ENISA EUVD · EUVD-2021-2559Official EUVD mapping0 linked advisory records.
Official EUVD record ↗BSI · German · WID-SEC-2026-0162Oracle Fusion Middleware: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Fusion Middleware ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2023-0119Oracle Utilities Applications: Mehrere SchwachstellenEin entfernter, anonymer Angreifer kann mehrere Schwachstellen in Oracle Utilities Applications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2022-0811Apache log4j: Schwachstelle ermöglicht Denial of ServiceEin entfernter, anonymer Angreifer kann eine Schwachstelle in Apache log4j ausnutzen, um einen Denial of Service Angriff durchzuführen.
Official advisory ↗Canadian Centre for Cyber Security · English · AV21-652Palo Alto Networks security advisoryOn 10 December 2021 Palo Alto Networks published a Security Advisory to address critical vulnerabilities which may affect multiple products using the Apache Log4j logging utility.
Exploitation of these vulnerabilities could lead to remote code execution.
Official advisory ↗Canadian Centre for Cyber Security · English · AV21-657Citrix security advisoryOn 11 December 2021 Citrix published a Security Advisory to address critical vulnerabilities which may affect multiple products using the Apache Log4j logging utility.
Exploitation of these vulnerabilities could lead to remote code execution.
Official advisory ↗Canadian Centre for Cyber Security · English · AL21-019Active exploitation of Apache Log4j vulnerability - update 7On 10 December 2021, Apache released a Security Advisory Footnote 1 Footnote 2 highlighting a critical remote code execution vulnerability in Log4j, a widely deployed Java-based logging utility. Open-source reporting indicates that active scanning and exploitation of this vulnerability have been observed.
Official advisory ↗Cyber Security Agency of Singapore · English · CSA-SB-20211222Security Bulletin 22 Dec 2021The Cyber Security Agency of Singapore included this CVE in its official Security Bulletin 22 Dec 2021, published on 22 December 2021. Open the linked bulletin for the product, severity and reference information published in that issue.
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0855Multiples vulnérabilités dans les produits Juniper Networkscord?id=CVE-2021-3903
Référence CVE CVE-2021-40153
https://www.cve.org/CVERecord?id=CVE-2021-40153
Référence CVE CVE-2021-4104
https://www.cve.org/CVERecord?id=CVE-2021-4104
Référence CVE CVE-2021-41043
https://www.cve.org/CVERecord?id=CVE-2021-41043
Référence CVE CVE-2021-41072
https://www.cve.org/CVERecord?id=CVE-2021-41072
Référence CVE CVE-2021-42550
https://www.cve.org/CVERecord?id=CVE-2021-42550
Référence CVE CVE-2021-44228
https://www.cve.org/CVERecord?id=CVE-2021-44228
Référence CVE CVE-2021-44832
https://www.cve.org/CVERecord?id=CVE-2021-44832
Référence CVE CVE-2021-45046
https://www.cve.org/CVERecord?id=CVE-2021-45046
Référence CVE CVE-2021-45105
https://www.cve.org/CVERecord?id=CVE-2021-45105
Référence CVE CVE-2021-47606
https://www.cve.org/CVERecord?id=CVE-2021-47606
Référence CVE CVE-2022-24805
https://www.cve.org/CVERecord?id=CVE-2022-24805
Référence CVE CVE-2022-24806
https://www.cve.org/CVERecord?id=CVE-2022-24806
Référence CVE CVE-2022-24807
