CVE-2021-44228
Description
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.logging.log4j:log4j-coreMaven | >= 2.13.0, < 2.15.0 | 2.15.0 |
org.apache.logging.log4j:log4j-coreMaven | >= 2.0-beta9, < 2.3.1 | 2.3.1 |
org.apache.logging.log4j:log4j-coreMaven | >= 2.4, < 2.12.2 | 2.12.2 |
com.guicedee.services:log4j-coreMaven | <= 1.2.1.2-jre17 | — |
org.ops4j.pax.logging:pax-logging-log4j2Maven | >= 1.8.0, < 1.9.2 | 1.9.2 |
org.ops4j.pax.logging:pax-logging-log4j2Maven | >= 1.10.0, < 1.10.8 | 1.10.8 |
org.ops4j.pax.logging:pax-logging-log4j2Maven | >= 1.11.0, < 1.11.10 | 1.11.10 |
org.ops4j.pax.logging:pax-logging-log4j2Maven | >= 2.0.0, < 2.0.11 | 2.0.11 |
Affected products
381- cpe:2.3:a:cisco:advanced_malware_protection_virtual_private_cloud_appliance:*:*:*:*:*:*:*:*Range: <3.5.4
cpe:2.3:a:cisco:automated_subsea_tuning:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:cisco:automated_subsea_tuning:*:*:*:*:*:*:*:*range: <2.1.0
- cpe:2.3:a:cisco:automated_subsea_tuning:02.01.00:*:*:*:*:*:*:*
cpe:2.3:a:cisco:broadworks:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:cisco:broadworks:*:*:*:*:*:*:*:*range: <2021.11_1.162
- cpe:2.3:a:cisco:broadworks:-:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:business_process_automation:*:*:*:*:*:*:*:*Range: <3.0.000.115
- cpe:2.3:a:cisco:cloudcenter_cost_optimizer:*:*:*:*:*:*:*:*Range: <5.5.2
cpe:2.3:a:cisco:cloudcenter_suite:4.10.0.15:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:cisco:cloudcenter_suite:4.10.0.15:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:cloudcenter_suite:5.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:cloudcenter_suite:5.4.1:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:cloudcenter_suite:5.5.0:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:cloudcenter_suite:5.5.1:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:cloudcenter_suite_admin:*:*:*:*:*:*:*:*Range: <5.3.1
- cpe:2.3:a:cisco:cloudcenter_workload_manager:*:*:*:*:*:*:*:*Range: <5.5.2
cpe:2.3:a:cisco:common_services_platform_collector:*:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:cisco:common_services_platform_collector:*:*:*:*:*:*:*:*range: <2.9.1.3
- cpe:2.3:a:cisco:common_services_platform_collector:002.009\(000.000\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:common_services_platform_collector:002.009\(000.001\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:common_services_platform_collector:002.009\(000.002\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:common_services_platform_collector:002.009\(001.000\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:common_services_platform_collector:002.009\(001.001\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:common_services_platform_collector:002.009\(001.002\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:common_services_platform_collector:002.010\(000.000\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:connected_mobile_experiences:-:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:contact_center_domain_manager:*:*:*:*:*:*:*:*Range: <12.5\(1\)
- cpe:2.3:a:cisco:contact_center_management_portal:*:*:*:*:*:*:*:*Range: <12.5\(1\)
cpe:2.3:a:cisco:crosswork_data_gateway:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:cisco:crosswork_data_gateway:*:*:*:*:*:*:*:*range: <2.0.2
- cpe:2.3:a:cisco:crosswork_data_gateway:3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:crosswork_network_automation:-:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:cisco:crosswork_network_automation:-:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:crosswork_network_automation:2.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:crosswork_network_automation:3.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:crosswork_network_automation:4.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:crosswork_network_automation:4.1.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:crosswork_network_controller:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:cisco:crosswork_network_controller:*:*:*:*:*:*:*:*range: <2.0.1
- cpe:2.3:a:cisco:crosswork_network_controller:3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:crosswork_optimization_engine:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:cisco:crosswork_optimization_engine:*:*:*:*:*:*:*:*range: <2.0.1
- cpe:2.3:a:cisco:crosswork_optimization_engine:3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:crosswork_platform_infrastructure:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:cisco:crosswork_platform_infrastructure:*:*:*:*:*:*:*:*range: <4.0.1
- cpe:2.3:a:cisco:crosswork_platform_infrastructure:4.1.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:crosswork_zero_touch_provisioning:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:cisco:crosswork_zero_touch_provisioning:*:*:*:*:*:*:*:*range: <2.0.1
- cpe:2.3:a:cisco:crosswork_zero_touch_provisioning:3.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:customer_experience_cloud_agent:*:*:*:*:*:*:*:*Range: <1.12.1
