ENISA EUVD · EUVD-2021-34768Known-exploited evidence recordedApache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.
Official EUVD record ↗BSI · German · WID-SEC-2022-0351Apache log4j: Schwachstelle ermöglicht CodeausführungEin entfernter, anonymer Angreifer kann eine Schwachstelle in Apache log4j ausnutzen, um beliebigen Programmcode auszuführen.
Official advisory ↗BSI · German · WID-SEC-2024-0064Juniper Produkte: Mehrere SchwachstellenEin Angreifer aus dem angrenzenden Netzwerk oder ein entfernter, anonymer, authentisierter, lokaler oder physischer Angreifer kann mehrere Schwachstellen in Juniper JUNOS, Juniper JUNOS Evolved, Juniper SRX Series, Juniper EX Series, Juniper QFX Series, Juniper ACX Series, Juniper PTX Series und Juniper MX Series ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen und seine Berechtigungen zu erweitern.
Official advisory ↗BSI · German · WID-SEC-2023-0063Juniper Junos Space: Mehrere SchwachstellenEin Angreifer aus dem angrenzenden Netzwerk oder ein entfernter anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Juniper Junos Space ausnutzen, um Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand auszulösen, beliebigen Code auszuführen und seine Privilegien zu erweitern.
Official advisory ↗Canadian Centre for Cyber Security · English · AL22-010APT actors continue exploitation of Log4Shell in VMware productsAn Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.
Official advisory ↗Canadian Centre for Cyber Security · English · AV21-664Fortinet security advisoryOn 12 December 2021 Fortinet published a PSIRT Advisory to investigate and address a critical vulnerability, tracked as CVE-2021-44228, which may affect multiple products using the Apache Log4j logging utility.
Exploitation of this vulnerability could lead to remote code execution.
Official advisory ↗Canadian Centre for Cyber Security · English · AV21-650Oracle security advisoryOn 10 December 2021 Oracle published a Security Advisory to address critical vulnerabilities which may affect multiple products using the Apache Log4j logging utility.
Exploitation of these vulnerabilities could lead to remote code execution.
Official advisory ↗Canadian Centre for Cyber Security · English · AV21-652Palo Alto Networks security advisoryOn 10 December 2021 Palo Alto Networks published a Security Advisory to address critical vulnerabilities which may affect multiple products using the Apache Log4j logging utility.
Exploitation of these vulnerabilities could lead to remote code execution.
Official advisory ↗Canadian Centre for Cyber Security · English · AV21-657Citrix security advisoryOn 11 December 2021 Citrix published a Security Advisory to address critical vulnerabilities which may affect multiple products using the Apache Log4j logging utility.
Exploitation of these vulnerabilities could lead to remote code execution.
Official advisory ↗Canadian Centre for Cyber Security · English · AV21-635Cisco security advisoryOn 10 December 2021 Cisco published a Security Advisory to investigate and address a critical vulnerability, tracked as CVE-2021-44228, which may affect multiple products using the Apache Log4j logging utility.
Exploitation of this vulnerability could lead to remote code execution.
Official advisory ↗Canadian Centre for Cyber Security · English · AV21-637VMware security advisoryOn 10 December 2021 VMware published a Security Advisory to investigate and address a critical vulnerability, tracked as CVE-2021-44228, which may affect multiple products using the Apache Log4j logging utility.
Exploitation of this vulnerability could lead to remote code execution.
Official advisory ↗Canadian Centre for Cyber Security · English · AV21-639Intel security advisoryOn 14 December 2021 Intel published a Security Advisory to investigate and address a critical vulnerability, tracked as CVE-2021-44228, which may affect multiple products using the Apache Log4j logging utility.
Exploitation of this vulnerability could lead to remote code execution.
Official advisory ↗Canadian Centre for Cyber Security · English · AV21-640[Control systems] ABB security advisoryOn 15 December 2021 ABB published a Security Advisory to investigate and address a critical vulnerability, tracked as CVE-2021-44228, which may affect multiple products using the Apache Log4j logging utility.
Exploitation of this vulnerability could lead to remote code execution.
Official advisory ↗Canadian Centre for Cyber Security · English · AV21-627IBM security advisoryBetween 6 and 12 December 2021 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:
IBM App Connect Enterprise
https://www.ibm.com/blogs/psirt/security-bulletin-ibm-app-connect-enterprise-v11-is-affected-by-vulnerabilities-in-node-js-cve-2021-23358-3/
Official advisory ↗Canadian Centre for Cyber Security · English · AL21-019Active exploitation of Apache Log4j vulnerability - update 7On 10 December 2021, Apache released a Security Advisory Footnote 1 Footnote 2 highlighting a critical remote code execution vulnerability in Log4j, a widely deployed Java-based logging utility. Open-source reporting indicates that active scanning and exploitation of this vulnerability have been observed.
Official advisory ↗Cyber Security Agency of Singapore · English · CSA-SB-20211215Security Bulletin 15 Dec 2021The Cyber Security Agency of Singapore included this CVE in its official Security Bulletin 15 Dec 2021, published on 15 December 2021. Open the linked bulletin for the product, severity and reference information published in that issue.
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0855Multiples vulnérabilités dans les produits Juniper Networksecord?id=CVE-2019-12900
Référence CVE CVE-2020-11023
https://www.cve.org/CVERecord?id=CVE-2020-11023
Référence CVE CVE-2021-22146
https://www.cve.org/CVERecord?id=CVE-2021-22146
Référence CVE CVE-2021-3903
https://www.cve.org/CVERecord?id=CVE-2021-3903
Référence CVE CVE-2021-40153
https://www.cve.org/CVERecord?id=CVE-2021-40153
Référence CVE CVE-2021-4104
https://www.cve.org/CVERecord?id=CVE-2021-4104
Référence CVE CVE-2021-41043
https://www.cve.org/CVERecord?id=CVE-2021-41043
Référence CVE CVE-2021-41072
https://www.cve.org/CVERecord?id=CVE-2021-41072
Référence CVE CVE-2021-42550
https://www.cve.org/CVERecord?id=CVE-2021-42550
Référence CVE CVE-2021-44228
https://www.cve.org/CVERecord?id=CVE-2021-44228
Référence CVE CVE-2021-44832
https://www.cve.org/CVERecord?id=CVE-2021-44832
Référence CVE CVE-2021-45046
https://www.cve.org/CVERecord?id=CVE-2021-45046
Référence CVE CVE-2021-45105
https://www.cve.org/CVERecord?id=CVE-2021-45105
Référence CVE CVE-2021-47606
https://www.cve.org/CVERecord?id=CVE-2021-47606
Référence CVE CVE-2022-24805
https://www.cve.org/CVERecord?id=CVE-2022-24805
Référence CVE CVE-2022-24806
https://www.cve.org/CVERecord?id=CVE-2022-24806
Référence CVE CVE-2022-24807
https://www.cve.org/CVERecord?id=CVE-2022-24807
Référence CVE CVE-2022-24808
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0756Multiples vulnérabilités dans les produits VMwareCVERecord?id=CVE-2021-35938
Référence CVE CVE-2021-35939
https://www.cve.org/CVERecord?id=CVE-2021-35939
Référence CVE CVE-2021-35942
https://www.cve.org/CVERecord?id=CVE-2021-35942
Référence CVE CVE-2021-38604
https://www.cve.org/CVERecord?id=CVE-2021-38604
Référence CVE CVE-2021-3875
https://www.cve.org/CVERecord?id=CVE-2021-3875
Référence CVE CVE-2021-3999
https://www.cve.org/CVERecord?id=CVE-2021-3999
Référence CVE CVE-2021-4122
https://www.cve.org/CVERecord?id=CVE-2021-4122
Référence CVE CVE-2021-4193
https://www.cve.org/CVERecord?id=CVE-2021-4193
Référence CVE CVE-2021-43618
https://www.cve.org/CVERecord?id=CVE-2021-43618
Référence CVE CVE-2021-44228
https://www.cve.org/CVERecord?id=CVE-2021-44228
Référence CVE CVE-2021-44832
https://www.cve.org/CVERecord?id=CVE-2021-44832
Référence CVE CVE-2021-45105
https://www.cve.org/CVERecord?id=CVE-2021-45105
Référence CVE CVE-2021-46848
https://www.cve.org/CVERecord?id=CVE-2021-46848
Référence CVE CVE-2022-0213
https://www.cve.org/CVERecord?id=CVE-2022-0213
Référence CVE CVE-2022-0396
https://www.cve.org/CVERecord?id=CVE-2022-0396
Référence CVE CVE-2022-0635
https://www.cve.org/CVERecord?id=CVE-2022-0635
Référence CVE CVE-2022-0667
https://www.cve.org/CVERecord?id=CVE-2022-0667
Référence CVE CVE-2022-1271
https://www.cve.org/CVERecord?id=CVE-2022-
Official advisory ↗CERT-FR · French · CERTFR-2024-AVI-0027Multiples vulnérabilités dans les produits Juniper Networksorg/CVERecord?id=CVE-2021-33656
Référence CVE CVE-2021-34798
https://www.cve.org/CVERecord?id=CVE-2021-34798
Référence CVE CVE-2021-3564
https://www.cve.org/CVERecord?id=CVE-2021-3564
Référence CVE CVE-2021-3573
https://www.cve.org/CVERecord?id=CVE-2021-3573
Référence CVE CVE-2021-3621
https://www.cve.org/CVERecord?id=CVE-2021-3621
Référence CVE CVE-2021-3752
https://www.cve.org/CVERecord?id=CVE-2021-3752
Référence CVE CVE-2021-39275
https://www.cve.org/CVERecord?id=CVE-2021-39275
Référence CVE CVE-2021-4104
https://www.cve.org/CVERecord?id=CVE-2021-4104
Référence CVE CVE-2021-4155
https://www.cve.org/CVERecord?id=CVE-2021-4155
Référence CVE CVE-2021-44228
https://www.cve.org/CVERecord?id=CVE-2021-44228
Référence CVE CVE-2021-44790
https://www.cve.org/CVERecord?id=CVE-2021-44790
Référence CVE CVE-2021-44832
https://www.cve.org/CVERecord?id=CVE-2021-44832
Référence CVE CVE-2022-0330
https://www.cve.org/CVERecord?id=CVE-2022-0330
Référence CVE CVE-2022-0934
https://www.cve.org/CVERecord?id=CVE-2022-0934
Référence CVE CVE-2022-1462
https://www.cve.org/CVERecord?id=CVE-2022-1462
Référence CVE CVE-2022-1679
https://www.cve.org/CVERecord?id=CVE-2022-1679
Référence CVE CVE-2022-1789
https://www.cve.org/CVERecord?id=CVE-2022-1789
Référence CVE CVE-2022-20141
https://www.cve.org/CVERecord?id=CVE-2022-2
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-717Multiples vulnérabilités dans les produits Schneiderord?id=CVE-2021-22780
Référence CVE CVE-2021-22781
https://www.cve.org/CVERecord?id=CVE-2021-22781
Référence CVE CVE-2021-22782
https://www.cve.org/CVERecord?id=CVE-2021-22782
Référence CVE CVE-2021-22786
https://www.cve.org/CVERecord?id=CVE-2021-22786
Référence CVE CVE-2021-22789
https://www.cve.org/CVERecord?id=CVE-2021-22789
Référence CVE CVE-2021-22790
https://www.cve.org/CVERecord?id=CVE-2021-22790
Référence CVE CVE-2021-22791
https://www.cve.org/CVERecord?id=CVE-2021-22791
Référence CVE CVE-2021-22792
https://www.cve.org/CVERecord?id=CVE-2021-22792
Référence CVE CVE-2021-4104
https://www.cve.org/CVERecord?id=CVE-2021-4104
Référence CVE CVE-2021-44228
https://www.cve.org/CVERecord?id=CVE-2021-44228
Référence CVE CVE-2021-44832
https://www.cve.org/CVERecord?id=CVE-2021-44832
Référence CVE CVE-2021-45046
https://www.cve.org/CVERecord?id=CVE-2021-45046
Référence CVE CVE-2021-45105
https://www.cve.org/CVERecord?id=CVE-2021-45105
Référence CVE CVE-2022-34759
https://www.cve.org/CVERecord?id=CVE-2022-34759
Référence CVE CVE-2022-34760
https://www.cve.org/CVERecord?id=CVE-2022-34760
Référence CVE CVE-2022-34761
https://www.cve.org/CVERecord?id=CVE-2022-34761
Référence CVE CVE-2022-34762
https://www.cve.org/CVERecord?id=CVE-2022-34762
Référence CVE CVE-2022-34763
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-570Multiples vulnérabilités dans les produits IBMCVERecord?id=CVE-2018-11798
Référence CVE CVE-2018-1320
https://www.cve.org/CVERecord?id=CVE-2018-1320
Référence CVE CVE-2019-0205
https://www.cve.org/CVERecord?id=CVE-2019-0205
Référence CVE CVE-2019-0210
https://www.cve.org/CVERecord?id=CVE-2019-0210
Référence CVE CVE-2020-13949
https://www.cve.org/CVERecord?id=CVE-2020-13949
Référence CVE CVE-2021-22945
https://www.cve.org/CVERecord?id=CVE-2021-22945
Référence CVE CVE-2021-22946
https://www.cve.org/CVERecord?id=CVE-2021-22946
Référence CVE CVE-2021-22947
https://www.cve.org/CVERecord?id=CVE-2021-22947
Référence CVE CVE-2021-3712
https://www.cve.org/CVERecord?id=CVE-2021-3712
Référence CVE CVE-2021-44228
https://www.cve.org/CVERecord?id=CVE-2021-44228
Référence CVE CVE-2021-45046
https://www.cve.org/CVERecord?id=CVE-2021-45046
Référence CVE CVE-2021-45105
https://www.cve.org/CVERecord?id=CVE-2021-45105
Référence CVE CVE-2022-0778
https://www.cve.org/CVERecord?id=CVE-2022-0778
Référence CVE CVE-2022-1292
https://www.cve.org/CVERecord?id=CVE-2022-1292
Référence CVE CVE-2022-1343
https://www.cve.org/CVERecord?id=CVE-2022-1343
Référence CVE CVE-2022-1434
https://www.cve.org/CVERecord?id=CVE-2022-1434
Référence CVE CVE-2022-1473
https://www.cve.org/CVERecord?id=CVE-2022-1473
Référence CVE CVE-2022-22576
https://www.cve.org/CVERecord?id=CVE-2022-2
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-568Multiples vulnérabilités dans les produits IBMVERecord?id=CVE-2020-8908
Référence CVE CVE-2020-9546
https://www.cve.org/CVERecord?id=CVE-2020-9546
Référence CVE CVE-2020-9547
https://www.cve.org/CVERecord?id=CVE-2020-9547
Référence CVE CVE-2020-9548
https://www.cve.org/CVERecord?id=CVE-2020-9548
Référence CVE CVE-2021-20190
https://www.cve.org/CVERecord?id=CVE-2021-20190
Référence CVE CVE-2021-27568
https://www.cve.org/CVERecord?id=CVE-2021-27568
Référence CVE CVE-2021-29425
https://www.cve.org/CVERecord?id=CVE-2021-29425
Référence CVE CVE-2021-33813
https://www.cve.org/CVERecord?id=CVE-2021-33813
Référence CVE CVE-2021-38153
https://www.cve.org/CVERecord?id=CVE-2021-38153
Référence CVE CVE-2021-44228
https://www.cve.org/CVERecord?id=CVE-2021-44228
Référence CVE CVE-2021-45046
https://www.cve.org/CVERecord?id=CVE-2021-45046
Référence CVE CVE-2021-45105
https://www.cve.org/CVERecord?id=CVE-2021-45105
Référence CVE CVE-2022-22965
https://www.cve.org/CVERecord?id=CVE-2022-22965
Gestion détaillée du document
le 17 juin 2022
Version initiale
Alertes
Avis
Bulletins d’actualités
Mentions légales
Conditions générales
À propos
Contact
cyber.gouv.fr
service-public.fr
legifrance.gouv.fr
info.gouv.fr
france.fr
info.gouv.fr/risques
Premier Ministre / Secrétariat Général de la Défense et de la Sécurité Nationale / Agence nationale de la
sécurité des sy
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-526Multiples vulnérabilités dans les produits IBMDe multiples vulnérabilités ont été découvertes dans les produits IBM.
Certaines d'entre elles permettent à un attaquant de provoquer une
exécution de code arbitraire à distance, une exécution de code
arbitraire et un déni de service à distance.
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-243Multiples vulnérabilités dans les produits Appleorg/CVERecord?id=CVE-2021-22947
Référence CVE CVE-2021-30918
https://www.cve.org/CVERecord?id=CVE-2021-30918
Référence CVE CVE-2021-36976
https://www.cve.org/CVERecord?id=CVE-2021-36976
Référence CVE CVE-2021-4136
https://www.cve.org/CVERecord?id=CVE-2021-4136
Référence CVE CVE-2021-4166
https://www.cve.org/CVERecord?id=CVE-2021-4166
Référence CVE CVE-2021-4173
https://www.cve.org/CVERecord?id=CVE-2021-4173
Référence CVE CVE-2021-4187
https://www.cve.org/CVERecord?id=CVE-2021-4187
Référence CVE CVE-2021-4192
https://www.cve.org/CVERecord?id=CVE-2021-4192
Référence CVE CVE-2021-4193
https://www.cve.org/CVERecord?id=CVE-2021-4193
Référence CVE CVE-2021-44228
https://www.cve.org/CVERecord?id=CVE-2021-44228
Référence CVE CVE-2021-46059
https://www.cve.org/CVERecord?id=CVE-2021-46059
Référence CVE CVE-2022-0128
https://www.cve.org/CVERecord?id=CVE-2022-0128
Référence CVE CVE-2022-0156
https://www.cve.org/CVERecord?id=CVE-2022-0156
Référence CVE CVE-2022-0158
https://www.cve.org/CVERecord?id=CVE-2022-0158
Référence CVE CVE-2022-22582
https://www.cve.org/CVERecord?id=CVE-2022-22582
Référence CVE CVE-2022-22596
https://www.cve.org/CVERecord?id=CVE-2022-22596
Référence CVE CVE-2022-22597
https://www.cve.org/CVERecord?id=CVE-2022-22597
Référence CVE CVE-2022-22598
https://www.cve.org/CVERecord?id=CVE-20
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-125Multiples vulnérabilités dans les produits SAPDe multiples vulnérabilités ont été découvertes dans les produits SAP.
Elles permettent à un attaquant de provoquer un déni de service à
distance, une atteinte à l'intégrité des données et une atteinte à la
confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-124Multiples vulnérabilités dans les produits Siemensd?id=CVE-2021-40360
Référence CVE CVE-2021-40363
https://www.cve.org/CVERecord?id=CVE-2021-40363
Référence CVE CVE-2021-40364
https://www.cve.org/CVERecord?id=CVE-2021-40364
Référence CVE CVE-2021-41990
https://www.cve.org/CVERecord?id=CVE-2021-41990
Référence CVE CVE-2021-41991
https://www.cve.org/CVERecord?id=CVE-2021-41991
Référence CVE CVE-2021-43336
https://www.cve.org/CVERecord?id=CVE-2021-43336
Référence CVE CVE-2021-44000
https://www.cve.org/CVERecord?id=CVE-2021-44000
Référence CVE CVE-2021-44016
https://www.cve.org/CVERecord?id=CVE-2021-44016
Référence CVE CVE-2021-44018
https://www.cve.org/CVERecord?id=CVE-2021-44018
Référence CVE CVE-2021-44228
https://www.cve.org/CVERecord?id=CVE-2021-44228
Référence CVE CVE-2021-45046
https://www.cve.org/CVERecord?id=CVE-2021-45046
Référence CVE CVE-2021-45106
https://www.cve.org/CVERecord?id=CVE-2021-45106
Référence CVE CVE-2021-46151
https://www.cve.org/CVERecord?id=CVE-2021-46151
Référence CVE CVE-2021-46152
https://www.cve.org/CVERecord?id=CVE-2021-46152
Référence CVE CVE-2021-46153
https://www.cve.org/CVERecord?id=CVE-2021-46153
Référence CVE CVE-2021-46154
https://www.cve.org/CVERecord?id=CVE-2021-46154
Référence CVE CVE-2021-46155
https://www.cve.org/CVERecord?id=CVE-2021-46155
Référence CVE CVE-2021-46156
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-1027Multiples vulnérabilités dans IBM Db2De multiples vulnérabilités ont été découvertes dans IBM Db2. Elles
permettent à un attaquant de provoquer une exécution de code arbitraire
à distance, un déni de service à distance et une atteinte à la
confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-016Multiples vulnérabilités dans les produits SAPDe multiples vulnérabilités ont été découvertes dans les produits SAP.
Certaines d'entre elles permettent à un attaquant de provoquer une
exécution de code arbitraire à distance, un déni de service à distance
et un contournement de la politique de sécurité.
Official advisory ↗CERT-FR · French · CERTFR-2021-AVI-953Multiples vulnérabilités dans les produits SchneiderDe multiples vulnérabilités ont été découvertes dans les produits
Schneider. Certaines d'entre elles permettent à un attaquant de
provoquer une exécution de code arbitraire à distance, un déni de
service à distance et un contournement de la politique de sécurité.
Official advisory ↗CERT-FR · French · CERTFR-2021-AVI-951Multiples vulnérabilités dans le noyau Linux de RedHatg/CVERecord?id=CVE-2021-34428
Référence CVE CVE-2021-3536
https://www.cve.org/CVERecord?id=CVE-2021-3536
Référence CVE CVE-2021-3597
https://www.cve.org/CVERecord?id=CVE-2021-3597
Référence CVE CVE-2021-3629
https://www.cve.org/CVERecord?id=CVE-2021-3629
Référence CVE CVE-2021-3690
https://www.cve.org/CVERecord?id=CVE-2021-3690
Référence CVE CVE-2021-37136
https://www.cve.org/CVERecord?id=CVE-2021-37136
Référence CVE CVE-2021-37137
https://www.cve.org/CVERecord?id=CVE-2021-37137
Référence CVE CVE-2021-37714
https://www.cve.org/CVERecord?id=CVE-2021-37714
Référence CVE CVE-2021-4104
https://www.cve.org/CVERecord?id=CVE-2021-4104
Référence CVE CVE-2021-44228
https://www.cve.org/CVERecord?id=CVE-2021-44228
Référence CVE CVE-2021-45046
https://www.cve.org/CVERecord?id=CVE-2021-45046
Référence CVE CVE-2021-45606
https://www.cve.org/CVERecord?id=CVE-2021-45606
Gestion détaillée du document
le 15 décembre 2021
Version initiale
Alertes
Avis
Bulletins d’actualités
Mentions légales
Conditions générales
À propos
Contact
cyber.gouv.fr
service-public.fr
legifrance.gouv.fr
info.gouv.fr
france.fr
info.gouv.fr/risques
Premier Ministre / Secrétariat Général de la Défense et de la Sécurité Nationale / Agence nationale de la
sécurité des systèmes d'information
Official advisory ↗NBSZ-NKI · Hungarian · cve-2021-44228CVE-2021-44228Kritikus
Official advisory ↗JVN iPedia · Japanese · JVNDB-2021-005429Apache Log4j における任意のコードが実行可能な脆弱性Log4j には JNDI Lookup 機能による外部入力値の検証不備に起因して任意の Java コードを実行可能な脆弱性が存在します。 The Apache Software Foundation が提供する Log4j は、Java ベースのロギングライブラリです。Log4j には、ログに記載された文字列から一部の値を変数として評価する Lookup 機能が実装されています。 その Lookup 機能の内、JNDI Lookup 機能を悪用することにより、ログに含まれる外部の URL もしくは内部パスから Java のクラス情報をデシリアライズして実行してしまう問題(CWE-20, CVE-2021-44228)が発見されました。 これにより、遠隔の攻撃者が細工した文字列を脆弱なシステムのログに記載させ、結果として任意の Java コードをシステムに実行させることが可能です。
Official advisory ↗JVN iPedia · Japanese · JVNDB-2021-020223レッドハットの Red Hat OpenShift における信頼できないデータのデシリアライゼーションに関する脆弱性レッドハットの Red Hat OpenShift には、信頼できないデータのデシリアライゼーションに関する脆弱性が存在します。
Official advisory ↗JVN iPedia · Japanese · JVNDB-2021-016230Log4j における信頼できないデータのデシリアライゼーションに関する脆弱性Log4j には、信頼できないデータのデシリアライゼーションに関する脆弱性が存在します。 本脆弱性は、CVE-2021-44228 と関連する脆弱性です。
Official advisory ↗KISA KrCERT/CC · Korean · KNVD-5914현재 악용되고 있는 Exploit(Update. 2023-05-01)vulnerabilityName | dateAdded | shortDescription | requiredAction | dueDate |
| --- | --- | --- | --- | --- | --- | --- |
| CVE-2023-21839 | Oracle | Oracle WebLogic Server Unspecified Vulnerability | 2023-05-01 | Oracle WebLogic Server contains an unspecified vulnerability that allows an unauthenticated attacker with network access via T3, IIOP, to compromise Oracle WebLogic Server. | Apply updates per vendor instructions. | 2023-05-22 |
| CVE-2021-45046 | Apache | Apache Log4j2 Deserialization of Untrusted Data Vulnerability | 2023-05-01 | Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations. | Apply updates per vendor instructions. | 2023-05-22 |
| CVE-2023-1389 | TP-Link | TP-Link Archer AX-21 Command Injection Vulnerability | 2023-05-01 | TP-Link Archer AX-21 contains a command injection vulnerability that allows for remote code execution. | Apply updates per vendor instructions. | 2023-05-22 |
Official advisory ↗KISA KrCERT/CC · Korean · KNVD-5873최근 해킹 공격에 활용되는 취약점 보안 업데이트 권고전의 소프트웨어, 서버를 사용하는 기업 및 사용자는 최신버전으로 업데이트 권고
##### □ 최근 악용되고있는 주요 취약점
ㅇ Apache APISIX에서 발생하는 인증 우회 취약점(CVE-2021-45232)[1]
ㅇ Apache HTTP Server에서 경로 탐색(Path Traversal)으로 인해 발생하는 정보노출 취약점(CVE-2021-42013)[2]
ㅇ Apache HTTP Server에서 경로 탐색(Path Traversal)으로 인해 발생하는 정보노출 취약점(CVE-2021-41773)[3]
ㅇ Apache OFBiz에서 발생하는 크로스 사이트 스크립팅(XSS) 취약점(CVE-2020-9496)[4]
ㅇ Apache OFBiz에서 발생하는 역직렬화 취약점(CVE-2021-26295)[5]
ㅇ Apache Struts에서 발생하는 원격코드 실행 취약점(CVE-2020-17530)[6]
ㅇ Apache Struts에서 사용자 입력값 검증 미흡으로 발생하는 원격 코드 실행 취약점(CVE-2021-31805)[7]
ㅇ Apache Tomcat이 AJP request 메시지를 처리할 때, 메시지에 대한 처리가 미흡하여 발생하는 원격코드실행 취약점(CVE-2020-1938)[8]
ㅇ Apache Log4j에서 발생하는 원격코드 실행 취약점(CVE-2021-44228)[9]
ㅇ Atlassian Confluence Server 및 Data Center에서 OGNL 인젝션으로 인해 발생하는 원격코드실행 취약점(CVE-2021-26084)[10]
ㅇ BIG-IP에서 iControl REST 인증 미흡으로 인해 발생하는 불충분한 인가 취약점(CVE-2022-1388)[11]
ㅇ BIG-IP, BIG-IQ의 iControl REST 인터페이스에서 발생하는 원격 코드 실행 취약점(CVE-2021-22986)[12]
ㅇ Grafana 소프트웨어에서 경로탐색(Directory Traversal)으로 인해 발생하는 정보노출 취약점(CVE-2021-43798)[13]
ㅇ Inspur ClusterEngine V4.0에서 발생하는 원격 코드 실행 취약점(CVE-2020-21224)[14]
ㅇ Oracle WebLogic Server에서 발생하는 원격 코드 실행 취약점(CVE-2021-2109)[15]
ㅇ SMBv3 프로토콜이 조작된 패킷을 처리할 때 버퍼오버플로우로 인해 발생하는 원격코드실행 취약점(CVE-2020-0796)[16]
ㅇ Spring Cloud Gateway에서 발생하는 원격코드 실행 취약점(CVE-2022-22947)[17]
ㅇ Spring Core에서 발생하는 원격코드실행 취약점(CVE-2022-22965)
Official advisory ↗KISA KrCERT/CC · Korean · KNVD-5585AWS Log4j 핫픽스 수정 보안 업데이트 권고※ CVE-2021-3100 : Amazon Linux Log4j 핫픽스(log4j-cve-2021-44228-hotpatch-1.1-12 이전)에서 발생하는 권한 상승 취약점
Official advisory ↗KISA KrCERT/CC · Korean · KNVD-5527SAP 제품 취약점 보안 업데이트 권고SAP 제품에서 발생하는 원격 코드 실행 취약점 (CVE-2021-44228) 등 4개
Official advisory ↗KISA KrCERT/CC · Korean · KNVD-5502SAP 제품 취약점 보안 업데이트 권고SAP 제품에서 발생하는 원격 코드 실행 취약점 (CVE-2021-44228) 등 4개
Official advisory ↗KISA KrCERT/CC · Korean · KNVD-5487설 연휴기간 사이버 공격 대비 보안 권고 사항 (상세)알아보는 Apache log4j 취약점 대응 가이드
- 보호나라 홈페이지 → 자료실 → 가이드 및 매뉴얼 내 68번 게시물
o 랜섬웨어 대응을 위한 안전한 정보시스템 백업 가이드(개정본)
- 보호나라 홈페이지 → 자료실 → 가이드 및 매뉴얼 내 64번 게시물
o 위 취약점 패치 권고 사항관련 보호나라 보안공지
- MS 윈도우 Exchange 서버 취약점 보안 업데이트 권고
(CVE-2021-31207, 34473, 34523, 26855, 26857, 27065, 26585)
·https://www.boho.or.kr/data/secNoticeView.do?bulletin_writing_sequence=36191 (`21.8.25)
