ENISA EUVD · EUVD-2022-0516Official EUVD mapping0 linked advisory records.
Official EUVD record ↗BSI · German · WID-SEC-2024-2180Oracle Fusion Middleware: Mehrere SchwachstellenEin entfernter, anonymer oder lokaler Angreifer kann mehrere Schwachstellen in Oracle Fusion Middleware ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2024-0064Juniper Produkte: Mehrere SchwachstellenEin Angreifer aus dem angrenzenden Netzwerk oder ein entfernter, anonymer, authentisierter, lokaler oder physischer Angreifer kann mehrere Schwachstellen in Juniper JUNOS, Juniper JUNOS Evolved, Juniper SRX Series, Juniper EX Series, Juniper QFX Series, Juniper ACX Series, Juniper PTX Series und Juniper MX Series ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen und seine Berechtigungen zu erweitern.
Official advisory ↗BSI · German · WID-SEC-2023-1031Oracle Retail Applications: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Retail Applications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2023-0123Oracle Siebel CRM: Mehrere SchwachstellenEin entfernter, anonymer Angreifer kann mehrere Schwachstellen in Oracle Siebel CRM ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2022-0169Oracle MySQL: Mehrere SchwachstellenEin entfernter, anonymer Angreifer kann mehrere Schwachstellen in Oracle MySQL ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2025-2471IBM Spectrum Protect Plus: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in IBM Spectrum Protect ausnutzen, um Daten zu manipulieren, Sicherheitsmaßnahmen zu umgehen und beliebigen Code auszuführen.
Official advisory ↗BSI · German · WID-SEC-2023-1524IBM Spectrum Protect Plus: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in IBM Spectrum Protect Plus ausnutzen, um einen Denial-of-Service-Zustand zu verursachen, seine Privilegien zu erweitern, Sicherheitsmaßnahmen zu umgehen und beliebigen Code auszuführen.
Official advisory ↗BSI · German · WID-SEC-2023-0122Oracle Supply Chain: Mehrere SchwachstellenEin entfernter, anonymer Angreifer kann mehrere Schwachstellen in Oracle Supply Chain ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2022-0197Apache log4j: Schwachstelle ermöglicht CodeausführungEin entfernter, authentisierter Angreifer kann eine Schwachstelle in Apache log4j ausnutzen, um beliebigen Programmcode auszuführen.
Official advisory ↗Canadian Centre for Cyber Security · English · AL21-019Active exploitation of Apache Log4j vulnerability - update 7On 10 December 2021, Apache released a Security Advisory Footnote 1 Footnote 2 highlighting a critical remote code execution vulnerability in Log4j, a widely deployed Java-based logging utility. Open-source reporting indicates that active scanning and exploitation of this vulnerability have been observed.
Official advisory ↗Cyber Security Agency of Singapore · English · CSA-SB-20211229Security Bulletin 29 Dec 2021The Cyber Security Agency of Singapore included this CVE in its official Security Bulletin 29 Dec 2021, published on 29 December 2021. Open the linked bulletin for the product, severity and reference information published in that issue.