- cpe:2.3:a:cisco:cx_cloud_agent:001.012:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:cyber_vision:4.0.2:*:*:*:*:*:*:*
cpe:2.3:a:cisco:cyber_vision_sensor_management_extension:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:cisco:cyber_vision_sensor_management_extension:*:*:*:*:*:*:*:*range: <4.0.3
- cpe:2.3:a:cisco:cyber_vision_sensor_management_extension:4.0.2:*:*:*:*:*:*:*
cpe:2.3:a:cisco:data_center_network_manager:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:cisco:data_center_network_manager:*:*:*:*:*:*:*:*range: <11.3\(1\)
- cpe:2.3:a:cisco:data_center_network_manager:11.3\(1\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:dna_center:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:cisco:dna_center:*:*:*:*:*:*:*:*range: <2.1.2.8
- cpe:2.3:a:cisco:dna_center:2.2.2.8:*:*:*:*:*:*:*
cpe:2.3:a:cisco:dna_spaces:-:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:cisco:dna_spaces:-:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:dna_spaces\:_connector:*:*:*:*:*:*:*:*range: <2.5
- cpe:2.3:a:cisco:dna_spaces_connector:-:*:*:*:*:*:*:*
cpe:2.3:a:cisco:emergency_responder:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:cisco:emergency_responder:*:*:*:*:*:*:*:*range: <11.5\(4\)
- cpe:2.3:a:cisco:emergency_responder:11.5:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:emergency_responder:11.5\(4.65000.14\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:emergency_responder:11.5\(4.66000.14\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:enterprise_chat_and_email:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:cisco:enterprise_chat_and_email:*:*:*:*:*:*:*:*range: <12.0\(1\)
- cpe:2.3:a:cisco:enterprise_chat_and_email:12.0\(1\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:enterprise_chat_and_email:12.5\(1\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:enterprise_chat_and_email:12.6\(1\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:evolved_programmable_network_manager:*:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:cisco:evolved_programmable_network_manager:*:*:*:*:*:*:*:*range: <=4.1.1
- cpe:2.3:a:cisco:evolved_programmable_network_manager:3.0:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:evolved_programmable_network_manager:3.1:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:evolved_programmable_network_manager:4.0:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:evolved_programmable_network_manager:4.1:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:evolved_programmable_network_manager:5.0:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:evolved_programmable_network_manager:5.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:finesse:*:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:cisco:finesse:*:*:*:*:*:*:*:*range: <12.6\(1\)
- cpe:2.3:a:cisco:finesse:12.5\(1\):su1:*:*:*:*:*:*
- cpe:2.3:a:cisco:finesse:12.5\(1\):su2:*:*:*:*:*:*
- cpe:2.3:a:cisco:finesse:12.6\(1\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:finesse:12.6\(1\):-:*:*:*:*:*:*
- cpe:2.3:a:cisco:finesse:12.6\(1\):es01:*:*:*:*:*:*
- cpe:2.3:a:cisco:finesse:12.6\(1\):es02:*:*:*:*:*:*
- cpe:2.3:a:cisco:finesse:12.6\(1\):es03:*:*:*:*:*:*
- cpe:2.3:a:cisco:fog_director:-:*:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:*:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:cisco:identity_services_engine:*:*:*:*:*:*:*:*range: <2.4.0
- cpe:2.3:a:cisco:identity_services_engine:002.004\(000.914\):-:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:002.006\(000.156\):-:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:002.007\(000.356\):-:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:003.000\(000.458\):-:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:003.001\(000.518\):-:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:003.002\(000.116\):-:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:2.4.0:-:*:*:*:*:*:*
cpe:2.3:a:cisco:integrated_management_controller_supervisor:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:cisco:integrated_management_controller_supervisor:*:*:*:*:*:*:*:*range: <2.3.2.1
- cpe:2.3:a:cisco:integrated_management_controller_supervisor:002.003\(002.000\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:integrated_management_controller_supervisor:2.3.2.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:intersight_virtual_appliance:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:cisco:intersight_virtual_appliance:*:*:*:*:*:*:*:*range: <1.0.9-361
- cpe:2.3:a:cisco:intersight_virtual_appliance:1.0.9-343:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:iot_operations_dashboard:-:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:mobility_services_engine:-:*:*:*:*:*:*:*
cpe:2.3:a:cisco:network_assurance_engine:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:cisco:network_assurance_engine:*:*:*:*:*:*:*:*range: <6.0.2
