CVE-2021-4104
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-44228. Note this issue only affects Log4j 1.2 when specifically configured to use JMSAppender, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.
Published:Dec 10, 2021
Last Modified:May 28, 2026
EPS:Dec 14, 2021
EPSS Score:0.72202
CVSS Score:7.5
Affected Products
Vendor
Product
Action
Vendor
Apache
Product
Log4j
Apache
Log4j
Vendor
Fedoraproject
Product
Fedora
Fedoraproject
Fedora
Vendor
Oracle
Product
Advanced Supply Chain Planning
Oracle
Advanced Supply Chain Planning
Vendor
Oracle
Product
Business Intelligence
Oracle
Business Intelligence
Vendor
Oracle
Product
Business Process Management Suite
Oracle
Business Process Management Suite
Vendor
Oracle
Product
Communications Eagle Ftp Table Base Retrieval
Oracle
Communications Eagle Ftp Table Base Retrieval
Vendor
Oracle
Product
Communications Messaging Server
Oracle
Communications Messaging Server
Vendor
Oracle
Product
Communications Network Integrity
Oracle
Communications Network Integrity
Vendor
Oracle
Product
Communications Offline Mediation Controller
Oracle
Communications Offline Mediation Controller
Vendor
Oracle
Product
Communications Unified Inventory Management
Oracle
Communications Unified Inventory Management
Vendor
Oracle
Product
E-business Suite Cloud Manager And Cloud Backup Module
Oracle
E-business Suite Cloud Manager And Cloud Backup Module
Vendor
Oracle
Product
Enterprise Manager Base Platform
Oracle
Enterprise Manager Base Platform
Vendor
Oracle
Product
Financial Services Revenue Management And Billing Analytics
Oracle
Financial Services Revenue Management And Billing Analytics
Vendor
Oracle
Product
Fusion Middleware Common Libraries And Tools
Oracle
Fusion Middleware Common Libraries And Tools
Vendor
Oracle
Product
Goldengate
Oracle
Goldengate
Vendor
Oracle
Product
Healthcare Data Repository
Oracle
Healthcare Data Repository
Vendor
Oracle
Product
Hyperion Data Relationship Management
Oracle
Hyperion Data Relationship Management
Vendor
Oracle
Product
Hyperion Infrastructure Technology
Oracle
Hyperion Infrastructure Technology
Vendor
Oracle
Product
Identity Management Suite
Oracle
Identity Management Suite
Vendor
Oracle
Product
Jdeveloper
Oracle
Jdeveloper
Vendor
Oracle
Product
Mysql Enterprise Monitor
Oracle
Mysql Enterprise Monitor
Vendor
Oracle
Product
Retail Allocation
Oracle
Retail Allocation
Vendor
Oracle
Product
Retail Extract Transform And Load
Oracle
Retail Extract Transform And Load
Vendor
Oracle
Product
Stream Analytics
Oracle
Stream Analytics
Vendor
Oracle
Product
Timesten Grid
Oracle
Timesten Grid
Vendor
Oracle
Product
Tuxedo
Oracle
Tuxedo
Vendor
Oracle
Product
Utilities Testing Accelerator
Oracle
Utilities Testing Accelerator
Vendor
Oracle
Product
Weblogic Server
Oracle
Weblogic Server
Vendor
Redhat
Product
Codeready Studio
Redhat
Codeready Studio
Vendor
Redhat
Product
Enterprise Linux
Redhat
Enterprise Linux
Vendor
Redhat
Product
Integration Camel K
Redhat
Integration Camel K
Vendor
Redhat
Product
Integration Camel Quarkus
Redhat
Integration Camel Quarkus
Vendor
Redhat
Product
Jboss A-mq
Redhat
Jboss A-mq
Vendor
Redhat
Product
Jboss A-mq Streaming
Redhat
Jboss A-mq Streaming
Vendor
Redhat
Product
Jboss Amq
Redhat
Jboss Amq
Vendor
Redhat
Product
Jboss Data Grid
Redhat
Jboss Data Grid
Vendor
Redhat
Product
Jboss Data Virtualization
Redhat
Jboss Data Virtualization
Vendor
Redhat
Product
Jboss Enterprise Application Platform
Redhat
Jboss Enterprise Application Platform
Vendor
Redhat
Product
Jboss Enterprise Application Platform Eus
Redhat
Jboss Enterprise Application Platform Eus
Vendor
Redhat
Product
Jboss Enterprise Web Server
Redhat
Jboss Enterprise Web Server
Vendor
Redhat
Product
Jboss Fuse
Redhat
Jboss Fuse
Vendor
Redhat
Product
Jboss Fuse Service Works
Redhat
Jboss Fuse Service Works
Vendor
Redhat
Product
Jboss Operations Network
Redhat
Jboss Operations Network
Vendor
Redhat
Product
Jboss Web Server
Redhat
Jboss Web Server
Vendor
Redhat
Product
Openshift
Redhat
Openshift
Vendor
Redhat
Product
Openshift Application Runtimes
Redhat
Openshift Application Runtimes
Vendor
Redhat
Product
Openshift Container Platform
Redhat
Openshift Container Platform
Vendor
Redhat
Product
Process Automation
Redhat
Process Automation
Vendor
Redhat
Product
Red Hat Single Sign On
Redhat
Red Hat Single Sign On
Vendor
Redhat
Product
Rhel Aus
Redhat
Rhel Aus
Vendor
Redhat
Product
Rhel E4s
Redhat
Rhel E4s
Vendor
Redhat
Product
Rhel Els
Redhat
Rhel Els
Vendor
Redhat
Product
Rhel Eus
Redhat
Rhel Eus
Vendor
Redhat
Product
Rhel Software Collections
Redhat
Rhel Software Collections
Vendor
Redhat
Product
Rhel Tus
Redhat
Rhel Tus
Vendor
Redhat
Product
Rhev Manager
Redhat
Rhev Manager
Vendor
Redhat
Product
Rhosemc
Redhat
Rhosemc
Vendor
Redhat
Product
Single Sign-on
Redhat
Single Sign-on
Vendor
Redhat
Product
Software Collections
Redhat
Software Collections
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
