← Back to CVE List
Vulnerability Intelligence Report
Apache Log4j2 vulnerable to RCE via JDBC Appender when attacker controls configuration

CVE-2021-44832

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.

No Active Exploit Signals
CVSS Base Score
6.6
MEDIUM
Exploitability:0.8
Impact Score:5.9
EPSS Probability:97.91%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-20 ↗CWE-20 Improper Input Validation
CWE-74 ↗CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Affected Products & Versions

Vendor Product Affected Versions
Apache Software Foundation Apache Log4j2 log4j-core < 2.17.1 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
97.906%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityApache Software Foundation · Vendor · USA
Reserved2021-12-11T00:00:00
Published2021-12-28T19:35:11
Last Updated2026-05-29T18:53:46

LINK COPIED TO CLIPBOARD