- cpe:2.3:a:cisco:network_assurance_engine:6.0\(2.1912\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:network_dashboard_fabric_controller:11.0\(1\):*:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:cisco:network_dashboard_fabric_controller:11.0\(1\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:network_dashboard_fabric_controller:11.1\(1\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:network_dashboard_fabric_controller:11.2\(1\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:network_dashboard_fabric_controller:11.3\(1\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:network_dashboard_fabric_controller:11.4\(1\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:network_dashboard_fabric_controller:11.5\(1\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:network_dashboard_fabric_controller:11.5\(2\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:network_dashboard_fabric_controller:11.5\(3\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:network_insights_for_data_center:6.0\(2.1914\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:network_services_orchestrator:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:cisco:network_services_orchestrator:*:*:*:*:*:*:*:*range: <5.3.5.1
- cpe:2.3:a:cisco:network_services_orchestrator:-:*:*:*:*:*:*:*
cpe:2.3:a:cisco:optical_network_controller:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:cisco:optical_network_controller:*:*:*:*:*:*:*:*range: <1.1.0
- cpe:2.3:a:cisco:optical_network_controller:1.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:packaged_contact_center_enterprise:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:cisco:packaged_contact_center_enterprise:*:*:*:*:*:*:*:*range: <11.6
- cpe:2.3:a:cisco:packaged_contact_center_enterprise:11.6\(1\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:paging_server:*:*:*:*:*:*:*:*+ 8 more
- cpe:2.3:a:cisco:paging_server:*:*:*:*:*:*:*:*range: <14.4.1
- cpe:2.3:a:cisco:paging_server:12.5\(2\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:paging_server:14.0\(1\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:paging_server:8.3\(1\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:paging_server:8.4\(1\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:paging_server:8.5\(1\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:paging_server:9.0\(1\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:paging_server:9.0\(2\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:paging_server:9.1\(1\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:prime_service_catalog:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:cisco:prime_service_catalog:*:*:*:*:*:*:*:*range: <12.1
- cpe:2.3:a:cisco:prime_service_catalog:12.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:sd-wan_vmanage:*:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:cisco:sd-wan_vmanage:*:*:*:*:*:*:*:*range: <20.3.4.1
- cpe:2.3:a:cisco:sd-wan_vmanage:20.3:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:sd-wan_vmanage:20.4:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:sd-wan_vmanage:20.5:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:sd-wan_vmanage:20.6.1:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:sd-wan_vmanage:20.6:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:sd-wan_vmanage:20.7:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:sd-wan_vmanage:20.8:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_firewall_threat_defense:6.2.3:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:cisco:secure_firewall_threat_defense:6.2.3:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:secure_firewall_threat_defense:6.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:secure_firewall_threat_defense:6.4.0:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:secure_firewall_threat_defense:6.5.0:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:secure_firewall_threat_defense:6.6.0:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:secure_firewall_threat_defense:6.7.0:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:secure_firewall_threat_defense:7.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:secure_firewall_threat_defense:7.1.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:smart_phy:*:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:cisco:smart_phy:*:*:*:*:*:*:*:*range: <3.2.1
- cpe:2.3:a:cisco:smart_phy:21.3:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:smart_phy:3.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:smart_phy:3.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:smart_phy:3.1.4:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:smart_phy:3.1.5:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:smart_phy:3.2.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:ucs_central_software:2.0:*:*:*:*:*:*:*+ 10 more
