PT-2021-5597 · Apache+9 · Log4J+9

Published

2021-12-10

·

Updated

2026-05-22

·

CVE-2021-4104

CVSS v2.0

7.6

High

VectorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Log4j version 1.2
Description The issue is related to the JMSAppender in Log4j 1.2, which is vulnerable to deserialization of untrusted data. An attacker with write access to the Log4j configuration can provide TopicBindingName and TopicConnectionFactoryBindingName configurations, causing JMSAppender to perform JNDI requests that result in remote code execution. This issue only affects Log4j 1.2 when specifically configured to use JMSAppender, which is not the default. Apache Log4j 1.2 reached end of life in August 2015.
Recommendations For Log4j version 1.2, upgrade to Log4j 2 as it addresses numerous other issues from the previous versions. As a temporary workaround, consider disabling the JMSAppender until a patch is available. Restrict access to the JMSAppender configuration to minimize the risk of exploitation. Avoid using the TopicBindingName and TopicConnectionFactoryBindingName configurations in the affected Log4j configuration until the issue is resolved.

Exploit

Fix

RCE

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

ALSA-2022:0290
BDU:2022-00031
CESA-2021_5206
CESA-2022_0290
CVE-2021-4104
DLA-2905-1
GHSA-3W6P-8F82-GW8R
GHSA-FP5R-V3W9-4333
MGASA-2023-0141
OESA-2022-1513
OESA-2022-2065
OPENSUSE-SU-2021:1612-1
OPENSUSE-SU-2021:1631-1
OPENSUSE-SU-2021:4111-1
OPENSUSE-SU-2021:4112-1
OPENSUSE-SU-2021_1612-1
OPENSUSE-SU-2021_4111-1
OPENSUSE-SU-2021_4112-1
OPENSUSE-SU-2022:0038-1
OPENSUSE-SU-2022_0040-1
OPENSUSE-SU-2024:11681-1
OPENSUSE-SU-2024:11682-1
OPENSUSE-SU-2024:11696-1
RHSA-2021:5206
RHSA-2021:5269
RHSA-2021_5206
RHSA-2022:0289
RHSA-2022:0290
RHSA-2022:0291
RHSA-2022:0294
RHSA-2022:0436
RHSA-2022:0438
RHSA-2022:0447
RHSA-2022:0448
RHSA-2022:0475
RHSA-2022:0524
RHSA-2022:1296
RHSA-2022:1297
RHSA-2022:5459
RHSA-2022:5460
RHSA-2022_0290
RHSA-2024:10207
RHSA-2024:5856
RLSA-2022:0290
ROSA-SA-2024-2519
SUSE-SU-2021:14866-1
SUSE-SU-2021:4096-1
SUSE-SU-2021:4097-1
SUSE-SU-2021:4111-1
SUSE-SU-2021:4112-1
SUSE-SU-2021:4115-1
SUSE-SU-2021:4160-1
SUSE-SU-2021:4190-1
SUSE-SU-2021_14866-1
SUSE-SU-2021_4111-1
SUSE-SU-2021_4112-1
SUSE-SU-2021_4115-1
SUSE-SU-2022:0126-1
SUSE-SU-2022:0133-1
SUSE-SU-2022:0354-1
SUSE-SU-2022:0355-1
USN-5223-1
USN-5223-2

Affected Products

Almalinux
Astra Linux
Centos
Jira
Linuxmint
Log4J
Red Hat
Rocky Linux
Suse
Ubuntu