CVE-2021-4104 Details
Description
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-44228. Note this issue only affects Log4j 1.2 when specifically configured to use JMSAppender, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 20, 2023References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-502 | Deserialization of Untrusted Data | [email protected] |
| CWE-502 | Deserialization of Untrusted Data | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache log4j | 1.2 |
CPE
Remediation
| |
| fedoraproject fedora | 35 |
CPE
Remediation
| |
| redhat codeready studio | 12.0 |
CPE
Remediation
| |
| redhat integration camel k | All versions |
CPE
Remediation
| |
| redhat integration camel quarkus | All versions |
CPE
Remediation
| |
| redhat jboss a-mq | 6.0.0 7 |
CPE
Remediation
| |
| redhat jboss a-mq streaming | All versions |
CPE
Remediation
| |
| redhat jboss data grid | 7.0.0 |
CPE
Remediation
| |
| redhat jboss data virtualization | 6.0.0 |
CPE
Remediation
| |
| redhat jboss enterprise application platform | 6.0.0 7.0 |
CPE
Remediation
| |
| redhat jboss fuse | 6.0.0 7.0.0 |
CPE
Remediation
| |
| redhat jboss fuse service works | 6.0 |
CPE
Remediation
| |
| redhat jboss operations network | 3.0 |
CPE
Remediation
| |
| redhat jboss web server | 3.0 |
CPE
Remediation
| |
| redhat openshift application runtimes | All versions |
CPE
Remediation
| |
| redhat openshift container platform | 4.6 4.7 4.8 |
CPE
Remediation
| |
| redhat process automation | 7.0 |
CPE
Remediation
| |
| redhat single sign-on | 7.0 |
CPE
Remediation
| |
| redhat software collections | All versions |
CPE
Remediation
| |
| redhat enterprise linux | 6.0 7.0 8.0 |
CPE
Remediation
| |
| oracle advanced supply chain planning | 12.1 12.2 |
CPE
Remediation
| |
| oracle business intelligence | 5.9.0.0.0 12.2.1.3.0 12.2.1.4.0 |
CPE
Remediation
| |
| oracle business process management suite | 12.2.1.3.0 12.2.1.4.0 |
CPE
Remediation
| |
| oracle communications eagle ftp table base retrieval | 4.5 |
CPE
Remediation
| |
| oracle communications messaging server | 8.1 |
CPE
Remediation
| |
| oracle communications network integrity | 7.3.6 |
CPE
Remediation
| |
| oracle communications offline mediation controller | < 12.0.0.4.0 12.0.0.5.0 |
CPE
Remediation
| |
| oracle communications unified inventory management | 7.3.4 7.3.5 7.4.1 7.4.2 |
CPE
Remediation
| |
| oracle e-business suite cloud manager and cloud backup module | 2.2.1.1.1 |
CPE
Remediation
| |
| oracle enterprise manager base platform | 13.4.0.0 13.5.0.0 |
CPE
Remediation
| |
| oracle financial services revenue management and billing analytics | 2.7.0.0 2.7.0.1 2.8.0.0 |
CPE
Remediation
| |
| oracle fusion middleware common libraries and tools | 12.2.1.4.0 |
CPE
Remediation
| |
| oracle goldengate | All versions |
CPE
Remediation
| |
| oracle healthcare data repository | 8.1.0 |
CPE
Remediation
| |
| oracle hyperion data relationship management | < 11.2.8.0 |
CPE
Remediation
| |
| oracle hyperion infrastructure technology | < 11.2.8.0 |
CPE
Remediation
| |
| oracle identity management suite | 12.2.1.3.0 12.2.1.4.0 |
CPE
Remediation
| |
| oracle jdeveloper | 12.2.1.3.0 |
CPE
Remediation
| |
| oracle mysql enterprise monitor | <= 8.0.29 |
CPE
Remediation
| |
| oracle retail allocation | 14.1.3.2 15.0.3.1 16.0.3 19.0.1 |
CPE
Remediation
| |
| oracle retail extract transform and load | 13.2.5 |
CPE
Remediation
| |
| oracle stream analytics | All versions |
CPE
Remediation
| |
| oracle timesten grid | All versions |
CPE
Remediation
| |
| oracle tuxedo | 12.2.2.0.0 |
CPE
Remediation
| |
| oracle utilities testing accelerator | 6.0.0.1.1 6.0.0.2.2 6.0.0.3.1 |
CPE
Remediation
| |
| oracle weblogic server | 12.2.1.3.0 12.2.1.4.0 14.1.1.0.0 |
CPE
Remediation
| |
Change History
22 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 28, 2026 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Dec 22, 2023 | CVE Modified | [email protected] |
| Dec 20, 2023 | CVE Modified | [email protected] |
| Nov 7, 2023 | CVE Source Update | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Oct 26, 2023 | CVE Modified | [email protected] |
| Oct 5, 2022 | Modified Analysis | [email protected] |
| Sep 7, 2022 | CVE Modified | [email protected] |
| Jul 25, 2022 | CVE Modified | [email protected] |
| Apr 20, 2022 | CVE Modified | [email protected] |
| Feb 19, 2022 | Modified Analysis | [email protected] |
| Feb 7, 2022 | CVE Modified | [email protected] |
| Jan 18, 2022 | CVE Modified | [email protected] |
| Jan 6, 2022 | Modified Analysis | [email protected] |
| Dec 23, 2021 | CVE Modified | [email protected] |
| Dec 21, 2021 | CVE Modified | [email protected] |
| Dec 16, 2021 | Initial Analysis | [email protected] |
| Dec 16, 2021 | CVE Modified | [email protected] |