- cpe:2.3:a:cisco:ucs_central_software:2.0:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:ucs_central_software:2.0\(1a\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:ucs_central_software:2.0\(1b\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:ucs_central_software:2.0\(1c\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:ucs_central_software:2.0\(1d\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:ucs_central_software:2.0\(1e\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:ucs_central_software:2.0\(1f\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:ucs_central_software:2.0\(1g\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:ucs_central_software:2.0\(1h\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:ucs_central_software:2.0\(1k\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:ucs_central_software:2.0\(1l\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_communications_manager:*:*:*:*:-:*:*:*+ 10 more
- cpe:2.3:a:cisco:unified_communications_manager:*:*:*:*:-:*:*:*range: <11.5\(1\)
- cpe:2.3:a:cisco:unified_communications_manager:*:*:*:*:session_management:*:*:*range: <11.5\(1\)
- cpe:2.3:a:cisco:unified_communications_manager:11.5\(1.17900.52\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:unified_communications_manager:11.5\(1.18119.2\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:unified_communications_manager:11.5\(1.18900.97\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:unified_communications_manager:11.5\(1.21900.40\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:unified_communications_manager:11.5\(1.22900.28\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:unified_communications_manager:11.5\(1\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:unified_communications_manager:11.5\(1\):*:*:*:-:*:*:*
- cpe:2.3:a:cisco:unified_communications_manager:11.5\(1\):*:*:*:session_management:*:*:*
- cpe:2.3:a:cisco:unified_communications_manager:11.5\(1\)su3:*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_communications_manager_im_\&_presence_service:11.5\(1.22900.6\):*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:cisco:unified_communications_manager_im_\&_presence_service:11.5\(1.22900.6\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:unified_communications_manager_im_\&_presence_service:11.5\(1\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:*:*:*:*:*:*:*:*range: <11.5\(1\)
- cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:11.5\(1\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:unified_computing_system:006.008\(001.000\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_contact_center_enterprise:*:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:cisco:unified_contact_center_enterprise:*:*:*:*:*:*:*:*range: <11.6\(2\)
- cpe:2.3:a:cisco:unified_contact_center_enterprise:11.6\(2\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:unified_contact_center_enterprise:12.0\(1\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:unified_contact_center_enterprise:12.5\(1\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:unified_contact_center_enterprise:12.6\(1\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:unified_contact_center_enterprise:12.6\(2\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_contact_center_express:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:cisco:unified_contact_center_express:*:*:*:*:*:*:*:*range: <12.5\(1\)
- cpe:2.3:a:cisco:unified_contact_center_express:12.5\(1\):-:*:*:*:*:*:*
- cpe:2.3:a:cisco:unified_contact_center_express:12.5\(1\):su1:*:*:*:*:*:*
- cpe:2.3:a:cisco:unified_contact_center_express:12.6\(1\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:unified_contact_center_express:12.6\(2\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:unified_contact_center_management_portal:12.6\(1\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_customer_voice_portal:*:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:cisco:unified_customer_voice_portal:*:*:*:*:*:*:*:*range: <11.6
- cpe:2.3:a:cisco:unified_customer_voice_portal:11.6:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:unified_customer_voice_portal:11.6\(1\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:unified_customer_voice_portal:12.0:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:unified_customer_voice_portal:12.0\(1\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:unified_customer_voice_portal:12.5:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:unified_customer_voice_portal:12.5\(1\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:unified_customer_voice_portal:12.6\(1\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_intelligence_center:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:cisco:unified_intelligence_center:*:*:*:*:*:*:*:*range: <12.6\(1\)
- cpe:2.3:a:cisco:unified_intelligence_center:12.6\(1\):-:*:*:*:*:*:*
- cpe:2.3:a:cisco:unified_intelligence_center:12.6\(1\):es01:*:*:*:*:*:*
- cpe:2.3:a:cisco:unified_intelligence_center:12.6\(1\):es02:*:*:*:*:*:*
