Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2021-4104 Details

Description

JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-44228. Note this issue only affects Log4j 1.2 when specifically configured to use JMSAppender, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
https://access.redhat.com/security/cve/CVE-2021-4104 CVE
https://github.com/apache/logging-log4j2/pull/608#issuecomment-990494126 CVE
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0033 CVE
https://security.gentoo.org/glsa/202209-02 CVE
https://security.gentoo.org/glsa/202310-16 CVE

see all 28 references

Weakness Enumeration

CWE-IDCWE NameSource
CWE-502Deserialization of Untrusted Data[email protected]
CWE-502Deserialization of Untrusted Data[email protected]

Affected Products

ProductVersions

Change History

22 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2021-4104
NVD Published Date:
Dec 14, 2021
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2021-4104 Details - Not Deferred