Deserialization of untrusted data in JMSAppender in Apache Log4j 1.2
65Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck.
ssvc Actcvss 7.5epss 81%
from disclosure to weapon
Published on NVDDec 14
VulnCheck+133d
exploitation probability
81%top 1% of all CVEs
observed exploitation
yesVulnCheck
What the vendors declare (VEX)
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Red HatVEX document ↗
Affected
6 products (7 components)
Red Hat OpenStack Platform 13 (Queens) · A-MQ Clients 2 · Red Hat AMQ Broker 7 · Red Hat JBoss Fuse Service Works 6 · Red Hat JBoss Operations Network 3 · and others 1
workaround: These are the possible mitigations for this flaw for releases version 1.x: - Comment out or remove JMSAppender in the Log4j configuration if it is used - Remove the JMSAppender class from the classpath…
Fixed
56 products (579 components)
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 Server · Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7 Server · Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 Server · Red Hat JBoss Web Server 3.1 for RHEL 7 · RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4 · and others 51
Not affected
19 products (2,282 components) — because the vulnerable code is not present in the product
Red Hat JBoss Enterprise Application Platform · Red Hat JBoss EAP 7.4 for RHEL 7 Server · Red Hat JBoss EAP 7.4 for RHEL 8 · Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 Server · Red Hat Enterprise Linux 7 · and others 14
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-44228. Note this issue only affects Log4j 1.2 when specifically configured to use JMSAppender, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
Apache Software Foundation · Apache Log4j 1.xReferences
https://access.redhat.com/security/cve/CVE-2021-4104https://github.com/apache/logging-log4j2/pull/608#issuecomment-990494126https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0033https://security.gentoo.org/glsa/202209-02https://security.gentoo.org/glsa/202310-16https://security.gentoo.org/glsa/202312-02https://security.gentoo.org/glsa/202312-04https://security.netapp.com/advisory/ntap-20211223-0007/https://www.cve.org/CVERecord?id=CVE-2021-44228https://www.kb.cert.org/vuls/id/930724https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.html