- cpe:2.3:a:cisco:unified_intelligence_center:12.6\(2\):-:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_sip_proxy:010.000\(000\):*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:cisco:unified_sip_proxy:010.000\(000\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:unified_sip_proxy:010.000\(001\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:unified_sip_proxy:010.002\(000\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:unified_sip_proxy:010.002\(001\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:unified_sip_proxy:*:*:*:*:*:*:*:*range: <10.2.1v2
cpe:2.3:a:cisco:unified_workforce_optimization:11.5\(1\):sr7:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:cisco:unified_workforce_optimization:11.5\(1\):sr7:*:*:*:*:*:*
- cpe:2.3:o:cisco:unified_workforce_optimization:*:*:*:*:*:*:*:*range: <11.5\(1\)
cpe:2.3:a:cisco:unity_connection:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:cisco:unity_connection:*:*:*:*:*:*:*:*range: <11.5\(1\)
- cpe:2.3:a:cisco:unity_connection:11.5:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:unity_connection:11.5\(1.10000.6\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:video_surveillance_manager:7.14\(1.26\):*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:cisco:video_surveillance_manager:7.14\(1.26\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:video_surveillance_manager:7.14\(2.26\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:video_surveillance_manager:7.14\(3.025\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:video_surveillance_manager:7.14\(4.018\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:video_surveillance_operations_manager:*:*:*:*:*:*:*:*Range: <7.14.4
cpe:2.3:a:cisco:virtual_topology_system:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:cisco:virtual_topology_system:*:*:*:*:*:*:*:*range: <2.6.7
- cpe:2.3:a:cisco:virtual_topology_system:2.6.6:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:virtualized_infrastructure_manager:*:*:*:*:*:*:*:*Range: <3.2.0
- cpe:2.3:a:cisco:virtualized_voice_browser:*:*:*:*:*:*:*:*Range: <12.5\(1\)
cpe:2.3:a:cisco:wan_automation_engine:*:*:*:*:*:*:*:*+ 8 more
- cpe:2.3:a:cisco:wan_automation_engine:*:*:*:*:*:*:*:*range: <7.3.0.2
- cpe:2.3:a:cisco:wan_automation_engine:7.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:wan_automation_engine:7.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:wan_automation_engine:7.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:wan_automation_engine:7.2.3:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:wan_automation_engine:7.3:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:wan_automation_engine:7.4:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:wan_automation_engine:7.5:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:wan_automation_engine:7.6:*:*:*:*:*:*:*
cpe:2.3:a:cisco:webex_meetings_server:*:*:*:*:*:*:*:*+ 16 more
- cpe:2.3:a:cisco:webex_meetings_server:*:*:*:*:*:*:*:*range: <3.0
- cpe:2.3:a:cisco:webex_meetings_server:3.0:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:webex_meetings_server:3.0:-:*:*:*:*:*:*
- cpe:2.3:a:cisco:webex_meetings_server:3.0:maintenance_release1:*:*:*:*:*:*
- cpe:2.3:a:cisco:webex_meetings_server:3.0:maintenance_release2:*:*:*:*:*:*
- cpe:2.3:a:cisco:webex_meetings_server:3.0:maintenance_release3:*:*:*:*:*:*
- cpe:2.3:a:cisco:webex_meetings_server:3.0:maintenance_release3:-:*:*:*:*:*
- cpe:2.3:a:cisco:webex_meetings_server:3.0:maintenance_release3_security_patch4:*:*:*:*:*:*
- cpe:2.3:a:cisco:webex_meetings_server:3.0:maintenance_release3_security_patch5:*:*:*:*:*:*
- cpe:2.3:a:cisco:webex_meetings_server:3.0:maintenance_release3_service_pack_2:*:*:*:*:*:*
- cpe:2.3:a:cisco:webex_meetings_server:3.0:maintenance_release3_service_pack_3:*:*:*:*:*:*
- cpe:2.3:a:cisco:webex_meetings_server:3.0:maintenance_release4:*:*:*:*:*:*
- cpe:2.3:a:cisco:webex_meetings_server:4.0:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:webex_meetings_server:4.0:-:*:*:*:*:*:*
- cpe:2.3:a:cisco:webex_meetings_server:4.0:maintenance_release1:*:*:*:*:*:*
- cpe:2.3:a:cisco:webex_meetings_server:4.0:maintenance_release2:*:*:*:*:*:*
- cpe:2.3:a:cisco:webex_meetings_server:4.0:maintenance_release3:*:*:*:*:*:*
- cpe:2.3:a:cisco:workload_optimization_manager:*:*:*:*:*:*:*:*Range: <3.2.1
- cpe:2.3:a:intel:computer_vision_annotation_tool:-:*:*:*:*:*:*:*
- cpe:2.3:a:intel:genomics_kernel_library:-:*:*:*:*:*:*:*
- cpe:2.3:a:intel:oneapi_sample_browser:-:*:*:*:*:eclipse:*:*
- cpe:2.3:a:intel:secure_device_onboard:-:*:*:*:*:*:*:*
- cpe:2.3:a:intel:system_studio:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*+ 2 more
- cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*
- cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
- cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*
- cpe:2.3:a:netapp:brocade_san_navigator:-:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:cloud_insights:-:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:cloud_manager:-:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:cloud_secure_agent:-:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:ontap_tools:-:*:*:*:*:vmware_vsphere:*:*
- cpe:2.3:a:netapp:snapcenter:-:*:*:*:*:vmware_vsphere:*:*
