CVE-2021-44228

Aliases:GHSA-jfh8-c2jp-5v3qDEBIAN-CVE-2021-44228
Analyzed
Published: 10 Dec 2021, 00:00
Last modified:21 Oct 2025, 23:25

Vulnerability Summary

Overall Risk (default)
critical
90/100
CVSS Score
10 CRITICAL
v3.1 (cve.org)
EPSS Score
100% CRITICAL
100% probability +5.64%
KEV
Listed
CIRCL • CISA
2 listings
Ransomware
Known Use
Public exploits
19 found
Dark Web
Not detected

Timeline

10 Dec 2021, 00:00
Published
Vulnerability first disclosed
10 Dec 2021, 00:00
Added to CISA KEV
Apache Log4j2 Remote Code Execution Vulnerability
24 Dec 2021, 00:00
CISA Remediation Due
For all affected software assets for which updates exist, the only acceptable remediation actions are: 1) Apply updates; OR 2) remove affected assets from agency networks. Temporary mitigations using one of the measures provided at https://www.cisa.gov/uscert/ed-22-02-apache-log4j-recommended-mitigation-measures are only acceptable until updates are available.
21 Oct 2025, 23:25
Last Modified
Vulnerability information updated
03 Sept 2026, 00:00
Added to CIRCL KEV
Added to Known Exploited Vulnerabilities catalog

Description

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.

CVSS Metrics

  • v3.1CRITICALScore: 10CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • v3.1CRITICALScore: 10CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:H
  • v2.0HIGHScore: 9.3AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS Trends

Current EPSS score: 100.00% Percentile: 100%

Techniques & Countermeasures

  • CWE-20Improper Input Validation

    The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

  • CWE-400Uncontrolled Resource Consumption

    The product does not properly control the allocation and maintenance of a limited resource.

  • CWE-502Deserialization of Untrusted Data

    The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

  • CWE-917Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')

    The product constructs all or part of an expression language (EL) statement in a framework such as a Java Server Page (JSP) using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended EL statement before it is executed.

Affected Systems

  • apache software foundationapache log4j2

    ≥ 2.0-beta9, < log4j-core*

  • apachelog4j

    ≥ 2.0.1, < 2.3.1 | ≥ 2.4.0, < 2.12.2 | ≥ 2.13.0, < 2.15.0 | 2.0 | 2.0:beta9 | 2.0:rc1 | 2.0:rc2

  • applexcode

    < 13.3

  • bentleysynchro

    ≥ 6.1, < 6.2.4.2

  • bentleysynchro_4d

    < 6.4.3.2

  • ciscoadvanced_malware_protection_virtual_private_cloud_appliance

    < 3.5.4

  • ciscoautomated_subsea_tuning

    < 2.1.0 | 02.01.00

  • ciscobroadworks

    < 2021.11_1.162 | na

  • ciscobusiness_process_automation

    < 3.0.000.115 | ≥ 3.1.000.000, < 3.1.000.044 | ≥ 3.2.000.000, < 3.2.000.009

  • ciscocloud_connect

    < 12.6\(1\)

  • ciscocloudcenter

    < 4.10.0.16

  • ciscocloudcenter_cost_optimizer

    < 5.5.2

  • ciscocloudcenter_suite

    4.10.0.15 | 5.3.0 | 5.4.1 | 5.5.0 | 5.5.1

  • ciscocloudcenter_suite_admin

    < 5.3.1

  • ciscocloudcenter_workload_manager

    < 5.5.2

  • ciscocommon_services_platform_collector

    < 2.9.1.3 | ≥ 2.10.0, < 2.10.0.1 | 002.009\(000.000\) | 002.009\(000.001\) | 002.009\(000.002\) | 002.009\(001.000\) | 002.009\(001.001\) | 002.009\(001.002\) | 002.010\(000.000\)

  • ciscoconnected_analytics_for_network_deployment

    006.004.000.003 | 006.005.000. | 006.005.000.000 | 007.000.001 | 007.001.000 | 007.002.000 | 7.3 | 007.003.000 | 007.003.001.001 | 007.003.003 | 008.000.000 | 008.000.000.000.004