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0855Multiples vulnérabilités dans les produits Juniper Networksecord?id=CVE-2020-11023
Référence CVE CVE-2021-22146
https://www.cve.org/CVERecord?id=CVE-2021-22146
Référence CVE CVE-2021-3903
https://www.cve.org/CVERecord?id=CVE-2021-3903
Référence CVE CVE-2021-40153
https://www.cve.org/CVERecord?id=CVE-2021-40153
Référence CVE CVE-2021-4104
https://www.cve.org/CVERecord?id=CVE-2021-4104
Référence CVE CVE-2021-41043
https://www.cve.org/CVERecord?id=CVE-2021-41043
Référence CVE CVE-2021-41072
https://www.cve.org/CVERecord?id=CVE-2021-41072
Référence CVE CVE-2021-42550
https://www.cve.org/CVERecord?id=CVE-2021-42550
Référence CVE CVE-2021-44228
https://www.cve.org/CVERecord?id=CVE-2021-44228
Référence CVE CVE-2021-44832
https://www.cve.org/CVERecord?id=CVE-2021-44832
Référence CVE CVE-2021-45046
https://www.cve.org/CVERecord?id=CVE-2021-45046
Référence CVE CVE-2021-45105
https://www.cve.org/CVERecord?id=CVE-2021-45105
Référence CVE CVE-2021-47606
https://www.cve.org/CVERecord?id=CVE-2021-47606
Référence CVE CVE-2022-24805
https://www.cve.org/CVERecord?id=CVE-2022-24805
Référence CVE CVE-2022-24806
https://www.cve.org/CVERecord?id=CVE-2022-24806
Référence CVE CVE-2022-24807
https://www.cve.org/CVERecord?id=CVE-2022-24807
Référence CVE CVE-2022-24808
https://www.cve.org/CVERecord?id=CVE-2022-24808
Référence CVE CVE-2022-24810
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0756Multiples vulnérabilités dans les produits VMwareCVERecord?id=CVE-2021-35939
Référence CVE CVE-2021-35942
https://www.cve.org/CVERecord?id=CVE-2021-35942
Référence CVE CVE-2021-38604
https://www.cve.org/CVERecord?id=CVE-2021-38604
Référence CVE CVE-2021-3875
https://www.cve.org/CVERecord?id=CVE-2021-3875
Référence CVE CVE-2021-3999
https://www.cve.org/CVERecord?id=CVE-2021-3999
Référence CVE CVE-2021-4122
https://www.cve.org/CVERecord?id=CVE-2021-4122
Référence CVE CVE-2021-4193
https://www.cve.org/CVERecord?id=CVE-2021-4193
Référence CVE CVE-2021-43618
https://www.cve.org/CVERecord?id=CVE-2021-43618
Référence CVE CVE-2021-44228
https://www.cve.org/CVERecord?id=CVE-2021-44228
Référence CVE CVE-2021-44832
https://www.cve.org/CVERecord?id=CVE-2021-44832
Référence CVE CVE-2021-45105
https://www.cve.org/CVERecord?id=CVE-2021-45105
Référence CVE CVE-2021-46848
https://www.cve.org/CVERecord?id=CVE-2021-46848
Référence CVE CVE-2022-0213
https://www.cve.org/CVERecord?id=CVE-2022-0213
Référence CVE CVE-2022-0396
https://www.cve.org/CVERecord?id=CVE-2022-0396
Référence CVE CVE-2022-0635
https://www.cve.org/CVERecord?id=CVE-2022-0635
Référence CVE CVE-2022-0667
https://www.cve.org/CVERecord?id=CVE-2022-0667
Référence CVE CVE-2022-1271
https://www.cve.org/CVERecord?id=CVE-2022-1271
Référence CVE CVE-2022-1292
https://www.cve.org/CVERecord?id=CVE-2022-12
Official advisory ↗CERT-FR · French · CERTFR-2024-AVI-0027Multiples vulnérabilités dans les produits Juniper Networksrg/CVERecord?id=CVE-2021-3564
Référence CVE CVE-2021-3573
https://www.cve.org/CVERecord?id=CVE-2021-3573
Référence CVE CVE-2021-3621
https://www.cve.org/CVERecord?id=CVE-2021-3621
Référence CVE CVE-2021-3752
https://www.cve.org/CVERecord?id=CVE-2021-3752
Référence CVE CVE-2021-39275
https://www.cve.org/CVERecord?id=CVE-2021-39275
Référence CVE CVE-2021-4104
https://www.cve.org/CVERecord?id=CVE-2021-4104
Référence CVE CVE-2021-4155
https://www.cve.org/CVERecord?id=CVE-2021-4155
Référence CVE CVE-2021-44228
https://www.cve.org/CVERecord?id=CVE-2021-44228
Référence CVE CVE-2021-44790
https://www.cve.org/CVERecord?id=CVE-2021-44790
Référence CVE CVE-2021-44832
https://www.cve.org/CVERecord?id=CVE-2021-44832
Référence CVE CVE-2022-0330
https://www.cve.org/CVERecord?id=CVE-2022-0330
Référence CVE CVE-2022-0934
https://www.cve.org/CVERecord?id=CVE-2022-0934
Référence CVE CVE-2022-1462
https://www.cve.org/CVERecord?id=CVE-2022-1462
Référence CVE CVE-2022-1679
https://www.cve.org/CVERecord?id=CVE-2022-1679
Référence CVE CVE-2022-1789
https://www.cve.org/CVERecord?id=CVE-2022-1789
Référence CVE CVE-2022-20141
https://www.cve.org/CVERecord?id=CVE-2022-20141
Référence CVE CVE-2022-21699
https://www.cve.org/CVERecord?id=CVE-2022-21699
Référence CVE CVE-2022-2196
https://www.cve.org/CVERecord?id=CVE-2022-21
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-960Multiples vulnérabilités dans les produits IBMDe multiples vulnérabilités ont été découvertes dans les produits IBM.
Elles permettent à un attaquant de provoquer une exécution de code
arbitraire à distance et un déni de service à distance.
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-933Multiples vulnérabilités dans Oracle SystemsDe multiples vulnérabilités ont été découvertes dans Oracle Systems.
Certaines d'entre elles permettent à un attaquant de provoquer un
problème de sécurité non spécifié par l'éditeur, un déni de service à
distance et une atteinte à l'intégrité des données.
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-717Multiples vulnérabilités dans les produits Schneiderord?id=CVE-2021-22781
Référence CVE CVE-2021-22782
https://www.cve.org/CVERecord?id=CVE-2021-22782
Référence CVE CVE-2021-22786
https://www.cve.org/CVERecord?id=CVE-2021-22786
Référence CVE CVE-2021-22789
https://www.cve.org/CVERecord?id=CVE-2021-22789
Référence CVE CVE-2021-22790
https://www.cve.org/CVERecord?id=CVE-2021-22790
Référence CVE CVE-2021-22791
https://www.cve.org/CVERecord?id=CVE-2021-22791
Référence CVE CVE-2021-22792
https://www.cve.org/CVERecord?id=CVE-2021-22792
Référence CVE CVE-2021-4104
https://www.cve.org/CVERecord?id=CVE-2021-4104
Référence CVE CVE-2021-44228
https://www.cve.org/CVERecord?id=CVE-2021-44228
Référence CVE CVE-2021-44832
https://www.cve.org/CVERecord?id=CVE-2021-44832
Référence CVE CVE-2021-45046
https://www.cve.org/CVERecord?id=CVE-2021-45046
Référence CVE CVE-2021-45105
https://www.cve.org/CVERecord?id=CVE-2021-45105
Référence CVE CVE-2022-34759
https://www.cve.org/CVERecord?id=CVE-2022-34759
Référence CVE CVE-2022-34760
https://www.cve.org/CVERecord?id=CVE-2022-34760
Référence CVE CVE-2022-34761
https://www.cve.org/CVERecord?id=CVE-2022-34761
Référence CVE CVE-2022-34762
https://www.cve.org/CVERecord?id=CVE-2022-34762
Référence CVE CVE-2022-34763
https://www.cve.org/CVERecord?id=CVE-2022-34763
Référence CVE CVE-2022-34764
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-526Multiples vulnérabilités dans les produits IBMDe multiples vulnérabilités ont été découvertes dans les produits IBM.
Certaines d'entre elles permettent à un attaquant de provoquer une
exécution de code arbitraire à distance, une exécution de code
arbitraire et un déni de service à distance.
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-366Multiples vulnérabilités dans Oracle PeopleSoftDe multiples vulnérabilités ont été découvertes dans Oracle PeopleSoft.
