CVE Vulnerabilities

CVE-2021-4104

Deserialization of Untrusted Data

Published: Dec 14, 2021 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-44228. Note this issue only affects Log4j 1.2 when specifically configured to use JMSAppender, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.

Weakness

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Affected Software

NameVendorStart VersionEnd Version
Log4jApache1.2 (including)1.2 (including)
EAP 6.4.24 releaseRedHat*
EAP 6.4 log4j asyncRedHatlog4j*
Red Hat Data Grid 7.3.9RedHatlog4j*
Red Hat Enterprise Linux 6 Extended Lifecycle SupportRedHatlog4j-0:1.2.14-6.5.el6_10*
Red Hat Enterprise Linux 7RedHatlog4j-0:1.2.17-17.el7_4*
Red Hat Enterprise Linux 7.3 Advanced Update SupportRedHatlog4j-0:1.2.17-16.el7_3*
Red Hat Enterprise Linux 7.4 Advanced Update SupportRedHatlog4j-0:1.2.17-17.el7_4*
Red Hat Enterprise Linux 7.6 Advanced Update Support(Disable again in 2026 - SPRHEL-7118)RedHatlog4j-0:1.2.17-17.el7_4*
Red Hat Enterprise Linux 7.6 Telco Extended Update SupportRedHatlog4j-0:1.2.17-17.el7_4*
Red Hat Enterprise Linux 7.6 Update Services for SAP SolutionsRedHatlog4j-0:1.2.17-17.el7_4*
Red Hat Enterprise Linux 7.7 Advanced Update SupportRedHatlog4j-0:1.2.17-17.el7_4*
Red Hat Enterprise Linux 7.7 Telco Extended Update SupportRedHatlog4j-0:1.2.17-17.el7_4*
Red Hat Enterprise Linux 7.7 Update Services for SAP SolutionsRedHatlog4j-0:1.2.17-17.el7_4*
Red Hat Enterprise Linux 8RedHatparfait:0.5-8050020220124063900.6b489b78*
Red Hat Enterprise Linux 8.1 Update Services for SAP SolutionsRedHatparfait:0.5-8010020220124232535.d5701770*
Red Hat Enterprise Linux 8.2 Extended Update SupportRedHatparfait:0.5-8020020220124231008.1c5d4e8a*
Red Hat Enterprise Linux 8.4 Extended Update SupportRedHatparfait:0.5-8040020220124230039.d304d9ed*
Red Hat Fuse 7.10.1RedHatlog4j*
Red Hat Fuse/AMQ 6.3.20RedHatlog4j*
Red Hat Fuse/AMQ 6.3.20RedHatlog4j*
Red Hat JBoss Data Virtualization 6.4.8.SP1RedHatlog4j*
Red Hat JBoss Data Virtualization 6.4.8.SP2RedHatlog4j*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatlog4j-eap6-0:1.2.17-3.redhat_00008.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatlog4j-jboss-logmanager-0:1.1.4-3.Final_redhat_00002.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-appclient-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjbossas-appclient-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjbossas-bundles-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-cli-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-client-all-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-clustering-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-cmp-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-configadmin-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-connector-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-controller-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-controller-client-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjbossas-core-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-core-security-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-deployment-repository-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-deployment-scanner-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjbossas-domain-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-domain-http-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-domain-management-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-ee-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-ee-deployment-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-ejb3-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-embedded-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-host-controller-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-jacorb-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjbossas-javadocs-0:7.5.24-1.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-jaxr-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-jaxrs-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-jdr-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-jmx-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-jpa-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-jsf-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-jsr77-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-logging-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-mail-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-management-client-content-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-messaging-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-modcluster-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjbossas-modules-eap-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-naming-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-network-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-osgi-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-osgi-configadmin-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-osgi-service-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-picketlink-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-platform-mbean-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-pojo-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-process-controller-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjbossas-product-eap-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-protocol-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-remoting-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-sar-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-security-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-server-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjbossas-standalone-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-system-jmx-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-threads-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-transactions-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-version-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-web-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-webservices-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjbossas-welcome-content-eap-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-weld-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-xts-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjbossts-1:4.17.45-2.Final_redhat_2.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjbossweb-0:7.5.32-2.Final_redhat_1.2.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatlog4j-eap6-0:1.2.17-3.redhat_00008.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatlog4j-jboss-logmanager-0:1.1.4-3.Final_redhat_00002.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-appclient-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjbossas-appclient-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjbossas-bundles-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-cli-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-client-all-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-clustering-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-cmp-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-configadmin-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-connector-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-controller-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-controller-client-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjbossas-core-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-core-security-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-deployment-repository-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-deployment-scanner-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjbossas-domain-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-domain-http-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-domain-management-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-ee-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-ee-deployment-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-ejb3-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-embedded-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-host-controller-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-jacorb-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjbossas-javadocs-0:7.5.24-1.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-jaxr-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-jaxrs-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-jdr-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-jmx-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-jpa-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-jsf-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-jsr77-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-logging-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-mail-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-management-client-content-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-messaging-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-modcluster-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjbossas-modules-eap-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-naming-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-network-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-osgi-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-osgi-configadmin-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-osgi-service-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-picketlink-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-platform-mbean-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-pojo-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-process-controller-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjbossas-product-eap-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-protocol-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-remoting-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-sar-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-security-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-server-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjbossas-standalone-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-system-jmx-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-threads-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-transactions-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-version-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-web-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-webservices-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjbossas-welcome-content-eap-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-weld-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-xts-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjbossts-1:4.17.45-2.Final_redhat_2.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjbossweb-0:7.5.32-2.Final_redhat_1.2.ep6.el7*
