CVE-2021-4104
Description
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-44228. Note this issue only affects Log4j 1.2 when specifically configured to use JMSAppender, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.
EPSS (Exploit Prediction Scoring System)
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score Trend (Last 90 Days)
Deserialization of Untrusted Data
DraftCommon Consequences
Applicable Platforms
Advanced Supply Chain Planning by Oracle
cpe:2.3:a:oracle:advanced_supply_chain_planning:12.2:*:*:*:*:*:*:*
Weblogic Server by Oracle
cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:*
Financial Services Revenue Management And Billing Analytics by Oracle
cpe:2.3:a:oracle:financial_services_revenue_management_and_billing_analytics:2.7.0.0:*:*:*:*:*:*:*
Stream Analytics by Oracle
cpe:2.3:a:oracle:stream_analytics:-:*:*:*:*:*:*:*
Communications Unified Inventory Management by Oracle
cpe:2.3:a:oracle:communications_unified_inventory_management:7.3.4:*:*:*:*:*:*:*
Retail Allocation by Oracle
cpe:2.3:a:oracle:retail_allocation:19.0.1:*:*:*:*:*:*:*
Enterprise Linux by Redhat
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
Identity Management Suite by Oracle
cpe:2.3:a:oracle:identity_management_suite:12.2.1.3.0:*:*:*:*:*:*:*
Openshift Container Platform by Redhat
cpe:2.3:a:redhat:openshift_container_platform:4.7:*:*:*:*:*:*:*
Communications Unified Inventory Management by Oracle
cpe:2.3:a:oracle:communications_unified_inventory_management:7.3.5:*:*:*:*:*:*:*
Codeready Studio by Redhat
cpe:2.3:a:redhat:codeready_studio:12.0:*:*:*:*:*:*:*
Process Automation by Redhat
cpe:2.3:a:redhat:process_automation:7.0:*:*:*:*:*:*:*
Jdeveloper by Oracle
cpe:2.3:a:oracle:jdeveloper:12.2.1.3.0:*:*:*:*:*:*:*
Financial Services Revenue Management And Billing Analytics by Oracle
cpe:2.3:a:oracle:financial_services_revenue_management_and_billing_analytics:2.7.0.1:*:*:*:*:*:*:*
Retail Allocation by Oracle
cpe:2.3:a:oracle:retail_allocation:15.0.3.1:*:*:*:*:*:*:*
Communications Offline Mediation Controller by Oracle
cpe:2.3:a:oracle:communications_offline_mediation_controller:*:*:*:*:*:*:*:*
Log4J by Apache
cpe:2.3:a:apache:log4j:1.2:*:*:*:*:*:*:*
Financial Services Revenue Management And Billing Analytics by Oracle
cpe:2.3:a:oracle:financial_services_revenue_management_and_billing_analytics:2.8.0.0:*:*:*:*:*:*:*
Enterprise Linux by Redhat
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
Retail Extract Transform And Load by Oracle
cpe:2.3:a:oracle:retail_extract_transform_and_load:13.2.5:*:*:*:*:*:*:*
Jboss A-Mq by Redhat
cpe:2.3:a:redhat:jboss_a-mq:6.0.0:*:*:*:*:*:*:*
Jboss Fuse Service Works by Redhat
cpe:2.3:a:redhat:jboss_fuse_service_works:6.0:*:*:*:*:*:*:*
Weblogic Server by Oracle
cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:*
Goldengate by Oracle
cpe:2.3:a:oracle:goldengate:-:*:*:*:*:*:*:*
Retail Allocation by Oracle
cpe:2.3:a:oracle:retail_allocation:14.1.3.2:*:*:*:*:*:*:*
Identity Management Suite by Oracle
cpe:2.3:a:oracle:identity_management_suite:12.2.1.4.0:*:*:*:*:*:*:*
Jboss Web Server by Redhat
cpe:2.3:a:redhat:jboss_web_server:3.0:*:*:*:*:*:*:*
Hyperion Infrastructure Technology by Oracle
cpe:2.3:a:oracle:hyperion_infrastructure_technology:*:*:*:*:*:*:*:*
Communications Offline Mediation Controller by Oracle
cpe:2.3:a:oracle:communications_offline_mediation_controller:12.0.0.5.0:*:*:*:*:*:*:*
Jboss Data Virtualization by Redhat
cpe:2.3:a:redhat:jboss_data_virtualization:6.0.0:*:*:*:*:*:*:*
Retail Allocation by Oracle
cpe:2.3:a:oracle:retail_allocation:16.0.3:*:*:*:*:*:*:*
Healthcare Data Repository by Oracle
cpe:2.3:a:oracle:healthcare_data_repository:8.1.0:*:*:*:*:*:*:*
Openshift Container Platform by Redhat
cpe:2.3:a:redhat:openshift_container_platform:4.6:*:*:*:*:*:*:*
Enterprise Manager Base Platform by Oracle
cpe:2.3:a:oracle:enterprise_manager_base_platform:13.5.0.0:*:*:*:*:*:*:*
