CyberSec.Space Logo
返回 CVE 浏览器

CVE-2021-45046

Known Exploited (CISA KEV)CRITICAL
9.0
CVSS Severity Score
EPSS Score64.5290%
EPSS Percentile98.56th
Published2021年12月14日
Last Modified2025年10月27日

Vulnerability Description

It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in an information leak and remote code execution in some environments and local code execution in all environments. Log4j 2.16.0 (Java 8) and 2.12.2 (Java 7) fix this issue by removing support for message lookup patterns and disabling JNDI functionality by default.

Affected Platforms (CPE)

📦
Apache

Log4j

>= 2.0.1 and < 2.12.2
📦
Apache

Log4j

>= 2.13.0 and < 2.16.0
📦
Apache

Log4j

= 2.0
📦
Apache

Log4j

= 2.0
📦
Apache

Log4j

= 2.0
📦
Apache

Log4j

= 2.0
📦
Cvat

Computer Vision Annotation Tool

All versions
📦
Intel

Audio Development Kit

All versions
📦
Intel

Datacenter Manager

All versions
📦
Intel

Genomics Kernel Library

All versions
📦
Intel

Oneapi

All versions
📦
Intel

Secure Device Onboard

All versions
📦
Intel

Sensor Solution Firmware Development Kit

All versions
📦
Intel

System Debugger

All versions
📦
Intel

System Studio

All versions
💻
Siemens

Sppa T3000 Ses3000 Firmware

All versions
📦
Siemens

Captial

< 2019.1
📦
Siemens

Captial

= 2019.1
📦
Siemens

Captial

= 2019.1
📦
Siemens

Comos

All versions
📦
Siemens

Desigo Cc Advanced Reports

= 4.0
📦
Siemens

Desigo Cc Advanced Reports

= 4.1
📦
Siemens

Desigo Cc Advanced Reports

= 4.2
📦
Siemens

Desigo Cc Advanced Reports

= 5.0
📦
Siemens

Desigo Cc Advanced Reports

= 5.1
📦
Siemens

Desigo Cc Info Center

= 5.0
📦
Siemens

Desigo Cc Info Center

= 5.1
📦
Siemens

E Car Operation Center

< 2021-12-13
📦
Siemens

Energy Engage

= 3.1
📦
Siemens

Energyip

= 8.5
📦
Siemens

Energyip

= 8.6
📦
Siemens

Energyip

= 8.7
📦
Siemens

Energyip

= 9.0
📦
Siemens

Energyip Prepay

= 3.7
📦
Siemens

Energyip Prepay

= 3.8
📦
Siemens

Gma Manager

< 8.6.2j-398
📦
Siemens

Head End System Universal Device Integration System

All versions
📦
Siemens

Industrial Edge Management

All versions
📦
Siemens

Industrial Edge Management Hub

< 2021-12-13
📦
Siemens

Logo\! Soft Comfort

All versions
📦
Siemens

Mendix

All versions
📦
Siemens

Mindsphere

< 2021-12-11
📦
Siemens

Navigator

< 2021-12-13
📦
Siemens

Nx

All versions
📦
Siemens

Opcenter Intelligence

<= 3.2
📦
Siemens

Operation Scheduler

<= 1.1.3
📦
Siemens

Sentron Powermanager

= 4.1
📦
Siemens

Sentron Powermanager

= 4.2
📦
Siemens

Siguard Dsa

= 4.2
📦
Siemens

Siguard Dsa

= 4.3
📦
Siemens

Siguard Dsa

= 4.4
📦
Siemens

Sipass Integrated

= 2.80
📦
Siemens

Sipass Integrated

= 2.85
📦
Siemens

Siveillance Command

<= 4.16.2.1
📦
Siemens

Siveillance Control Pro

All versions
📦
Siemens

Siveillance Identity

= 1.5
📦
Siemens

Siveillance Identity

= 1.6
📦
Siemens

Siveillance Vantage

All versions
📦
Siemens

Siveillance Viewpoint

All versions
📦
Siemens

Solid Edge Cam Pro

All versions
📦
Siemens

Solid Edge Harness Design

< 2020
📦
Siemens

Solid Edge Harness Design

= 2020
📦
Siemens

Solid Edge Harness Design

= 2020
📦
Siemens

Solid Edge Harness Design

= 2020
📦
Siemens

Spectrum Power 4

< 4.70
📦
Siemens

Spectrum Power 4

= 4.70
📦
Siemens

Spectrum Power 4

= 4.70
📦
Siemens

Spectrum Power 4

= 4.70
📦
Siemens

Spectrum Power 7

< 2.30
📦
Siemens

Spectrum Power 7

= 2.30
📦
Siemens

Spectrum Power 7

= 2.30
📦
Siemens

Spectrum Power 7

= 2.30
📦
Siemens

Teamcenter

All versions
📦
Siemens

Tracealertserverplus

All versions
📦
Siemens

Vesys

< 2019.1
📦
Siemens

Vesys

= 2019.1
📦
Siemens

Vesys

= 2019.1
📦
Siemens

Vesys

= 2019.1
📦
Siemens

Xpedition Enterprise

All versions
📦
Siemens

Xpedition Package Integrator

All versions
💻
Debian

Debian Linux

= 10.0
💻
Debian

Debian Linux

= 11.0
📦
Sonicwall

Email Security

< 10.0.12
💻
Fedoraproject

Fedora

= 34
💻
Fedoraproject

Fedora

= 35
💻
Siemens

6bk1602 0aa12 0tp0 Firmware

< 2.7.0
💻
Siemens

6bk1602 0aa22 0tp0 Firmware

< 2.7.0
💻
Siemens

6bk1602 0aa32 0tp0 Firmware

< 2.7.0
💻
Siemens

6bk1602 0aa42 0tp0 Firmware

< 2.7.0
💻
Siemens

6bk1602 0aa52 0tp0 Firmware

< 2.7.0

References & Advisories

相关漏洞威胁