- cpe:2.3:a:netapp:solidfire_\&_hci_storage_node:-:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:solidfire_enterprise_sds:-:*:*:*:*:*:*:*
cpe:2.3:a:siemens:capital:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:siemens:capital:*:*:*:*:*:*:*:*range: <2019.1
- cpe:2.3:a:siemens:capital:2019.1:-:*:*:*:*:*:*
- cpe:2.3:a:siemens:capital:2019.1:sp1912:*:*:*:*:*:*
cpe:2.3:a:siemens:desigo_cc_advanced_reports:3.0:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:siemens:desigo_cc_advanced_reports:3.0:*:*:*:*:*:*:*
- cpe:2.3:a:siemens:desigo_cc_advanced_reports:4.0:*:*:*:*:*:*:*
- cpe:2.3:a:siemens:desigo_cc_advanced_reports:4.1:*:*:*:*:*:*:*
- cpe:2.3:a:siemens:desigo_cc_advanced_reports:4.2:*:*:*:*:*:*:*
- cpe:2.3:a:siemens:desigo_cc_advanced_reports:5.0:*:*:*:*:*:*:*
- cpe:2.3:a:siemens:desigo_cc_advanced_reports:5.1:*:*:*:*:*:*:*
cpe:2.3:a:siemens:desigo_cc_info_center:5.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:siemens:desigo_cc_info_center:5.0:*:*:*:*:*:*:*
- cpe:2.3:a:siemens:desigo_cc_info_center:5.1:*:*:*:*:*:*:*
- cpe:2.3:a:siemens:e-car_operation_center:*:*:*:*:*:*:*:*Range: <2021-12-13
- cpe:2.3:a:siemens:energy_engage:3.1:*:*:*:*:*:*:*
cpe:2.3:a:siemens:energyip:8.5:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:siemens:energyip:8.5:*:*:*:*:*:*:*
- cpe:2.3:a:siemens:energyip:8.6:*:*:*:*:*:*:*
- cpe:2.3:a:siemens:energyip:8.7:*:*:*:*:*:*:*
- cpe:2.3:a:siemens:energyip:9.0:*:*:*:*:*:*:*
- cpe:2.3:a:siemens:head-end_system_universal_device_integration_system:*:*:*:*:*:*:*:*
- cpe:2.3:a:siemens:industrial_edge_management:*:*:*:*:*:*:*:*
- cpe:2.3:a:siemens:industrial_edge_management_hub:*:*:*:*:*:*:*:*Range: <2021-12-13
- cpe:2.3:a:siemens:logo\!_soft_comfort:*:*:*:*:*:*:*:*
- cpe:2.3:a:siemens:mendix:*:*:*:*:*:*:*:*
- cpe:2.3:a:siemens:nx:*:*:*:*:*:*:*:*
- cpe:2.3:a:siemens:opcenter_intelligence:*:*:*:*:*:*:*:*Range: >=3.2,<3.5
- cpe:2.3:a:siemens:operation_scheduler:*:*:*:*:*:*:*:*Range: <=1.1.3
cpe:2.3:a:siemens:sentron_powermanager:4.1:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:siemens:sentron_powermanager:4.1:*:*:*:*:*:*:*
- cpe:2.3:a:siemens:sentron_powermanager:4.2:*:*:*:*:*:*:*
cpe:2.3:a:siemens:sipass_integrated:2.80:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:siemens:sipass_integrated:2.80:*:*:*:*:*:*:*
- cpe:2.3:a:siemens:sipass_integrated:2.85:*:*:*:*:*:*:*
- cpe:2.3:a:siemens:siveillance_command:*:*:*:*:*:*:*:*Range: <=4.16.2.1
- cpe:2.3:a:siemens:siveillance_control_pro:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:siveillance_identity:1.5:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:siemens:siveillance_identity:1.5:*:*:*:*:*:*:*
- cpe:2.3:a:siemens:siveillance_identity:1.6:*:*:*:*:*:*:*
- cpe:2.3:a:siemens:siveillance_vantage:*:*:*:*:*:*:*:*
- cpe:2.3:a:siemens:siveillance_viewpoint:*:*:*:*:*:*:*:*
- cpe:2.3:a:siemens:solid_edge_cam_pro:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_harness_design:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:siemens:solid_edge_harness_design:*:*:*:*:*:*:*:*range: <2020
- cpe:2.3:a:siemens:solid_edge_harness_design:2020:*:*:*:*:*:*:*
- cpe:2.3:a:siemens:solid_edge_harness_design:2020:-:*:*:*:*:*:*
- cpe:2.3:a:siemens:solid_edge_harness_design:2020:sp2002:*:*:*:*:*:*
cpe:2.3:a:siemens:spectrum_power_4:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:siemens:spectrum_power_4:*:*:*:*:*:*:*:*range: <4.70
- cpe:2.3:a:siemens:spectrum_power_4:4.70:-:*:*:*:*:*:*
- cpe:2.3:a:siemens:spectrum_power_4:4.70:sp7:*:*:*:*:*:*
- cpe:2.3:a:siemens:spectrum_power_4:4.70:sp8:*:*:*:*:*:*
cpe:2.3:a:siemens:spectrum_power_7:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:siemens:spectrum_power_7:*:*:*:*:*:*:*:*range: <2.30
- cpe:2.3:a:siemens:spectrum_power_7:2.30:*:*:*:*:*:*:*
- cpe:2.3:a:siemens:spectrum_power_7:2.30:-:*:*:*:*:*:*
- cpe:2.3:a:siemens:spectrum_power_7:2.30:sp2:*:*:*:*:*:*
- cpe:2.3:a:siemens:teamcenter:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:vesys:*:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:siemens:vesys:*:*:*:*:*:*:*:*range: <2019.1
- cpe:2.3:a:siemens:vesys:2019.1:*:*:*:*:*:*:*
- cpe:2.3:a:siemens:vesys:2019.1:-:*:*:*:*:*:*
- cpe:2.3:a:siemens:vesys:2019.1:sp1912:*:*:*:*:*:*
- cpe:2.3:a:siemens:vesys:2020.1:-:*:*:*:*:*:*
- cpe:2.3:a:siemens:vesys:2021.1:-:*:*:*:*:*:*
- cpe:2.3:a:siemens:xpedition_enterprise:-:*:*:*:*:*:*:*
- cpe:2.3:a:siemens:xpedition_package_integrator:-:*:*:*:*:*:*:*
cpe:2.3:o:cisco:fxos:6.2.3:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:o:cisco:fxos:6.2.3:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:fxos:6.3.0:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:fxos:6.4.0:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:fxos:6.5.0:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:fxos:6.6.0:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:fxos:6.7.0:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:fxos:7.0.0:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:fxos:7.1.0:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
