CVE Feed

    Dashboard / CVE / CVE-2021-45046

    CVE-2021-45046

    It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in an information leak and remote code execution in some environments and local code execution in all environments. Log4j 2.16.0 (Java 8) and 2.12.2 (Java 7) fix this issue by removing support for message lookup patterns and disabling JNDI functionality by default.

    Published:Dec 14, 2021
    Last Modified:Oct 27, 2025
    EPS:Dec 14, 2021
    EPSS Score:0.9434
    CVSS Score:9

    CISA Notification

    Description

    It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in an information leak and remote code execution in some environments and local code execution in all environments. Log4j 2.16.0 (Java 8) and 2.12.2 (Java 7) fix this issue by removing support for message lookup patterns and disabling JNDI functionality by default.

    Required Action:

    Apply updates per vendor instructions.

    Notes:

    No extra notes provided.

    Due Date
    May 22, 2023
    1208 days ago
    Alert Date
    May 1, 2023
    1229 days ago

    Affected Products

    Vendor
    Apache
    Product
    Log4j
    Vendor
    Cvat
    Product
    Computer Vision Annotation Tool
    Vendor
    Debian
    Product
    Debian Linux
    Vendor
    Fedoraproject
    Product
    Fedora
    Vendor
    Intel
    Product
    Audio Development Kit
    Vendor
    Intel
    Product
    Datacenter Manager
    Vendor
    Intel
    Product
    Genomics Kernel Library
    Vendor
    Intel
    Product
    Oneapi
    Vendor
    Intel
    Product
    Secure Device Onboard
    Vendor
    Intel
    Product
    Sensor Solution Firmware Development Kit
    Vendor
    Intel
    Product
    System Debugger
    Vendor
    Intel
    Product
    System Studio
    Vendor
    Redhat
    Product
    Amq Streams
    Vendor
    Redhat
    Product
    Camel Quarkus
    Vendor
    Redhat
    Product
    Integration
    Vendor
    Redhat
    Product
    Jboss Data Grid
    Vendor
    Redhat
    Product
    Jboss Enterprise Application Platform
    Vendor
    Redhat
    Product
    Jboss Enterprise Application Platform Eus
    Vendor
    Redhat
    Product
    Jboss Fuse
    Vendor
    Redhat
    Product
    Logging
    Vendor
    Redhat
    Product
    Openshift
    Vendor
    Redhat
    Product
    Openshift Application Runtimes
    Vendor
    Siemens
    Product
    6bk1602-0aa12-0tp0
    Vendor
    Siemens
    Product
    6bk1602-0aa12-0tp0 Firmware
    Vendor
    Siemens
    Product
    6bk1602-0aa22-0tp0
    Vendor
    Siemens
    Product
    6bk1602-0aa22-0tp0 Firmware
    Vendor
    Siemens
    Product
    6bk1602-0aa32-0tp0
    Vendor
    Siemens
    Product
    6bk1602-0aa32-0tp0 Firmware
    Vendor
    Siemens
    Product
    6bk1602-0aa42-0tp0
    Vendor
    Siemens
    Product
    6bk1602-0aa42-0tp0 Firmware
    Vendor
    Siemens
    Product
    6bk1602-0aa52-0tp0
    Vendor
    Siemens
    Product
    6bk1602-0aa52-0tp0 Firmware
    Vendor
    Siemens
    Product
    Captial
    Vendor
    Siemens
    Product
    Comos
    Vendor
    Siemens
    Product
    Desigo Cc Advanced Reports
    Vendor
    Siemens
    Product
    Desigo Cc Info Center
    Vendor
    Siemens
    Product
    E-car Operation Center
    Vendor
    Siemens
    Product
    Energy Engage
    Vendor
    Siemens
    Product
    Energyip
    Vendor
    Siemens
    Product
    Energyip Prepay
    Vendor
    Siemens
    Product
    Gma-manager
    Vendor
    Siemens
    Product
    Head-end System Universal Device Integration System
    Vendor
    Siemens
    Product
    Industrial Edge Management
    Vendor
    Siemens
    Product
    Industrial Edge Management Hub
    Vendor
    Siemens
    Product
    Logo\! Soft Comfort
    Vendor
    Siemens
    Product
    Mendix
    Vendor
    Siemens
    Product
    Mindsphere
    Vendor
    Siemens
    Product
    Navigator
    Vendor
    Siemens
    Product
    Nx
    Vendor
    Siemens
    Product
    Opcenter Intelligence
    Vendor
    Siemens
    Product
    Operation Scheduler
    Vendor
    Siemens
    Product
    Sentron Powermanager
    Vendor
    Siemens
    Product
    Siguard Dsa
    Vendor
    Siemens
    Product
    Sipass Integrated
    Vendor
    Siemens
    Product
    Siveillance Command
    Vendor
    Siemens
    Product
    Siveillance Control Pro
    Vendor
    Siemens
    Product
    Siveillance Identity
    Vendor
    Siemens
    Product
    Siveillance Vantage
    Vendor
    Siemens
    Product
    Siveillance Viewpoint
    Vendor
    Siemens
    Product
    Solid Edge Cam Pro
    Vendor
    Siemens
    Product
    Solid Edge Harness Design
    Vendor
    Siemens
    Product
    Spectrum Power 4
    Vendor
    Siemens
    Product
    Spectrum Power 7
    Vendor
    Siemens
    Product
    Sppa-t3000 Ses3000
    Vendor
    Siemens
    Product
    Sppa-t3000 Ses3000 Firmware
    Vendor
    Siemens
    Product
    Teamcenter
    Vendor
    Siemens
    Product
    Tracealertserverplus
    Vendor
    Siemens
    Product
    Vesys
    Vendor
    Siemens
    Product
    Xpedition Enterprise
    Vendor
    Siemens
    Product
    Xpedition Package Integrator
    Vendor
    Sonicwall
    Product
    Email Security

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High