Certaines d'entre elles permettent à un attaquant de provoquer un déni
de service à distance, un contournement de la politique de sécurité et
une atteinte à l'intégrité des données.
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-345Multiples vulnérabilités dans les produits SAPsécurité.
Solution
Se référer au bulletin de sécurité de l'éditeur pour l'obtention des
correctifs (cf. section Documentation).
Documentation
Bulletin de sécurité SAP du 12 avril 2022
https://dam.sap.com/mac/app/e/pdf/preview/embed/ucQrx6G?ltr=a&rc=10
Référence CVE CVE-2020-26291
https://www.cve.org/CVERecord?id=CVE-2020-26291
Référence CVE CVE-2021-21480
https://www.cve.org/CVERecord?id=CVE-2021-21480
Référence CVE CVE-2021-27516
https://www.cve.org/CVERecord?id=CVE-2021-27516
Référence CVE CVE-2021-3647
https://www.cve.org/CVERecord?id=CVE-2021-3647
Référence CVE CVE-2021-38162
https://www.cve.org/CVERecord?id=CVE-2021-38162
Référence CVE CVE-2021-44832
https://www.cve.org/CVERecord?id=CVE-2021-44832
Référence CVE CVE-2022-0613
https://www.cve.org/CVERecord?id=CVE-2022-0613
Référence CVE CVE-2022-22532
https://www.cve.org/CVERecord?id=CVE-2022-22532
Référence CVE CVE-2022-22533
https://www.cve.org/CVERecord?id=CVE-2022-22533
Référence CVE CVE-2022-22536
https://www.cve.org/CVERecord?id=CVE-2022-22536
Référence CVE CVE-2022-22541
https://www.cve.org/CVERecord?id=CVE-2022-22541
Référence CVE CVE-2022-22542
https://www.cve.org/CVERecord?id=CVE-2022-22542
Référence CVE CVE-2022-22543
https://www.cve.org/CVERecord?id=CVE-2022-22543
Référence CVE CVE-2022-22545
https://www.cve.org/CVERecord?id=CV
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-205Multiples vulnérabilités dans les produits IBMDe multiples vulnérabilités ont été découvertes dans les produits IBM.
Certaines d'entre elles permettent à un attaquant de provoquer une
exécution de code arbitraire à distance, un déni de service à distance
et une atteinte à l'intégrité des données.
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-125Multiples vulnérabilités dans les produits SAPDe multiples vulnérabilités ont été découvertes dans les produits SAP.
Elles permettent à un attaquant de provoquer un déni de service à
distance, une atteinte à l'intégrité des données et une atteinte à la
confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-1027Multiples vulnérabilités dans IBM Db2De multiples vulnérabilités ont été découvertes dans IBM Db2. Elles
permettent à un attaquant de provoquer une exécution de code arbitraire
à distance, un déni de service à distance et une atteinte à la
confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-056Multiples vulnérabilités dans Oracle WebLogic ServerVERecord?id=CVE-2018-1324
Référence CVE CVE-2019-10219
https://www.cve.org/CVERecord?id=CVE-2019-10219
Référence CVE CVE-2020-11023
https://www.cve.org/CVERecord?id=CVE-2020-11023
Référence CVE CVE-2020-13956
https://www.cve.org/CVERecord?id=CVE-2020-13956
Référence CVE CVE-2020-2934
https://www.cve.org/CVERecord?id=CVE-2020-2934
Référence CVE CVE-2020-5258
https://www.cve.org/CVERecord?id=CVE-2020-5258
Référence CVE CVE-2021-27568
https://www.cve.org/CVERecord?id=CVE-2021-27568
Référence CVE CVE-2021-29425
https://www.cve.org/CVERecord?id=CVE-2021-29425
Référence CVE CVE-2021-4104
https://www.cve.org/CVERecord?id=CVE-2021-4104
Référence CVE CVE-2021-44832
https://www.cve.org/CVERecord?id=CVE-2021-44832
Référence CVE CVE-2022-21252
https://www.cve.org/CVERecord?id=CVE-2022-21252
Référence CVE CVE-2022-21257
https://www.cve.org/CVERecord?id=CVE-2022-21257
Référence CVE CVE-2022-21258
https://www.cve.org/CVERecord?id=CVE-2022-21258
Référence CVE CVE-2022-21259
https://www.cve.org/CVERecord?id=CVE-2022-21259
Référence CVE CVE-2022-21260
https://www.cve.org/CVERecord?id=CVE-2022-21260
Référence CVE CVE-2022-21261
https://www.cve.org/CVERecord?id=CVE-2022-21261
Référence CVE CVE-2022-21262
https://www.cve.org/CVERecord?id=CVE-2022-21262
Référence CVE CVE-2022-21292
https://www.cve.org/CVERecord?id=
Official advisory ↗JVN iPedia · Japanese · JVNDB-2021-005429Apache Log4j における任意のコードが実行可能な脆弱性Log4j には JNDI Lookup 機能による外部入力値の検証不備に起因して任意の Java コードを実行可能な脆弱性が存在します。 The Apache Software Foundation が提供する Log4j は、Java ベースのロギングライブラリです。Log4j には、ログに記載された文字列から一部の値を変数として評価する Lookup 機能が実装されています。 その Lookup 機能の内、JNDI Lookup 機能を悪用することにより、ログに含まれる外部の URL もしくは内部パスから Java のクラス情報をデシリアライズして実行してしまう問題(CWE-20, CVE-2021-44228)が発見されました。 これにより、遠隔の攻撃者が細工した文字列を脆弱なシステムのログに記載させ、結果として任意の Java コードをシステムに実行させることが可能です。
Official advisory ↗KISA KrCERT/CC · Korean · KNVD-5474Apache Log4j 보안 업데이트 권고(CVE-2021-45105, 44832, CVE-2022-23302, 23305, 23307) (Update. 22-1-21 17:00)#### Apache Log4j 보안 업데이트 권고(CVE-2021-45105, 44832, CVE-2022-23302, 23305, 23307) (Update. 22-1-21 17:00) 2021.12.18
2021-12-18 : CVE-2021-45105 취약점 보안 업데이트
2021-12-20 : 조치방안 내 오타 수정
2021-12-22 : 대응방안 업데이트(Java 6, 7 대상)
2021-12-29 : CVE-2021-44832 취약점 보안 업데이트
2021-12-30 : Log4j 2.12.4, 2.3.2 다운로드 추가
2021-12-31 : 영향을 받는 부분 수정
2022-1-3 : 영향받는 버전 수정
2022-1-21 : CVE-2022-23302, 23305, 23307 취약점 관련 내용 추가
##### □ 개요
o Apache 소프트웨어 재단은 자사의 Log4j에서 발생하는 취약점을 해결한 보안 업데이트 권고[1]
o 공격자는 해당 취약점을 이용하여 정상 서비스 중지 등의 피해를 발생시킬수 있으므로, 최신 버전으로 업데이트 권고
※ Log4j 취약점을 이용한 침해사고 발생시 한국인터넷진흥원에 신고해 주시기 바랍니다.
##### □ 주요 내용
o Apache Log4j 2에서 발생하는 서비스 거부 취약점(CVE-2021-45105)[2]
o Apache Log4j 2에서 발생하는 원격코드 실행 취약점(CVE-2021-44832)[4]
o Apache Log4j 1에서 발생하는 원격 코드 실행 취약점(CVE-2022-23302)[6]
o Apache Log4j 1에서 발생하는 SQL Injection 취약점(CVE-2022-23305)[6]
o Apache Log4j 1에서 발생하는 원격 코드 실행 취약점(CVE-2022-23307)[6]
※ Log4j : 프로그
Official advisory ↗