CVE-2021-45046
Description
It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in an information leak and remote code execution in some environments and local code execution in all environments. Log4j 2.16.0 (Java 8) and 2.12.2 (Java 7) fix this issue by removing support for message lookup patterns and disabling JNDI functionality by default.
EPSS (Exploit Prediction Scoring System)
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score Trend (Last 91 Days)
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
IncompleteCommon Consequences
Applicable Platforms
Siguard Dsa by Siemens
cpe:2.3:a:siemens:siguard_dsa:4.2:*:*:*:*:*:*:*
Sipass Integrated by Siemens
cpe:2.3:a:siemens:sipass_integrated:2.85:*:*:*:*:*:*:*
Spectrum Power 4 by Siemens
cpe:2.3:a:siemens:spectrum_power_4:*:*:*:*:*:*:*:*
Datacenter Manager by Intel
cpe:2.3:a:intel:datacenter_manager:-:*:*:*:*:*:*:*
Solid Edge Harness Design by Siemens
cpe:2.3:a:siemens:solid_edge_harness_design:*:*:*:*:*:*:*:*
Captial by Siemens
cpe:2.3:a:siemens:captial:*:*:*:*:*:*:*:*
Debian Linux by Debian
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
Audio Development Kit by Intel
cpe:2.3:a:intel:audio_development_kit:-:*:*:*:*:*:*:*
Gma-Manager by Siemens
cpe:2.3:a:siemens:gma-manager:*:*:*:*:*:*:*:*
Spectrum Power 7 by Siemens
cpe:2.3:a:siemens:spectrum_power_7:*:*:*:*:*:*:*:*
Log4J by Apache
cpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:*
Vesys by Siemens
cpe:2.3:a:siemens:vesys:2019.1:-:*:*:*:*:*:*
Log4J by Apache
cpe:2.3:a:apache:log4j:2.0:-:*:*:*:*:*:*
Spectrum Power 4 by Siemens
cpe:2.3:a:siemens:spectrum_power_4:4.70:sp7:*:*:*:*:*:*
Genomics Kernel Library by Intel
cpe:2.3:a:intel:genomics_kernel_library:-:*:*:*:*:*:*:*
Vesys by Siemens
cpe:2.3:a:siemens:vesys:2019.1:sp1912:*:*:*:*:*:*
Teamcenter by Siemens
cpe:2.3:a:siemens:teamcenter:*:*:*:*:*:*:*:*
Xpedition Package Integrator by Siemens
cpe:2.3:a:siemens:xpedition_package_integrator:-:*:*:*:*:*:*:*
Energyip Prepay by Siemens
cpe:2.3:a:siemens:energyip_prepay:3.7:*:*:*:*:*:*:*
System Debugger by Intel
cpe:2.3:a:intel:system_debugger:-:*:*:*:*:*:*:*
Secure Device Onboard by Intel
cpe:2.3:a:intel:secure_device_onboard:-:*:*:*:*:*:*:*
Solid Edge Harness Design by Siemens
cpe:2.3:a:siemens:solid_edge_harness_design:2020:-:*:*:*:*:*:*
Desigo Cc Advanced Reports by Siemens
cpe:2.3:a:siemens:desigo_cc_advanced_reports:5.1:*:*:*:*:*:*:*
Logo\! Soft Comfort by Siemens
cpe:2.3:a:siemens:logo\!_soft_comfort:*:*:*:*:*:*:*:*
Energyip Prepay by Siemens
cpe:2.3:a:siemens:energyip_prepay:3.8:*:*:*:*:*:*:*
Captial by Siemens
cpe:2.3:a:siemens:captial:2019.1:sp1912:*:*:*:*:*:*
Siveillance Command by Siemens
