Vulnslist

Cisco vulnerabilities by product, model, software, and advisory.

CVE-2021-44832

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.

SeverityMEDIUM
CVSS6.6
CWECWE-20
KEV
Published
Modified

Related Products

Product Advisory Evidence
Cisco Unity Connection cisco-sa-apache-log4j-qRuKNEbd Cisco OpenVuln
Cisco Unity cisco-sa-apache-log4j-qRuKNEbd Cisco OpenVuln
Cisco Unified Communications Manager IM and Presence Service cisco-sa-apache-log4j-qRuKNEbd Cisco OpenVuln
Cisco Unified Communications Manager / Cisco Unity Connection cisco-sa-apache-log4j-qRuKNEbd Cisco OpenVuln
Cisco Unified Communications Manager cisco-sa-apache-log4j-qRuKNEbd Cisco OpenVuln
Cisco Network Services Orchestrator cisco-sa-apache-log4j-qRuKNEbd Cisco OpenVuln
Cisco Evolved Programmable Network Manager (EPNM) cisco-sa-apache-log4j-qRuKNEbd Cisco OpenVuln