Vulnerability Intelligence Report
Apache Log4j2 vulnerable to RCE via JDBC Appender when attacker controls configuration
CVE-2021-44832
Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.
No Active Exploit Signals
CVSS Base Score
6.6
MEDIUM
Exploitability:0.8
Impact Score:5.9
EPSS Probability:97.91%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-20 ↗CWE-20 Improper Input Validation
CWE-74 ↗CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Apache Software Foundation | Apache Log4j2 | log4j-core < 2.17.1 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
97.906%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Apache Software Foundation · Vendor · USA |
| Reserved | 2021-12-11T00:00:00 |
| Published | 2021-12-28T19:35:11 |
| Last Updated | 2026-05-29T18:53:46 |
Community Chatter & Buzz