cpe:2.3:a:siemens:siveillance_command:*:*:*:*:*:*:*:*
Energy Engage by Siemens
cpe:2.3:a:siemens:energy_engage:3.1:*:*:*:*:*:*:*
Navigator by Siemens
cpe:2.3:a:siemens:navigator:*:*:*:*:*:*:*:*
Siveillance Viewpoint by Siemens
cpe:2.3:a:siemens:siveillance_viewpoint:*:*:*:*:*:*:*:*
6Bk1602-0Aa42-0Tp0 Firmware by Siemens
cpe:2.3:o:siemens:6bk1602-0aa42-0tp0_firmware:*:*:*:*:*:*:*:*
Desigo Cc Info Center by Siemens
cpe:2.3:a:siemens:desigo_cc_info_center:5.0:*:*:*:*:*:*:*
Energyip by Siemens
cpe:2.3:a:siemens:energyip:8.7:*:*:*:*:*:*:*
Log4J by Apache
cpe:2.3:a:apache:log4j:2.0:beta9:*:*:*:*:*:*
Solid Edge Cam Pro by Siemens
cpe:2.3:a:siemens:solid_edge_cam_pro:*:*:*:*:*:*:*:*
Desigo Cc Advanced Reports by Siemens
cpe:2.3:a:siemens:desigo_cc_advanced_reports:4.1:*:*:*:*:*:*:*
Comos by Siemens
cpe:2.3:a:siemens:comos:*:*:*:*:*:*:*:*
Tracealertserverplus by Siemens
cpe:2.3:a:siemens:tracealertserverplus:*:*:*:*:*:*:*:*
Mindsphere by Siemens
cpe:2.3:a:siemens:mindsphere:*:*:*:*:*:*:*:*
Mendix by Siemens
cpe:2.3:a:siemens:mendix:*:*:*:*:*:*:*:*
Siveillance Control Pro by Siemens
cpe:2.3:a:siemens:siveillance_control_pro:*:*:*:*:*:*:*:*
Oneapi by Intel
cpe:2.3:a:intel:oneapi:-:*:*:*:*:eclipse:*:*
Vesys by Siemens
cpe:2.3:a:siemens:vesys:*:*:*:*:*:*:*:*
Operation Scheduler by Siemens
cpe:2.3:a:siemens:operation_scheduler:*:*:*:*:*:*:*:*
Sentron Powermanager by Siemens
cpe:2.3:a:siemens:sentron_powermanager:4.1:*:*:*:*:*:*:*
Energyip by Siemens
cpe:2.3:a:siemens:energyip:8.6:*:*:*:*:*:*:*
6Bk1602-0Aa52-0Tp0 Firmware by Siemens
cpe:2.3:o:siemens:6bk1602-0aa52-0tp0_firmware:*:*:*:*:*:*:*:*
Fedora by Fedoraproject
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
Sipass Integrated by Siemens
cpe:2.3:a:siemens:sipass_integrated:2.80:*:*:*:*:*:*:*
Solid Edge Harness Design by Siemens
cpe:2.3:a:siemens:solid_edge_harness_design:2020:sp2002:*:*:*:*:*:*
Log4J by Apache
cpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:*
Spectrum Power 7 by Siemens
cpe:2.3:a:siemens:spectrum_power_7:2.30:-:*:*:*:*:*:*
Siguard Dsa by Siemens
cpe:2.3:a:siemens:siguard_dsa:4.3:*:*:*:*:*:*:*
Solid Edge Harness Design by Siemens
cpe:2.3:a:siemens:solid_edge_harness_design:2020:*:*:*:*:*:*:*
Siveillance Identity by Siemens
cpe:2.3:a:siemens:siveillance_identity:1.5:*:*:*:*:*:*:*
Vesys by Siemens
cpe:2.3:a:siemens:vesys:2019.1:*:*:*:*:*:*:*
Energyip by Siemens
cpe:2.3:a:siemens:energyip:8.5:*:*:*:*:*:*:*
Computer Vision Annotation Tool by Cvat
cpe:2.3:a:cvat:computer_vision_annotation_tool:-:*:*:*:*:*:*:*
Sentron Powermanager by Siemens
cpe:2.3:a:siemens:sentron_powermanager:4.2:*:*:*:*:*:*:*
Spectrum Power 7 by Siemens
cpe:2.3:a:siemens:spectrum_power_7:2.30:*:*:*:*:*:*:*
Spectrum Power 4 by Siemens
cpe:2.3:a:siemens:spectrum_power_4:4.70:-:*:*:*:*:*:*
Desigo Cc Advanced Reports by Siemens
cpe:2.3:a:siemens:desigo_cc_advanced_reports:5.0:*:*:*:*:*:*:*
Desigo Cc Info Center by Siemens
cpe:2.3:a:siemens:desigo_cc_info_center:5.1:*:*:*:*:*:*:*
Fedora by Fedoraproject
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
Desigo Cc Advanced Reports by Siemens
cpe:2.3:a:siemens:desigo_cc_advanced_reports:4.2:*:*:*:*:*:*:*
Xpedition Enterprise by Siemens
cpe:2.3:a:siemens:xpedition_enterprise:-:*:*:*:*:*:*:*
Head-End System Universal Device Integration System by Siemens
cpe:2.3:a:siemens:head-end_system_universal_device_integration_system:*:*:*:*:*:*:*:*
6Bk1602-0Aa32-0Tp0 Firmware by Siemens
cpe:2.3:o:siemens:6bk1602-0aa32-0tp0_firmware:*:*:*:*:*:*:*:*
Email Security by Sonicwall
cpe:2.3:a:sonicwall:email_security:*:*:*:*:*:*:*:*
E-Car Operation Center by Siemens
cpe:2.3:a:siemens:e-car_operation_center:*:*:*:*:*:*:*:*
Log4J by Apache
cpe:2.3:a:apache:log4j:2.0:rc1:*:*:*:*:*:*
Spectrum Power 7 by Siemens
cpe:2.3:a:siemens:spectrum_power_7:2.30:sp2:*:*:*:*:*:*
Desigo Cc Advanced Reports by Siemens
cpe:2.3:a:siemens:desigo_cc_advanced_reports:4.0:*:*:*:*:*:*:*
6Bk1602-0Aa12-0Tp0 Firmware by Siemens
cpe:2.3:o:siemens:6bk1602-0aa12-0tp0_firmware:*:*:*:*:*:*:*:*
Nx by Siemens
cpe:2.3:a:siemens:nx:*:*:*:*:*:*:*:*
Opcenter Intelligence by Siemens
cpe:2.3:a:siemens:opcenter_intelligence:*:*:*:*:*:*:*:*
Siveillance Identity by Siemens
cpe:2.3:a:siemens:siveillance_identity:1.6:*:*:*:*:*:*:*
6Bk1602-0Aa22-0Tp0 Firmware by Siemens
cpe:2.3:o:siemens:6bk1602-0aa22-0tp0_firmware:*:*:*:*:*:*:*:*
Energyip by Siemens
cpe:2.3:a:siemens:energyip:9.0:*:*:*:*:*:*:*
Spectrum Power 4 by Siemens
cpe:2.3:a:siemens:spectrum_power_4:4.70:sp8:*:*:*:*:*:*
Industrial Edge Management Hub by Siemens
cpe:2.3:a:siemens:industrial_edge_management_hub:*:*:*:*:*:*:*:*
Siguard Dsa by Siemens
cpe:2.3:a:siemens:siguard_dsa:4.4:*:*:*:*:*:*:*
Industrial Edge Management by Siemens
cpe:2.3:a:siemens:industrial_edge_management:*:*:*:*:*:*:*:*
Sppa-T3000 Ses3000 Firmware by Siemens
cpe:2.3:o:siemens:sppa-t3000_ses3000_firmware:*:*:*:*:*:*:*:*
Log4J by Apache
cpe:2.3:a:apache:log4j:2.0:rc2:*:*:*:*:*:*
Sensor Solution Firmware Development Kit by Intel
cpe:2.3:a:intel:sensor_solution_firmware_development_kit:-:*:*:*:*:*:*:*
Siveillance Vantage by Siemens
cpe:2.3:a:siemens:siveillance_vantage:*:*:*:*:*:*:*:*
Captial by Siemens
cpe:2.3:a:siemens:captial:2019.1:-:*:*:*:*:*:*
Debian Linux by Debian
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
System Studio by Intel
cpe:2.3:a:intel:system_studio:-:*:*:*:*:*:*:*