  • ciscoconnected_mobile_experiences

    na

  • ciscocontact_center_domain_manager

    < 12.5\(1\)

  • ciscocontact_center_management_portal

    < 12.5\(1\)

  • ciscocrosswork_data_gateway

    < 2.0.2 | 3.0.0

  • ciscocrosswork_network_automation

    na | 2.0.0 | 3.0.0 | 4.1.0 | 4.1.1

  • ciscocrosswork_network_controller

    < 2.0.1 | 3.0.0

  • ciscocrosswork_optimization_engine

    < 2.0.1 | 3.0.0

  • ciscocrosswork_platform_infrastructure

    < 4.0.1 | 4.1.0

  • ciscocrosswork_zero_touch_provisioning

    < 2.0.1 | 3.0.0

  • ciscocustomer_experience_cloud_agent

    < 1.12.1

  • ciscocx_cloud_agent

    001.012

  • ciscocyber_vision

    4.0.2

  • ciscocyber_vision_sensor_management_extension

    < 4.0.3 | 4.0.2

  • ciscodata_center_network_manager

    < 11.3\(1\) | 11.3\(1\)

  • ciscodna_center

    < 2.1.2.8 | ≥ 2.2.2.0, < 2.2.2.8 | ≥ 2.2.3.0, < 2.2.3.4 | 2.2.2.8

  • ciscodna_spaces

    na

  • ciscodna_spaces_connector

    na

  • ciscoemergency_responder

    < 11.5\(4\) | 11.5 | 11.5\(4.65000.14\) | 11.5\(4.66000.14\)

  • ciscoenterprise_chat_and_email

    < 12.0\(1\) | 12.0\(1\) | 12.5\(1\) | 12.6\(1\)

  • ciscoevolved_programmable_network_manager

    ≤ 4.1.1 | 3.0 | 3.1 | 4.0 | 4.1 | 5.0 | 5.1

  • ciscofinesse

    < 12.6\(1\) | 12.6\(1\) | 12.5\(1\):su1 | 12.5\(1\):su2 | 12.6\(1\):es01 | 12.6\(1\):es02 | 12.6\(1\):es03

  • ciscofirepower_threat_defense

    6.2.3 | 6.3.0 | 6.4.0 | 6.5.0 | 6.6.0 | 6.7.0 | 7.0.0 | 7.1.0

  • ciscofog_director

    na

  • ciscofxos

    6.2.3 | 6.3.0 | 6.4.0 | 6.5.0 | 6.6.0 | 6.7.0 | 7.0.0 | 7.1.0

  • ciscoidentity_services_engine

    < 2.4.0 | 2.4.0 | 002.004\(000.914\) | 002.006\(000.156\) | 002.007\(000.356\) | 003.000\(000.458\) | 003.001\(000.518\) | 003.002\(000.116\)

  • ciscointegrated_management_controller_supervisor

    < 2.3.2.1 | 002.003\(002.000\) | 2.3.2.0

  • ciscointersight_virtual_appliance

    < 1.0.9-361 | 1.0.9-343

  • ciscoiot_operations_dashboard

    na

  • ciscomobility_services_engine

    na

  • cisconetwork_assurance_engine

    < 6.0.2 | 6.0\(2.1912\)

  • cisconetwork_dashboard_fabric_controller

    11.0\(1\) | 11.1\(1\) | 11.2\(1\) | 11.3\(1\) | 11.4\(1\) | 11.5\(1\) | 11.5\(2\) | 11.5\(3\)

  • cisconetwork_insights_for_data_center

    6.0\(2.1914\)

  • cisconetwork_services_orchestrator

    < 5.3.5.1 | ≥ 5.4, < 5.4.5.2 | ≥ 5.5, < 5.5.4.1 | ≥ 5.6, < 5.6.3.1 | na

Showing first 50 affected entries in server-rendered view.

References (80)