CVE-2021-45105

Aliases:GHSA-p6xc-xr62-6r2g
Modified
Published: 18 Dec 2021, 11:55
Last modified:29 May 2026, 11:45

Vulnerability Summary

Overall Risk (default)
medium
38/100
CVSS Score
5.9 MEDIUM
v3.1 (nvd)
EPSS Score
74.02% CRITICAL
74% probability +3.59%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

18 Dec 2021, 11:55
Published
Vulnerability first disclosed
29 May 2026, 11:45
Last Modified
Vulnerability information updated

Description

Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.

CVSS Metrics

  • v3.1MEDIUMScore: 5.9CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
  • v3.1HIGHScore: 8.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
  • v2.0MEDIUMScore: 4.3AV:N/AC:M/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 74.02% Percentile: 99%

Techniques & Countermeasures

  • CWE-20Improper Input Validation

    The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

  • CWE-674Uncontrolled Recursion

    The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

Affected Systems

  • apache software foundationapache log4j2

    ≥ log4j-core, < 2.17.0

  • apachelog4j

    ≥ 2.0, < 2.3.1 | ≥ 2.4, < 2.12.3 | ≥ 2.13.0, ≤ 2.16.0

  • debiandebian_linux

    10.0 | 11.0

  • org.apache.logging.log4jlog4j-core

    ≥ 2.4.0, < 2.12.3 | ≥ 2.13.0, < 2.17.0 | < 2.3.1

  • org.ops4j.pax.loggingpax-logging-log4j2

    ≥ 1.8.0, < 1.9.2 | ≥ 1.10.0, < 1.10.9 | ≥ 1.11.0, < 1.11.12 | ≥ 2.0.0, < 2.0.13

  • netappcloud_manager

    na

  • oracleagile_engineering_data_management

    6.2.1.0

  • oracleagile_plm

    9.3.6

  • oracleagile_plm_mcad_connector

    3.6

  • oracleautovue_for_agile_product_lifecycle_management

    21.0.2

  • oraclebanking_deposits_and_lines_of_credit_servicing

    2.12.0

  • oraclebanking_enterprise_default_management

    2.7.1 | 2.12.0

  • oraclebanking_loans_servicing

    2.12.0

  • oraclebanking_party_management

    2.7.0

  • oraclebanking_payments

    14.5

  • oraclebanking_platform

    2.6.2 | 2.7.1 | 2.12.0

  • oraclebanking_trade_finance

    14.5

  • oraclebanking_treasury_management

    14.5

  • oraclebusiness_intelligence

    5.5.0.0.0

  • oraclecommunications_asap

    7.3

  • oraclecommunications_billing_and_revenue_management

    12.0.0.4 | 12.0.0.5

  • oraclecommunications_cloud_native_core_console

    1.9.0

  • oraclecommunications_cloud_native_core_network_function_cloud_native_environment

    1.10.0

  • oraclecommunications_cloud_native_core_network_repository_function

    1.15.0 | 1.15.1

  • oraclecommunications_cloud_native_core_network_slice_selection_function

    1.8.0

  • oraclecommunications_cloud_native_core_policy

    1.15.0

  • oraclecommunications_cloud_native_core_security_edge_protection_proxy

    1.7.0

  • oraclecommunications_cloud_native_core_service_communication_proxy

    1.15.0

  • oraclecommunications_cloud_native_core_unified_data_repository

    1.15.0

  • oraclecommunications_convergence

    3.0.2.2.0 | 3.0.3.0

  • oraclecommunications_convergent_charging_controller

    ≥ 12.0.1.0.0, ≤ 12.0.4.0.0 | 6.0.1.0.0

  • oraclecommunications_diameter_signaling_router

    ≥ 8.3.0.0, ≤ 8.5.1.0

  • oraclecommunications_eagle_element_management_system

    46.6

  • oraclecommunications_eagle_ftp_table_base_retrieval

    4.5

  • oraclecommunications_element_manager

    < 9.0

  • oraclecommunications_evolved_communications_application_server

    7.1

  • oraclecommunications_interactive_session_recorder

    6.3 | 6.4

  • oraclecommunications_ip_service_activator

    7.4.0

  • oraclecommunications_messaging_server

    8.1

  • oraclecommunications_network_charging_and_control

    ≥ 12.0.1.0.0, ≤ 12.0.4.0.0 | 6.0.1.0.0

  • oraclecommunications_network_integrity

    7.3.6

  • oraclecommunications_performance_intelligence_center

    10.4.0.3

  • oraclecommunications_pricing_design_center

    12.0.0.4 | 12.0.0.5

  • oraclecommunications_service_broker

    6.2

  • oraclecommunications_services_gatekeeper

    7.0

  • oraclecommunications_session_report_manager

    < 9.0

  • oraclecommunications_session_route_manager

    < 9.0

  • oraclecommunications_unified_inventory_management

    7.3.5 | 7.4.1 | 7.4.2

  • oraclecommunications_user_data_repository

    12.4

  • oraclecommunications_webrtc_session_controller

    7.2.0.0 | 7.2.1

Showing first 50 affected entries in server-rendered view.

References (20)