- cpe:2.3:o:siemens:6bk1602-0aa12-0tp0_firmware:*:*:*:*:*:*:*:*Range: <2.7.0
- cpe:2.3:o:siemens:6bk1602-0aa22-0tp0_firmware:*:*:*:*:*:*:*:*Range: <2.7.0
- cpe:2.3:o:siemens:6bk1602-0aa32-0tp0_firmware:*:*:*:*:*:*:*:*Range: <2.7.0
- cpe:2.3:o:siemens:6bk1602-0aa42-0tp0_firmware:*:*:*:*:*:*:*:*Range: <2.7.0
- cpe:2.3:o:siemens:6bk1602-0aa52-0tp0_firmware:*:*:*:*:*:*:*:*Range: <2.7.0
- cpe:2.3:o:siemens:sppa-t3000_ses3000_firmware:*:*:*:*:*:*:*:*
- ghsa-coords22 versionspkg:maven/com.guicedee.services/log4j-corepkg:maven/org.apache.logging.log4j/log4j-corepkg:maven/org.ops4j.pax.logging/pax-logging-log4j2pkg:maven/org.xbib.elasticsearch/log4jpkg:maven/uk.co.nichesolutions.logging.log4j/log4j-corepkg:rpm/opensuse/disruptor&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/disruptor&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/jakarta-servlet&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/jakarta-servlet&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/log4j&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/log4j&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/log4j&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/logback&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/logback&distro=openSUSE%20Leap%2015.3pkg:rpm/suse/storm&distro=HPE%20Helion%20OpenStack%208pkg:rpm/suse/storm&distro=SUSE%20OpenStack%20Cloud%208pkg:rpm/suse/storm&distro=SUSE%20OpenStack%20Cloud%209pkg:rpm/suse/storm&distro=SUSE%20OpenStack%20Cloud%20Crowbar%208pkg:rpm/suse/storm&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209pkg:rpm/suse/venv-openstack-monasca&distro=HPE%20Helion%20OpenStack%208pkg:rpm/suse/venv-openstack-monasca&distro=SUSE%20OpenStack%20Cloud%208pkg:rpm/suse/venv-openstack-monasca&distro=SUSE%20OpenStack%20Cloud%209
<= 1.2.1.2-jre17+ 21 more
- (no CPE)range: <= 1.2.1.2-jre17
- (no CPE)range: >= 2.13.0, < 2.15.0
- (no CPE)range: >= 1.8.0, < 1.9.2
- (no CPE)
- (no CPE)
- (no CPE)range: < 3.4.4-lp152.2.3.1
- (no CPE)range: < 3.4.4-3.3.1
- (no CPE)range: < 5.0.0-lp152.2.1
- (no CPE)range: < 5.0.0-5.3.1
- (no CPE)range: < 2.13.0-lp152.3.3.1
- (no CPE)range: < 2.13.0-4.3.1
- (no CPE)range: < 2.13.2-2.1
- (no CPE)range: < 1.2.8-lp152.2.3.2
- (no CPE)range: < 1.2.8-3.3.1
- (no CPE)range: < 1.2.3-3.8.2
- (no CPE)range: < 1.2.3-3.8.2
- (no CPE)range: < 1.2.3-3.5.1
- (no CPE)range: < 1.2.3-3.8.2
- (no CPE)range: < 1.2.3-3.5.1
- (no CPE)range: < 2.2.2~dev1-11.32.1
- (no CPE)range: < 2.2.2~dev1-11.32.1
- (no CPE)range: < 2.7.1~dev10-3.25.1
- Apache Software Foundation/Apache Log4j2v5Range: 2.0-beta9
Patches
Vulnerability mechanics
References
77- msrc-blog.microsoft.com/2021/12/11/microsofts-response-to-cve-2021-44228-apache-log4j2/nvdPatchThird Party AdvisoryVendor Advisory
- www.oracle.com/security-alerts/cpuapr2022.htmlnvdPatchThird Party AdvisoryWEB
- www.oracle.com/security-alerts/cpujan2022.htmlnvdPatchThird Party AdvisoryWEB
- packetstormsecurity.com/files/165261/Apache-Log4j2-2.14.1-Information-Disclosure.htmlnvdExploitThird Party AdvisoryVDB EntryWEB
- packetstormsecurity.com/files/165270/Apache-Log4j2-2.14.1-Remote-Code-Execution.htmlnvdExploitThird Party AdvisoryVDB EntryWEB
- packetstormsecurity.com/files/165371/VMware-Security-Advisory-2021-0028.4.htmlnvdExploitThird Party AdvisoryVDB EntryWEB
- packetstormsecurity.com/files/165532/Log4Shell-HTTP-Header-Injection.htmlnvdExploitThird Party AdvisoryVDB EntryWEB
- packetstormsecurity.com/files/165642/VMware-vCenter-Server-Unauthenticated-Log4Shell-JNDI-Injection-Remote-Code-Execution.htmlnvdExploitThird Party AdvisoryVDB EntryWEB
- packetstormsecurity.com/files/165673/UniFi-Network-Application-Unauthenticated-Log4Shell-Remote-Code-Execution.htmlnvdExploitThird Party AdvisoryVDB EntryWEB
- packetstormsecurity.com/files/167917/MobileIron-Log4Shell-Remote-Command-Execution.htmlnvdExploitThird Party AdvisoryVDB EntryWEB
- seclists.org/fulldisclosure/2022/Dec/2nvdExploitMailing ListThird Party AdvisoryWEB
- github.com/nu11secur1ty/CVE-mitre/tree/main/CVE-2021-44228nvdExploitThird Party AdvisoryWEB
- twitter.com/kurtseifried/status/1469345530182455296nvdBroken LinkExploitThird Party AdvisoryWEB
- www.nu11secur1ty.com/2021/12/cve-2021-44228.htmlnvdExploitThird Party AdvisoryWEB
- packetstormsecurity.com/files/165225/Apache-Log4j2-2.14.1-Remote-Code-Execution.htmlnvdThird Party AdvisoryVDB EntryWEB
- packetstormsecurity.com/files/165260/VMware-Security-Advisory-2021-0028.htmlnvdThird Party AdvisoryVDB EntryWEB
- packetstormsecurity.com/files/165281/Log4j2-Log4Shell-Regexes.htmlnvdThird Party AdvisoryVDB EntryWEB
- packetstormsecurity.com/files/165282/Log4j-Payload-Generator.htmlnvdThird Party AdvisoryVDB EntryWEB
- packetstormsecurity.com/files/165306/L4sh-Log4j-Remote-Code-Execution.htmlnvdThird Party AdvisoryVDB EntryWEB
- packetstormsecurity.com/files/165307/Log4j-Remote-Code-Execution-Word-Bypassing.htmlnvdThird Party AdvisoryVDB EntryWEB
- packetstormsecurity.com/files/165311/log4j-scan-Extensive-Scanner.htmlnvdBroken LinkThird Party AdvisoryVDB EntryWEB
- packetstormsecurity.com/files/167794/Open-Xchange-App-Suite-7.10.x-Cross-Site-Scripting-Command-Injection.htmlnvdThird Party AdvisoryVDB EntryWEB
- packetstormsecurity.com/files/171626/AD-Manager-Plus-7122-Remote-Code-Execution.htmlnvdThird Party AdvisoryVDB EntryWEB
- seclists.org/fulldisclosure/2022/Jul/11nvdMailing ListThird Party AdvisoryWEB
- seclists.org/fulldisclosure/2022/Mar/23nvdMailing ListThird Party AdvisoryWEB
- www.openwall.com/lists/oss-security/2021/12/10/1nvdMailing ListMitigationThird Party AdvisoryWEB
- www.openwall.com/lists/oss-security/2021/12/10/2nvdMailing ListMitigationThird Party AdvisoryWEB
- www.openwall.com/lists/oss-security/2021/12/10/3nvdMailing ListThird Party AdvisoryWEB
- www.openwall.com/lists/oss-security/2021/12/13/1nvdMailing ListThird Party AdvisoryWEB
- www.openwall.com/lists/oss-security/2021/12/13/2nvdMailing ListThird Party AdvisoryWEB
- www.openwall.com/lists/oss-security/2021/12/14/4nvdMailing ListThird Party AdvisoryWEB
- www.openwall.com/lists/oss-security/2021/12/15/3nvdMailing ListThird Party AdvisoryWEB
- cert-portal.siemens.com/productcert/pdf/ssa-397453.pdfnvdThird Party AdvisoryWEB
- cert-portal.siemens.com/productcert/pdf/ssa-479842.pdfnvdThird Party AdvisoryWEB
- cert-portal.siemens.com/productcert/pdf/ssa-661247.pdfnvdThird Party AdvisoryWEB
- cert-portal.siemens.com/productcert/pdf/ssa-714170.pdfnvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-7rjr-3q55-vv33ghsaADVISORY
- github.com/advisories/GHSA-jfh8-c2jp-5v3qghsaADVISORY
- lists.debian.org/debian-lts-announce/2021/12/msg00007.htmlnvdMailing ListThird Party AdvisoryWEB
- logging.apache.org/log4j/2.x/security.htmlnvdRelease NotesVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2021-44228ghsaADVISORY
- psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0032nvdThird Party AdvisoryWEB
- security.netapp.com/advisory/ntap-20211210-0007/nvdThird Party Advisory
- support.apple.com/kb/HT213189nvdThird Party AdvisoryWEB
- tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbdnvdThird Party AdvisoryWEB
- www.bentley.com/en/common-vulnerability-exposure/be-2022-0001nvdThird Party AdvisoryWEB
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdThird Party AdvisoryUS Government ResourceWEB
- www.debian.org/security/2021/dsa-5020nvdMailing ListThird Party AdvisoryWEB
- www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00646.htmlnvdThird Party AdvisoryWEB
- www.kb.cert.org/vuls/id/930724nvdThird Party AdvisoryUS Government ResourceWEB
- www.oracle.com/security-alerts/alert-cve-2021-44228.htmlnvdThird Party AdvisoryWEB
- github.com/apache/logging-log4j2/pull/608ghsaWEB
- github.com/cisagov/log4j-affected-db/blob/develop/SOFTWARE-LIST.mdnvdBroken LinkProductUS Government ResourceWEB
- github.com/github/advisory-database/pull/5501ghsaWEB
- issues.apache.org/jira/browse/LOG4J2-3198ghsaWEB
- issues.apache.org/jira/browse/LOG4J2-3201ghsaWEB
- issues.apache.org/jira/browse/LOG4J2-3214ghsaWEB
- issues.apache.org/jira/browse/LOG4J2-3221ghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M5CSVUNV4HWZZXGOKNSK6L7RPM7BOKIBghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M5CSVUNV4HWZZXGOKNSK6L7RPM7BOKIB/nvdRelease Notes
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VU57UJDCFIASIO35GC55JMKSRXJMCDFMghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VU57UJDCFIASIO35GC55JMKSRXJMCDFM/nvdRelease Notes
- lists.fedoraproject.org/archives/list/[email protected]/message/M5CSVUNV4HWZZXGOKNSK6L7RPM7BOKIBghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/VU57UJDCFIASIO35GC55JMKSRXJMCDFMghsaWEB
- logging.apache.org/log4j/2.x/changes-report.htmlghsaWEB
- logging.apache.org/log4j/2.x/manual/lookups.htmlghsaWEB
- logging.apache.org/log4j/2.x/manual/migration.htmlghsaWEB
- msrc-blog.microsoft.com/2021/12/11/microsofts-response-to-cve-2021-44228-apache-log4j2ghsaWEB
- packetstormsecurity.com/files/165673/UniFi-Network-Application-Unauthenticated-Log4Shell-Remote-Code-Execution.htmlghsaWEB
- packetstormsecurity.com/files/167794/Open-Xchange-App-Suite-7.10.x-Cross-Site-Scripting-Command-Injection.htmlghsaWEB
- packetstormsecurity.com/files/167917/MobileIron-Log4Shell-Remote-Command-Execution.htmlghsaWEB
- packetstormsecurity.com/files/171626/AD-Manager-Plus-7122-Remote-Code-Execution.htmlghsaWEB
- sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbdghsaWEB
- seclists.org/fulldisclosure/2022/Dec/2ghsaWEB
- seclists.org/fulldisclosure/2022/Jul/11ghsaWEB
- seclists.org/fulldisclosure/2022/Mar/23ghsaWEB
- security.netapp.com/advisory/ntap-20211210-0007ghsaWEB
News mentions
4- Contrast CVE Shield aims to protect applications while security teams deploy patchesHelp Net Security · Jul 29, 2026
- What do Ports Hear When Nobody's Listening? An Assessment of Automated Cybercrime [Guest Diary], (Wed, Jun 24th)SANS Internet Storm Center · Jun 25, 2026
- Inside the customer environment: Where threat actors, vulnerabilities, and exposed assets intersectTenable Blog · May 27, 2026
- From Stuxnet to ChatGPT: 20 News Events That Shaped CyberDark Reading · May 6, 2026