Red Hat JBoss Enterprise Application Platform 7RedHatlog4j*
Red Hat JBoss Enterprise Application Platform 7RedHatlog4j*
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7RedHateap7-log4j-jboss-logmanager-0:1.2.2-1.Final_redhat_00002.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7RedHateap7-apache-cxf-0:3.4.10-1.SP1_redhat_00001.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7RedHateap7-avro-0:1.7.6-8.redhat_00003.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7RedHateap7-h2database-0:1.4.197-3.redhat_00004.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7RedHateap7-jboss-annotations-api_1.3_spec-0:2.0.1-4.Final_redhat_00001.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7RedHateap7-jboss-marshalling-0:2.0.15-1.Final_redhat_00001.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7RedHateap7-jboss-server-migration-0:1.7.2-12.Final_redhat_00013.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7RedHateap7-jboss-xnio-base-0:3.7.13-1.Final_redhat_00001.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7RedHateap7-log4j-jboss-logmanager-0:1.2.2-2.Final_redhat_00002.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7RedHateap7-wildfly-0:7.3.11-4.GA_redhat_00002.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7RedHateap7-wss4j-0:2.3.3-2.redhat_00001.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7RedHateap7-xalan-j2-0:2.7.1-38.redhat_00015.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7RedHateap7-xml-security-0:2.2.3-2.redhat_00001.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8RedHateap7-log4j-jboss-logmanager-0:1.2.2-1.Final_redhat_00002.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8RedHateap7-log4j-0:2.17.1-1.redhat_00001.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7RedHateap7-log4j-jboss-logmanager-0:1.2.2-1.Final_redhat_00002.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7RedHateap7-log4j-0:2.17.1-1.redhat_00001.1.el7eap*
Red Hat JBoss Web Server 3.1RedHatlog4j-eap6*
Red Hat JBoss Web Server 3 for RHEL 7RedHatlog4j-eap6-0:1.2.17-3.redhat_00008.1.ep6.el7*
Red Hat JBoss Web Server 3 for RHEL 7RedHattomcat7-0:7.0.70-46.ep7.el7*
Red Hat JBoss Web Server 3 for RHEL 7RedHattomcat8-0:8.0.36-49.ep7.el7*
Red Hat JBoss Web Server 3 for RHEL 7RedHattomcat-native-0:1.2.23-26.redhat_26.ep7.el7*
Red Hat OpenShift Container Platform 4.6RedHatopenshift4/ose-metering-hadoop:v4.6.0-202112150545.p0.gf381145.assembly.art3595*
Red Hat OpenShift Container Platform 4.6RedHatopenshift4/ose-metering-presto:v4.6.0-202112150545.p0.g190688a.assembly.art3595*
Red Hat OpenShift Container Platform 4.6RedHatopenshift4/ose-metering-hive:v4.6.0-202112160147.p0.gf139e12.assembly.stream*
Red Hat OpenShift Container Platform 4.7RedHatopenshift4/ose-metering-hadoop:v4.7.0-202112150631.p0.g6046504.assembly.4.7.40*
Red Hat OpenShift Container Platform 4.7RedHatopenshift4/ose-metering-presto:v4.7.0-202112150631.p0.gd502108.assembly.4.7.40*
Red Hat OpenShift Container Platform 4.7RedHatopenshift4/ose-metering-hive:v4.7.0-202112160422.p0.g6a2b6aa.assembly.4.7.40*
Red Hat OpenShift Container Platform 4.8RedHatopenshift4/ose-metering-hadoop:v4.8.0-202112150431.p0.gebd9cb4.assembly.art3599*
Red Hat OpenShift Container Platform 4.8RedHatopenshift4/ose-metering-presto:v4.8.0-202112150431.p0.g4b934ae.assembly.art3599*
Red Hat OpenShift Container Platform 4.8RedHatopenshift4/ose-metering-hive:v4.8.0-202112160147.p0.g5672016.assembly.stream*
Red Hat Single Sign-On 7.4.10RedHatlog4j*
Red Hat Single Sign-On 7.5 for RHEL 7RedHatrh-sso7-keycloak-0:15.0.4-1.redhat_00003.1.el7sso*
Red Hat Single Sign-On 7.5 for RHEL 8RedHatrh-sso7-keycloak-0:15.0.4-1.redhat_00003.1.el8sso*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatrh-maven36-log4j12-0:1.2.17-23.3.el7*
Red Hat Virtualization Engine 4.4RedHatorg.ovirt.engine-root-0:4.4.10.6-1*
Red Hat Virtualization Engine 4.4RedHatsnmp4j-0:3.6.4-0.1.el8ev*
RHEL-8 based Middleware ContainersRedHatrh-sso-7/sso74-openshift-rhel8:7.4-45*
RHEL-8 based Middleware ContainersRedHatrh-sso-7/sso74-openj9-openshift-rhel8:7.4-60*
RHEL-8 based Middleware ContainersRedHatrh-sso-7/sso75-openshift-rhel8:7.5-17*
RHEL-8 based Middleware ContainersRedHatrh-sso-7/sso7-rhel8-operator-bundle:7.5.1-9*
RHSSO 7.5.1RedHatlog4j*
Apache-log4j1.2Ubuntubionic*
Apache-log4j1.2Ubuntuesm-apps/bionic*
Apache-log4j1.2Ubuntuesm-apps/focal*
Apache-log4j1.2Ubuntuesm-apps/xenial*
Apache-log4j1.2Ubuntuesm-infra-legacy/trusty*
Apache-log4j1.2Ubuntufocal*
Apache-log4j1.2Ubuntuhirsute*
Apache-log4j1.2Ubuntuimpish*
Apache-log4j1.2Ubuntulunar*
Apache-log4j1.2Ubuntumantic*
Apache-log4j1.2Ubuntutrusty/esm*
Apache-log4j1.2Ubuntuupstream*
Apache-log4j1.2Ubuntuxenial*

Potential Mitigations

  • Make fields transient to protect them from deserialization.
  • An attempt to serialize and then deserialize a class containing transient fields will result in NULLs where the transient data should be. This is an excellent way to prevent time, environment-based, or sensitive variables from being carried over and used improperly.

References