techniques:
* Java 8 (or later) users should upgrade to release
arXiv
The Road of Adaptive AI for Precision in Cybersecurity
arxiv_fulltext·2025-12-05
The Road of Adaptive AI for Precision in Cybersecurity
## Abstract
Cybersecurity's evolving complexity presents unique challenges and opportunities for AI research and practice. This paper shares key lessons and insights from designing, building, and operating production-grade GenAI pipelines in cybersecurity, with a focus on the continual adaptation required to keep pace with ever-shifting knowledge bases, tooling, and threats.
Our goal is to provide an actionable perspective for AI practitioners and industry stakeholders navigating the frontier of GenAI for cybersecurity, with particular attention to how different adaptation mechanisms complement each other in end-to-end systems.
We present practical guidance derived from real-world deployments, propose best practices for leveraging retrieval- and model-level adaptation, and highlight ope
arXiv
Hacktivism Goes Orbital: Investigating NB65's Breach of ROSCOSMOS
arxiv_fulltext·2024-02-15
Hacktivism Goes Orbital: Investigating NB65's Breach of ROSCOSMOS
## Abstract
In March of 2022, Network battalion 65 (NB65), a hacktivist affiliate of Anonymous, publicly asserted its successful breach of ROSCOSMOS's satellite imaging capabilities in response to Russia's invasion of Ukraine. NB65 disseminated a series of primary sources as substantiation, proclaiming the incapacitation of ROSCOSMOS's space-based vehicle monitoring system and doxing of related proprietary documentation. Despite the profound implications of hacktivist incursions into the space sector, the event has garnered limited attention due to the obscurity of technical attack vectors and ROCOSMOS's denial of NB65's allegations. Through analysis of NB65's released primary sources of evidence, this paper uncovers the probable vulnerabilities and exploits that enabled the alleged breac
arXiv
Attack Techniques and Threat Identification for Vulnerabilities
arxiv_fulltext·2022-06-22
Attack Techniques and Threat Identification for Vulnerabilities
Attack Techniques and Threat Identification for Vulnerabilities
Constantin Adam
Muhammed Fatih Bulut
Daby Sow
cmadam, mfbulut, [email protected]
IBM T.J. Watson Research Center
Yorktown Heights
NY
USA
Steven Ocepek
Chris Bedell
steve.ocepek, [email protected]
IBM Security X-Force Red
USA
Lilian Ngweta
[email protected]
Rensselaer Polytechnic Institute
Troy
NY
USA
Adam and Bulut, et al.
## Abstract
Modern organizations struggle with what is often considered an insurmountable number of vulnerabilities that are discovered and reported by their network and application vulnerability scanners. Therefore, prioritization and focus become critical, to spend their limited time on the highest risk vulnerabilities. In doing this, it is important for these organizations not only to
arXiv
The Race to the Vulnerable: Measuring the Log4j Shell Incident
arxiv_fulltext·2022-06-07
The Race to the Vulnerable: Measuring the Log4j Shell Incident
IEEEexample:BSTcontrolNew
5pt
textblock0.8(0.1,0.02)
If you cite this paper, please use the TMA reference:
R. Hiesgen, M. Nawrocki, T. C. Schmidt, and M. Wählisch.
2022. The Race to the Vulnerable: Measuring the Log4j Shell Incident.
In Proc. of Network Traffic Measurement and Analysis Conference (TMA ’22).
IFIP, 9 pages.
textblock
The Race to the Vulnerable:
Measuring the Log4j Shell Incident
Raphael Hiesgen
HAW Hamburg\ [email protected]
Marcin Nawrocki
Freie Universit\"at Berlin\ [email protected]
Thomas C. Schmidt
HAW Hamburg\ [email protected]
Matthias W\"ahlisch
Freie Universit\"at Berlin\ [email protected]
## Abstract
The critical remote-code-execution (RCE) Log4Shell is a severe vulnerability that was disclosed to the public on December 10, 2021. It
http://www.openwall.com/lists/oss-security/2021/12/19/1https://cert-portal.siemens.com/productcert/pdf/ssa-479842.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-501673.pdfhttps://logging.apache.org/log4j/2.x/security.htmlhttps://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0032https://security.netapp.com/advisory/ntap-20211218-0001/https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbdhttps://www.debian.org/security/2021/dsa-5024https://www.kb.cert.org/vuls/id/930724https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.zerodayinitiative.com/advisories/ZDI-21-1541/http://www.openwall.com/lists/oss-security/2021/12/19/1https://cert-portal.siemens.com/productcert/pdf/ssa-479842.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-501673.pdfhttps://logging.apache.org/log4j/2.x/security.htmlhttps://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0032https://security.netapp.com/advisory/ntap-20211218-0001/https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbdhttps://www.debian.org/security/2021/dsa-5024https://www.kb.cert.org/vuls/id/930724https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.zerodayinitiative.com/advisories/ZDI-21-1541/
2021-12-18
Published
Exploited in the wild