https://www.cve.org/CVERecord?id=CVE-2022-24807
Référence CVE CVE-2022-24808
https://www.cve.org/CVERecord?id=CVE-2022-24808
Référence CVE CVE-2022-24810
https://www.cve.org/CVERecord?id=CVE-2022-24810
Référence CVE CVE-2022-48622
https://www.cve.org/CVERecord?id=CVE-2022-48622
Référence CVE CVE-2023-0464
https://www.cve.org/CVERecord?id=C
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0756Multiples vulnérabilités dans les produits VMwareCVERecord?id=CVE-2021-35942
Référence CVE CVE-2021-38604
https://www.cve.org/CVERecord?id=CVE-2021-38604
Référence CVE CVE-2021-3875
https://www.cve.org/CVERecord?id=CVE-2021-3875
Référence CVE CVE-2021-3999
https://www.cve.org/CVERecord?id=CVE-2021-3999
Référence CVE CVE-2021-4122
https://www.cve.org/CVERecord?id=CVE-2021-4122
Référence CVE CVE-2021-4193
https://www.cve.org/CVERecord?id=CVE-2021-4193
Référence CVE CVE-2021-43618
https://www.cve.org/CVERecord?id=CVE-2021-43618
Référence CVE CVE-2021-44228
https://www.cve.org/CVERecord?id=CVE-2021-44228
Référence CVE CVE-2021-44832
https://www.cve.org/CVERecord?id=CVE-2021-44832
Référence CVE CVE-2021-45105
https://www.cve.org/CVERecord?id=CVE-2021-45105
Référence CVE CVE-2021-46848
https://www.cve.org/CVERecord?id=CVE-2021-46848
Référence CVE CVE-2022-0213
https://www.cve.org/CVERecord?id=CVE-2022-0213
Référence CVE CVE-2022-0396
https://www.cve.org/CVERecord?id=CVE-2022-0396
Référence CVE CVE-2022-0635
https://www.cve.org/CVERecord?id=CVE-2022-0635
Référence CVE CVE-2022-0667
https://www.cve.org/CVERecord?id=CVE-2022-0667
Référence CVE CVE-2022-1271
https://www.cve.org/CVERecord?id=CVE-2022-1271
Référence CVE CVE-2022-1292
https://www.cve.org/CVERecord?id=CVE-2022-1292
Référence CVE CVE-2022-1473
https://www.cve.org/CVERecord?id=CVE-2022-1473
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-717Multiples vulnérabilités dans les produits Schneiderord?id=CVE-2021-22786
Référence CVE CVE-2021-22789
https://www.cve.org/CVERecord?id=CVE-2021-22789
Référence CVE CVE-2021-22790
https://www.cve.org/CVERecord?id=CVE-2021-22790
Référence CVE CVE-2021-22791
https://www.cve.org/CVERecord?id=CVE-2021-22791
Référence CVE CVE-2021-22792
https://www.cve.org/CVERecord?id=CVE-2021-22792
Référence CVE CVE-2021-4104
https://www.cve.org/CVERecord?id=CVE-2021-4104
Référence CVE CVE-2021-44228
https://www.cve.org/CVERecord?id=CVE-2021-44228
Référence CVE CVE-2021-44832
https://www.cve.org/CVERecord?id=CVE-2021-44832
Référence CVE CVE-2021-45046
https://www.cve.org/CVERecord?id=CVE-2021-45046
Référence CVE CVE-2021-45105
https://www.cve.org/CVERecord?id=CVE-2021-45105
Référence CVE CVE-2022-34759
https://www.cve.org/CVERecord?id=CVE-2022-34759
Référence CVE CVE-2022-34760
https://www.cve.org/CVERecord?id=CVE-2022-34760
Référence CVE CVE-2022-34761
https://www.cve.org/CVERecord?id=CVE-2022-34761
Référence CVE CVE-2022-34762
https://www.cve.org/CVERecord?id=CVE-2022-34762
Référence CVE CVE-2022-34763
https://www.cve.org/CVERecord?id=CVE-2022-34763
Référence CVE CVE-2022-34764
https://www.cve.org/CVERecord?id=CVE-2022-34764
Référence CVE CVE-2022-34765
https://www.cve.org/CVERecord?id=CVE-2022-34765
Référence CVE CVE-2022-37300
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-570Multiples vulnérabilités dans les produits IBMRecord?id=CVE-2019-0205
Référence CVE CVE-2019-0210
https://www.cve.org/CVERecord?id=CVE-2019-0210
Référence CVE CVE-2020-13949
https://www.cve.org/CVERecord?id=CVE-2020-13949
Référence CVE CVE-2021-22945
https://www.cve.org/CVERecord?id=CVE-2021-22945
Référence CVE CVE-2021-22946
https://www.cve.org/CVERecord?id=CVE-2021-22946
Référence CVE CVE-2021-22947
https://www.cve.org/CVERecord?id=CVE-2021-22947
Référence CVE CVE-2021-3712
https://www.cve.org/CVERecord?id=CVE-2021-3712
Référence CVE CVE-2021-44228
https://www.cve.org/CVERecord?id=CVE-2021-44228
Référence CVE CVE-2021-45046
https://www.cve.org/CVERecord?id=CVE-2021-45046
Référence CVE CVE-2021-45105
https://www.cve.org/CVERecord?id=CVE-2021-45105
Référence CVE CVE-2022-0778
https://www.cve.org/CVERecord?id=CVE-2022-0778
Référence CVE CVE-2022-1292
https://www.cve.org/CVERecord?id=CVE-2022-1292
Référence CVE CVE-2022-1343
https://www.cve.org/CVERecord?id=CVE-2022-1343
Référence CVE CVE-2022-1434
https://www.cve.org/CVERecord?id=CVE-2022-1434
Référence CVE CVE-2022-1473
https://www.cve.org/CVERecord?id=CVE-2022-1473
Référence CVE CVE-2022-22576
https://www.cve.org/CVERecord?id=CVE-2022-22576
Référence CVE CVE-2022-27774
https://www.cve.org/CVERecord?id=CVE-2022-27774
Référence CVE CVE-2022-27775
https://www.cve.org/CVERecord?id=CVE-2022-2
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-568Multiples vulnérabilités dans les produits IBMcord?id=CVE-2020-9547
Référence CVE CVE-2020-9548
https://www.cve.org/CVERecord?id=CVE-2020-9548
Référence CVE CVE-2021-20190
https://www.cve.org/CVERecord?id=CVE-2021-20190
Référence CVE CVE-2021-27568
https://www.cve.org/CVERecord?id=CVE-2021-27568
Référence CVE CVE-2021-29425
https://www.cve.org/CVERecord?id=CVE-2021-29425
Référence CVE CVE-2021-33813
https://www.cve.org/CVERecord?id=CVE-2021-33813
Référence CVE CVE-2021-38153
https://www.cve.org/CVERecord?id=CVE-2021-38153
Référence CVE CVE-2021-44228
https://www.cve.org/CVERecord?id=CVE-2021-44228
Référence CVE CVE-2021-45046
https://www.cve.org/CVERecord?id=CVE-2021-45046
Référence CVE CVE-2021-45105
https://www.cve.org/CVERecord?id=CVE-2021-45105
Référence CVE CVE-2022-22965
https://www.cve.org/CVERecord?id=CVE-2022-22965
Gestion détaillée du document
le 17 juin 2022
Version initiale
Alertes
Avis
Bulletins d’actualités
Mentions légales
Conditions générales
À propos
Contact
cyber.gouv.fr
service-public.fr
legifrance.gouv.fr
info.gouv.fr
france.fr
info.gouv.fr/risques
Premier Ministre / Secrétariat Général de la Défense et de la Sécurité Nationale / Agence nationale de la
sécurité des systèmes d'information
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-526Multiples vulnérabilités dans les produits IBMDe multiples vulnérabilités ont été découvertes dans les produits IBM.
Certaines d'entre elles permettent à un attaquant de provoquer une
exécution de code arbitraire à distance, une exécution de code
arbitraire et un déni de service à distance.
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-125Multiples vulnérabilités dans les produits SAPDe multiples vulnérabilités ont été découvertes dans les produits SAP.
Elles permettent à un attaquant de provoquer un déni de service à
distance, une atteinte à l'intégrité des données et une atteinte à la
confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-1027Multiples vulnérabilités dans IBM Db2De multiples vulnérabilités ont été découvertes dans IBM Db2. Elles
permettent à un attaquant de provoquer une exécution de code arbitraire
à distance, un déni de service à distance et une atteinte à la
confidentialité des données.
Official advisory ↗JVN iPedia · Japanese · JVNDB-2021-005429Apache Log4j における任意のコードが実行可能な脆弱性Log4j には JNDI Lookup 機能による外部入力値の検証不備に起因して任意の Java コードを実行可能な脆弱性が存在します。 The Apache Software Foundation が提供する Log4j は、Java ベースのロギングライブラリです。Log4j には、ログに記載された文字列から一部の値を変数として評価する Lookup 機能が実装されています。 その Lookup 機能の内、JNDI Lookup 機能を悪用することにより、ログに含まれる外部の URL もしくは内部パスから Java のクラス情報をデシリアライズして実行してしまう問題(CWE-20, CVE-2021-44228)が発見されました。 これにより、遠隔の攻撃者が細工した文字列を脆弱なシステムのログに記載させ、結果として任意の Java コードをシステムに実行させることが可能です。
Official advisory ↗KISA KrCERT/CC · Korean · KNVD-5487설 연휴기간 사이버 공격 대비 보안 권고 사항 (상세)확인적용
② 기본 원격포트(22. 3389) 사용을 자제하고, OTP 등을 통한 추가 인증 강화
③ VPN 장비를 운영하는 경우, 허가된 사용자와 단말기만 업무망에 접근할 수 있도록 설정하고 OTP 등을 통한 추가 인증 강화
④ 다수의 서버를 운영하는 경우 내부 서버 간 원격접속이 불가능 하도록 접근 제어 설정
⑤ AD 인프라를 운영 중인 기업의 경우, 관리자 그룹 계정의 최소화 및 관련 PC의 인터넷망 분리 운영
⑥ 주요 관리자 PC에 대한 주기적인 보안 점검 및 인터넷망 분리 운영
⑦ 외부에 오픈된 DB서비스(MSSQL, MYSQL 등) 접근을 차단하고, 불필요하게 외부에 오픈된 원격 접속 서비스 접근 차단
⑧ DB 최초 설치 시 기본 관리자 패스워드는 반드시 변경 후 사용하고, 사용하지 않는 계정 비활성화
⑨ 가상머신 운영환경을 타깃으로 하는 리눅스용 랜섬웨어 공격이 발생하고 있으니 백업 및 운영체계 강화
☞ 특히 아래의 취약점을 이용하여 해킹사고가 발생 할 수 있으니 반드시 보안 업데이트 등 조치 필요
(1) MS 윈도우 Exchange 서버 취약점 보안 업데이트 권고 (CVE-2021-26855, 26857, 27065, 26585, 27065, 31207, 34473, 34523)
(2) Apache Log4j 보안 업데이트 권고 (CVE-2021-45105, 44832, CVE-2022-23302, 23305, 23307)
o PC 보안 강화 방안
① 피싱 메일에 주의하고 본문 링크 클릭, 첨부파일 다운로드, 실행에 주의
② 매월 운영체제 및 주요 프로그램(웹브라우저, Flash, Java 등)의 보안 업데이트 확인적용
③ 상용 메일을 통한 주요 업무 자료 송수신 금지
※ 불가피한 경우, OTP 설정 및 허가된 사용자 단말기 추가 등을 통해 인증 강화
④ 웹하드·P2P 사이트를 통한 불법 다운로드 금지
o NAS 보안 강화 방안
① 최초 설치 시 기본 관리자 패스워드는 반드시 변경 후 사용
② 자동 업데이트를 활성화하여 최신 펌웨어 유지
③ 인터넷을 통한 직접 접속은 차단하고, 사내망에서 운영 권고
※ 불가피한 경우, 장비의 비밀번호 관리 및 백업, 보안 업데이트 등 철저한 관리 필요
o IoT 보안 강화 방안
① 관리자 페이지 초기 설정 비밀번호 변경 후 사용
② 불필요한 SSH 등 포트 사용 중지
※ 불가피한 경우, 장비의 로그인 계정 변경(관리자 로그인 계정과 다른 값으로 설정)
☞ 특히 IP카메라, LTE모뎀, DVR 제품의 경우 필수적으로 조치 필요
o 공통 보안 강화 방안
① 사용하지 않는 시스템은 전원을 종료하여 해킹 경로로 활용되는 것을 사전 방지
② 중요 파일 및 문서 등은 네트워
Official advisory ↗KISA KrCERT/CC · Korean · KNVD-5474Apache Log4j 보안 업데이트 권고(CVE-2021-45105, 44832, CVE-2022-23302, 23305, 23307) (Update. 22-1-21 17:00)#### Apache Log4j 보안 업데이트 권고(CVE-2021-45105, 44832, CVE-2022-23302, 23305, 23307) (Update. 22-1-21 17:00) 2021.12.18
2021-12-18 : CVE-2021-45105 취약점 보안 업데이트
2021-12-20 : 조치방안 내 오타 수정
2021-12-22 : 대응방안 업데이트(Java 6, 7 대상)
2021-12-29 : CVE-2021-44832 취약점 보안 업데이트
2021-12-30 : Log4j 2.12.4, 2.3.2 다운로드 추가
2021-12-31 : 영향을 받는 부분 수정
2022-1-3 : 영향받는 버전 수정
2022-1-21 : CVE-2022-23302, 23305, 23307 취약점 관련 내용 추가
##### □ 개요
o Apache 소프트웨어 재단은 자사의 Log4j에서 발생하는 취약점을 해결한 보안 업데이트 권고[1]
o 공격자는 해당 취약점을 이용하여 정상 서비스 중지 등의 피해를 발생시킬수 있으므로, 최신 버전으로 업데이트 권고
※ Log4j 취약점을 이용한 침해사고 발생시 한국인터넷진흥원에 신고해 주시기 바랍니다.
##### □ 주요 내용
o Apache Log4j 2에서 발생하는 서비스 거부 취약점(CVE-2021-45105)[2]
o Apache Log4j 2에서 발생하는 원격코드 실행 취약점(C
Official advisory ↗NCSC-NL · Dutch · NCSC-2026-0027Kwetsbaarheden verholpen in Oracle Fusion MiddlewareMultiple vulnerabilities across Apache Log4j, Oracle products, and various dependencies expose systems to denial-of-service and remote code execution risks, necessitating updates to secure versions.
Official advisory ↗