E-Business Suite Cloud Manager And Cloud Backup Module by Oracle
cpe:2.3:a:oracle:e-business_suite_cloud_manager_and_cloud_backup_module:2.2.1.1.1:*:*:*:*:*:*:*
Software Collections by Redhat
cpe:2.3:a:redhat:software_collections:-:*:*:*:*:*:*:*
Business Intelligence by Oracle
cpe:2.3:a:oracle:business_intelligence:12.2.1.3.0:*:*:*:enterprise:*:*:*
Fedora by Fedoraproject
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
Business Intelligence by Oracle
cpe:2.3:a:oracle:business_intelligence:12.2.1.4.0:*:*:*:enterprise:*:*:*
Jboss Enterprise Application Platform by Redhat
cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.0:*:*:*:*:*:*:*
Jboss A-Mq Streaming by Redhat
cpe:2.3:a:redhat:jboss_a-mq_streaming:-:*:*:*:*:*:*:*
Utilities Testing Accelerator by Oracle
cpe:2.3:a:oracle:utilities_testing_accelerator:6.0.0.3.1:*:*:*:*:*:*:*
Timesten Grid by Oracle
cpe:2.3:a:oracle:timesten_grid:-:*:*:*:*:*:*:*
Openshift Container Platform by Redhat
cpe:2.3:a:redhat:openshift_container_platform:4.8:*:*:*:*:*:*:*
Single Sign-On by Redhat
cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:*
Jboss Fuse by Redhat
cpe:2.3:a:redhat:jboss_fuse:6.0.0:*:*:*:*:*:*:*
Openshift Application Runtimes by Redhat
cpe:2.3:a:redhat:openshift_application_runtimes:-:*:*:*:*:*:*:*
Utilities Testing Accelerator by Oracle
cpe:2.3:a:oracle:utilities_testing_accelerator:6.0.0.1.1:*:*:*:*:*:*:*
Jboss A-Mq by Redhat
cpe:2.3:a:redhat:jboss_a-mq:7:*:*:*:*:*:*:*
Advanced Supply Chain Planning by Oracle
cpe:2.3:a:oracle:advanced_supply_chain_planning:12.1:*:*:*:*:*:*:*
Communications Unified Inventory Management by Oracle
cpe:2.3:a:oracle:communications_unified_inventory_management:7.4.1:*:*:*:*:*:*:*
Mysql Enterprise Monitor by Oracle
cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:*
Jboss Enterprise Application Platform by Redhat
cpe:2.3:a:redhat:jboss_enterprise_application_platform:6.0.0:*:*:*:*:*:*:*
Communications Network Integrity by Oracle
cpe:2.3:a:oracle:communications_network_integrity:7.3.6:*:*:*:*:*:*:*
Jboss Fuse by Redhat
cpe:2.3:a:redhat:jboss_fuse:7.0.0:*:*:*:*:*:*:*
Business Intelligence by Oracle
cpe:2.3:a:oracle:business_intelligence:5.9.0.0.0:*:*:*:enterprise:*:*:*
Integration Camel K by Redhat
cpe:2.3:a:redhat:integration_camel_k:-:*:*:*:*:*:*:*
Jboss Operations Network by Redhat
cpe:2.3:a:redhat:jboss_operations_network:3.0:*:*:*:*:*:*:*
Utilities Testing Accelerator by Oracle
cpe:2.3:a:oracle:utilities_testing_accelerator:6.0.0.2.2:*:*:*:*:*:*:*
Communications Eagle Ftp Table Base Retrieval by Oracle
cpe:2.3:a:oracle:communications_eagle_ftp_table_base_retrieval:4.5:*:*:*:*:*:*:*
Jboss Data Grid by Redhat
cpe:2.3:a:redhat:jboss_data_grid:7.0.0:*:*:*:*:*:*:*
Enterprise Manager Base Platform by Oracle
cpe:2.3:a:oracle:enterprise_manager_base_platform:13.4.0.0:*:*:*:*:*:*:*
Business Process Management Suite by Oracle
cpe:2.3:a:oracle:business_process_management_suite:12.2.1.4.0:*:*:*:*:*:*:*
Communications Messaging Server by Oracle
cpe:2.3:a:oracle:communications_messaging_server:8.1:*:*:*:*:*:*:*
Communications Unified Inventory Management by Oracle
cpe:2.3:a:oracle:communications_unified_inventory_management:7.4.2:*:*:*:*:*:*:*
Business Process Management Suite by Oracle
cpe:2.3:a:oracle:business_process_management_suite:12.2.1.3.0:*:*:*:*:*:*:*
Hyperion Data Relationship Management by Oracle
cpe:2.3:a:oracle:hyperion_data_relationship_management:*:*:*:*:*:*:*:*
Tuxedo by Oracle
cpe:2.3:a:oracle:tuxedo:12.2.2.0.0:*:*:*:*:*:*:*
Integration Camel Quarkus by Redhat
cpe:2.3:a:redhat:integration_camel_quarkus:-:*:*:*:*:*:*:*
Weblogic Server by Oracle
cpe:2.3:a:oracle:weblogic_server:12.2.1.3.0:*:*:*:*:*:*:*
Fusion Middleware Common Libraries And Tools by Oracle
cpe:2.3:a:oracle:fusion_middleware_common_libraries_and_tools:12.2.1.4.0:*:*:*:*:*:*:*
Enterprise Linux by Redhat
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*