·https://www.boho.or.kr/data/secNoticeView.do?bulletin_writing_sequence=35931 (`21.3.18)
·https://www.boho.or.kr/data/secNoticeView.do?bulletin_writing_sequence=35930 (`21.3.8)
·https://www.boho.or.kr/data/secNoticeView.do?bulletin_writing_sequence=35929 (`21.3.3)
- Apache Log4j 보안 업데이트 권고 (CVE-2021-44228, 45046, 4104, 45105, 44832, CVE-2022-23302, 23305, 23307)
·https://www.boho.or.kr/data/secNoticeView.do?bulletin_writing_sequence=36397 (`22.1.21)
·https://www.boho.or.kr/data/secNoticeView.do?bulletin_writing_sequence=36389 (`22.1.3)
##### □ 작성 : 침해사고분석단 사고분석팀
Official advisory ↗KISA KrCERT/CC · Korean · KNVD-5481SAP 제품 취약점 보안 업데이트 권고#### SAP 제품 취약점 보안 업데이트 권고 2022.01.13
##### □ 개요
o SAP 社는 자사 제품의 취약점을 해결한 보안 업데이트 공지 [1]
o 공격자는 취약점을 악용하여 피해를 발생시킬 수 있으므로, 해당 제품을 사용하는 이용자들은 최신 버전으로 업데이트 권고
##### □ 설명 [1]
o SAP 제품에서 발생하는 원격코드실행 취약점(CVE-2021-44228)
o SAP S/4HANA에서 발생하는 다중 취약점(CVE-2022-22530, 22531)
o SAP NetWeaver AS ABAP에서 발생하는 코드 삽입 취약점(CVE-2021-44235)
##### □ 영향받는 제품
CVE ID
영향받는 제품
버전
CVE-2021-44228
제조사 홈페이지 참고 [1]
제조사 홈페이지 참고 [1]
CVE-2022-22530, 22531
SAP S/4HANA
100, 101, 102, 103, 104, 105, 106
CVE-2021-44235
SAP NetWeaver AS ABAP
700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756
##### □ 해결방안
o 제조사 홈페이지를 참고하여 최신버전으로 업데이트
##### □ 기타 문의사항
o 한국인터넷진흥원 사이버민원센터: 국번없이 118
[참고사이트]
[1]
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=596902035
##### □ 작성 : 침해사고분석단 취약점분석팀
Official advisory ↗KISA KrCERT/CC · Korean · KNVD-5466Apache Log4j 보안 업데이트 권고 (Update. 22-1-3 14:40)he Log4j 보안 업데이트 권고 (Update. 22-1-3 14:40) 2021.12.11
2021-12-12 : 영향 받는 버전 및 참고 사이트 추가
2021-12-13 : 1.x 버전 사용자 최신 업데이트 권고 및 버전확인방법 추가
2021-12-13 : 탐지정책 추가
2021-12-15 : CVE-2021-45046, CVE-2021-4104 추가, 대응방안 수정
2021-12-16 : 대응방안 수정
2021-12-17 : 취약점 주요내용 수정
2021-12-22 : 영향받는 버전 및 대응방안 수정
2022-1-3 : 영향받는 버전 수정
##### □ 개요
o Apache 소프트웨어 재단은 자사의 Log4j 2에서 발생하는 취약점을 해결한 보안 업데이트 권고[1]
o 공격자는 해당 취약점을 이용하여 악성코드 감염 등의 피해를 발생시킬수 있으므로, 최신 버전으로 업데이트 권고
※ 관련 사항은 참고사이트 [6] 취약점 대응가이드를 참고 바랍니다.
※ 참고 사이트 [4]를 확인하여 해당 제품을 이용 중일 경우, 해당 제조사의 권고에 따라 패치 또는 대응 방안 적용
※ Log4j 취약점을 이용한 침해사고 발생시 한국인터넷진흥원에 신고해 주시기 바랍니다.
##### □ 주요 내용
o Apache Log4j 2에서 발생하는 원격코드 실행 취약점(CVE-2021-44228)[2]
o Apache Log4j 2에서 발생하는 원격코드 실행 취약점(CVE-2021-45046)[7]
o Apache Log4j 1.x에서 발생하는 원격코드 실행 취약점(CVE-2021-4104)[8]
※ Log4j : 프로그램 작성 중 로그를 남기기 위해 사용되는 자바 기반의 오픈소스 유틸리티
##### □ 영향을 받는 버전
o CVE-2021-44228
- 2.0-beta9 ~
2.14.1 이하
※ 취약점이 해결된 버전 제외(Log4j 2.3.1, 2.12.2, 2.12.3
및 이후 업데이트 버전 제외
)
o CVE-2021-45046
- 2.0-beta9
~ 2.15.0 버전
※ 취약점이 해결된 버전 제외(Log4j 2.3.1, 2.12.2, 2.12.3
및 이후 업데이트 버전 제외
)
o CVE-2021-4104
- 1.x 버전
※ JMSAppender를 사용하지 않는 경우 취약점 영향 없음
##### □ 대응방안
o 제조사 홈페이지를 통해 최신버전으로 업데이트 적용 [3]
※ 제조사 홈페이지에 신규버전이 계속 업데이트되고 있어 확인 후 업데이트 적용 필요
- CVE-2021-44228, CVE-2021-45046
· Java 8 이상 :
Log4j 2.17.0 이상 버전
으로 업데이트
· Java 7 :
Log4j 2.12.3 이상
Official advisory ↗