CVE-2021-44228
Analyzed Analyzed - Analysis Complete

BaseFortify

Vulnerability report for CVE-2021-44228, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2021-12-10

Last updated on: 2026-08-11

Assigner: Apache Software Foundation

Description

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2021-12-10
Last Modified
2026-08-11
Generated
2026-08-15
AI Q&A
2024-11-28
EPSS Evaluated
2025-08-20
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
cisco secure_firewall_threat_defense 7.1.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-502 The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.
CWE-917 The product constructs all or part of an expression language (EL) statement in a framework such as a Java Server Page (JSP) using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended EL statement before it is executed.
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability, known as CVE-2021-44228, affects a software called Apache Log4j2. It allows attackers to run harmful code on a server if they can control the messages that are logged. This is possible because the software did not properly secure certain features that let it connect to external servers. The issue has been fixed in later versions of the software.

Impact Analysis

If you use software that relies on Apache Log4j2 and it is affected by this vulnerability, attackers could potentially take control of your system. This could lead to unauthorized access to sensitive information, data loss, or even complete system compromise.

Compliance Impact

This vulnerability could put your organization at risk of non-compliance with regulations like GDPR and HIPAA. If sensitive data is exposed or compromised due to this vulnerability, it could lead to legal penalties and damage to your reputation.

Mitigation Strategies

From log4j version 2.15.0, the vulnerable behavior has been disabled by default. To fully mitigate the vulnerability, upgrade to log4j version 2.16.0 or later, or apply the necessary patches if available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2021-44228. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart