{"id":"CVE-2021-45105","title":"Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups","summary":"Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial …","severity":"medium","cvss":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-20","CWE-674","CWE-20","CWE-674"],"vendor":"apache","product":"log4j","affected":["log4j >= 2.0, < 2.3.1","log4j >= 2.4, < 2.12.3","log4j >= 2.13.0, <= 2.16.0","cloud_manager","debian_linux = 10.0","debian_linux = 11.0","email_security <= 10.0.12","network_security_manager >= 2.0, < 3.0","web_application_firewall >= 3.0.0, < 3.1.0","6bk1602-0aa12-0tp0_firmware < 2.7.0","6bk1602-0aa22-0tp0_firmware < 2.7.0","6bk1602-0aa32-0tp0_firmware < 2.7.0","6bk1602-0aa42-0tp0_firmware < 2.7.0","6bk1602-0aa52-0tp0_firmware < 2.7.0","agile_engineering_data_management = 6.2.1.0","agile_plm_mcad_connector = 3.6","agile_product_lifecycle_management = 9.3.6","autovue_for_agile_product_lifecycle_management = 21.0.2","banking_deposits_and_lines_of_credit_servicing = 2.12.0","banking_enterprise_default_management = 2.7.1","banking_enterprise_default_management = 2.12.0","banking_loans_servicing = 2.12.0","banking_party_management = 2.7.0","banking_payments = 14.5","banking_platform = 2.6.2","banking_platform = 2.7.1","banking_platform = 2.12.0","banking_trade_finance = 14.5","banking_treasury_management = 14.5","business_intelligence = 5.5.0.0.0","communications_asap = 7.3","communications_billing_and_revenue_management = 12.0.0.4","communications_billing_and_revenue_management = 12.0.0.5","communications_cloud_native_core_console = 1.9.0","communications_cloud_native_core_network_function_cloud_native_environment = 1.10.0","communications_cloud_native_core_network_repository_function = 1.15.0","communications_cloud_native_core_network_repository_function = 1.15.1","communications_cloud_native_core_network_slice_selection_function = 1.8.0","communications_cloud_native_core_policy = 1.15.0","communications_cloud_native_core_security_edge_protection_proxy = 1.7.0","communications_cloud_native_core_service_communication_proxy = 1.15.0","communications_cloud_native_core_unified_data_repository = 1.15.0","communications_convergence = 3.0.2.2.0","communications_convergence = 3.0.3.0","communications_convergent_charging_controller >= 12.0.1.0.0, <= 12.0.4.0.0","communications_convergent_charging_controller = 6.0.1.0.0","communications_diameter_signaling_router >= 8.3.0.0, <= 8.5.1.0","communications_eagle_element_management_system = 46.6","communications_eagle_ftp_table_base_retrieval = 4.5","communications_element_manager < 9.0","communications_evolved_communications_application_server = 7.1","communications_interactive_session_recorder = 6.3","communications_interactive_session_recorder = 6.4","communications_ip_service_activator = 7.4.0","communications_messaging_server = 8.1","communications_network_charging_and_control >= 12.0.1.0.0, <= 12.0.4.0.0","communications_network_charging_and_control = 6.0.1.0.0","communications_network_integrity = 7.3.6","communications_performance_intelligence_center = 10.4.0.3","communications_pricing_design_center = 12.0.0.4","communications_pricing_design_center = 12.0.0.5","communications_service_broker = 6.2","communications_services_gatekeeper = 7.0","communications_session_report_manager < 9.0","communications_session_route_manager < 9.0","communications_unified_inventory_management = 7.3.5","communications_unified_inventory_management = 7.4.1","communications_unified_inventory_management = 7.4.2","communications_user_data_repository = 12.4","communications_webrtc_session_controller = 7.2.0.0","communications_webrtc_session_controller = 7.2.1","data_integrator = 12.2.1.3.0","data_integrator = 12.2.1.4.0","e-business_suite = 12.2","enterprise_manager_base_platform = 13.4.0.0","enterprise_manager_base_platform = 13.5.0.0","enterprise_manager_for_peoplesoft = 13.4.1.1","enterprise_manager_for_peoplesoft = 13.5.1.1","enterprise_manager_ops_center = 12.4.0.0","financial_services_analytical_applications_infrastructure >= 8.0.7, <= 8.1.1","financial_services_model_management_and_governance = 8.0.8.0.0","financial_services_model_management_and_governance = 8.1.0.0.0","financial_services_model_management_and_governance = 8.1.1.0.0","flexcube_universal_banking >= 12.1.0, <= 12.4","flexcube_universal_banking >= 14.0.0, <= 14.3.0","flexcube_universal_banking = 11.83.3","flexcube_universal_banking = 14.5","health_sciences_empirica_signal = 9.1.0.6","health_sciences_empirica_signal = 9.2.0.0","health_sciences_inform = 6.2.1.1","health_sciences_inform = 6.3.2.1","health_sciences_inform = 7.0.0.0","health_sciences_information_manager >= 3.0.1, <= 3.0.4","healthcare_data_repository = 8.1.1","healthcare_foundation >= 7.3.0.1, <= 7.3.0.4","healthcare_master_person_index = 5.0.1","healthcare_translational_research = 4.1.0","healthcare_translational_research = 4.1.1","hospitality_suite8 = 8.13.0","hospitality_suite8 = 8.14.0"],"patched":["log4j 2.12.3","network_security_manager 3.0","web_application_firewall 3.1.0","6bk1602-0aa12-0tp0_firmware 2.7.0","6bk1602-0aa22-0tp0_firmware 2.7.0","6bk1602-0aa32-0tp0_firmware 2.7.0","6bk1602-0aa42-0tp0_firmware 2.7.0","6bk1602-0aa52-0tp0_firmware 2.7.0","communications_element_manager 9.0","communications_session_report_manager 9.0","communications_session_route_manager 9.0"],"published":"2021-12-18","updated":"2026-08-25","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2021-45105","references":[{"url":"http://www.openwall.com/lists/oss-security/2021/12/19/1","label":"security@apache.org"},{"url":"https://cert-portal.siemens.com/productcert/pdf/ssa-479842.pdf","label":"security@apache.org"},{"url":"https://cert-portal.siemens.com/productcert/pdf/ssa-501673.pdf","label":"security@apache.org"},{"url":"https://logging.apache.org/log4j/2.x/security.html","label":"security@apache.org"},{"url":"https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0032","label":"security@apache.org"},{"url":"https://security.netapp.com/advisory/ntap-20211218-0001/","label":"security@apache.org"},{"url":"https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd","label":"security@apache.org"},{"url":"https://www.debian.org/security/2021/dsa-5024","label":"security@apache.org"},{"url":"https://www.kb.cert.org/vuls/id/930724","label":"security@apache.org"},{"url":"https://www.oracle.com/security-alerts/cpuapr2022.html","label":"security@apache.org"},{"url":"https://www.oracle.com/security-alerts/cpujan2022.html","label":"security@apache.org"},{"url":"https://www.oracle.com/security-alerts/cpujul2022.html","label":"security@apache.org"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-21-1541/","label":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2021/12/19/1","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://cert-portal.siemens.com/productcert/pdf/ssa-479842.pdf","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://cert-portal.siemens.com/productcert/pdf/ssa-501673.pdf","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://logging.apache.org/log4j/2.x/security.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0032","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20211218-0001/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.debian.org/security/2021/dsa-5024","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.kb.cert.org/vuls/id/930724","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuapr2022.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujan2022.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujul2022.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-21-1541/","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","exploit-available"],"epss":0.99999,"epssPercentile":0.99991,"zeroDay":true,"ingestedAt":"2026-08-25T17:29:31.858Z","exploits":{"github":7,"githubRepos":["https://github.com/cckuailong/Log4j_dos_CVE-2021-45105","https://github.com/pravin-pp/log4j2-CVE-2021-45105","https://github.com/tejas-nagchandi/CVE-2021-45105"],"checkedAt":"2026-09-08T15:36:49.499Z"},"exploitAvailable":true,"slug":"CVE-2021-45105","body":"## Overview\n\nApache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.\n\n## Affected\n\n- `log4j >= 2.0, < 2.3.1`\n- `log4j >= 2.4, < 2.12.3`\n- `log4j >= 2.13.0, <= 2.16.0`\n- `cloud_manager`\n- `debian_linux = 10.0`\n- `debian_linux = 11.0`\n- `email_security <= 10.0.12`\n- `network_security_manager >= 2.0, < 3.0`\n- `web_application_firewall >= 3.0.0, < 3.1.0`\n- `6bk1602-0aa12-0tp0_firmware < 2.7.0`\n- `6bk1602-0aa22-0tp0_firmware < 2.7.0`\n- `6bk1602-0aa32-0tp0_firmware < 2.7.0`\n- `6bk1602-0aa42-0tp0_firmware < 2.7.0`\n- `6bk1602-0aa52-0tp0_firmware < 2.7.0`\n- `agile_engineering_data_management = 6.2.1.0`\n- `agile_plm_mcad_connector = 3.6`\n- `agile_product_lifecycle_management = 9.3.6`\n- `autovue_for_agile_product_lifecycle_management = 21.0.2`\n- `banking_deposits_and_lines_of_credit_servicing = 2.12.0`\n- `banking_enterprise_default_management = 2.7.1`\n- `banking_enterprise_default_management = 2.12.0`\n- `banking_loans_servicing = 2.12.0`\n- `banking_party_management = 2.7.0`\n- `banking_payments = 14.5`\n- `banking_platform = 2.6.2`\n- `banking_platform = 2.7.1`\n- `banking_platform = 2.12.0`\n- `banking_trade_finance = 14.5`\n- `banking_treasury_management = 14.5`\n- `business_intelligence = 5.5.0.0.0`\n- `communications_asap = 7.3`\n- `communications_billing_and_revenue_management = 12.0.0.4`\n- `communications_billing_and_revenue_management = 12.0.0.5`\n- `communications_cloud_native_core_console = 1.9.0`\n- `communications_cloud_native_core_network_function_cloud_native_environment = 1.10.0`\n- `communications_cloud_native_core_network_repository_function = 1.15.0`\n- `communications_cloud_native_core_network_repository_function = 1.15.1`\n- `communications_cloud_native_core_network_slice_selection_function = 1.8.0`\n- `communications_cloud_native_core_policy = 1.15.0`\n- `communications_cloud_native_core_security_edge_protection_proxy = 1.7.0`\n- `communications_cloud_native_core_service_communication_proxy = 1.15.0`\n- `communications_cloud_native_core_unified_data_repository = 1.15.0`\n- `communications_convergence = 3.0.2.2.0`\n- `communications_convergence = 3.0.3.0`\n- `communications_convergent_charging_controller >= 12.0.1.0.0, <= 12.0.4.0.0`\n- `communications_convergent_charging_controller = 6.0.1.0.0`\n- `communications_diameter_signaling_router >= 8.3.0.0, <= 8.5.1.0`\n- `communications_eagle_element_management_system = 46.6`\n- `communications_eagle_ftp_table_base_retrieval = 4.5`\n- `communications_element_manager < 9.0`\n- `communications_evolved_communications_application_server = 7.1`\n- `communications_interactive_session_recorder = 6.3`\n- `communications_interactive_session_recorder = 6.4`\n- `communications_ip_service_activator = 7.4.0`\n- `communications_messaging_server = 8.1`\n- `communications_network_charging_and_control >= 12.0.1.0.0, <= 12.0.4.0.0`\n- `communications_network_charging_and_control = 6.0.1.0.0`\n- `communications_network_integrity = 7.3.6`\n- `communications_performance_intelligence_center = 10.4.0.3`\n- `communications_pricing_design_center = 12.0.0.4`\n- `communications_pricing_design_center = 12.0.0.5`\n- `communications_service_broker = 6.2`\n- `communications_services_gatekeeper = 7.0`\n- `communications_session_report_manager < 9.0`\n- `communications_session_route_manager < 9.0`\n- `communications_unified_inventory_management = 7.3.5`\n- `communications_unified_inventory_management = 7.4.1`\n- `communications_unified_inventory_management = 7.4.2`\n- `communications_user_data_repository = 12.4`\n- `communications_webrtc_session_controller = 7.2.0.0`\n- `communications_webrtc_session_controller = 7.2.1`\n- `data_integrator = 12.2.1.3.0`\n- `data_integrator = 12.2.1.4.0`\n- `e-business_suite = 12.2`\n- `enterprise_manager_base_platform = 13.4.0.0`\n- `enterprise_manager_base_platform = 13.5.0.0`\n- `enterprise_manager_for_peoplesoft = 13.4.1.1`\n- `enterprise_manager_for_peoplesoft = 13.5.1.1`\n- `enterprise_manager_ops_center = 12.4.0.0`\n- `financial_services_analytical_applications_infrastructure >= 8.0.7, <= 8.1.1`\n- `financial_services_model_management_and_governance = 8.0.8.0.0`\n- `financial_services_model_management_and_governance = 8.1.0.0.0`\n- `financial_services_model_management_and_governance = 8.1.1.0.0`\n- `flexcube_universal_banking >= 12.1.0, <= 12.4`\n- `flexcube_universal_banking >= 14.0.0, <= 14.3.0`\n- `flexcube_universal_banking = 11.83.3`\n- `flexcube_universal_banking = 14.5`\n- `health_sciences_empirica_signal = 9.1.0.6`\n- `health_sciences_empirica_signal = 9.2.0.0`\n- `health_sciences_inform = 6.2.1.1`\n- `health_sciences_inform = 6.3.2.1`\n- `health_sciences_inform = 7.0.0.0`\n- `health_sciences_information_manager >= 3.0.1, <= 3.0.4`\n- `healthcare_data_repository = 8.1.1`\n- `healthcare_foundation >= 7.3.0.1, <= 7.3.0.4`\n- `healthcare_master_person_index = 5.0.1`\n- `healthcare_translational_research = 4.1.0`\n- `healthcare_translational_research = 4.1.1`\n- `hospitality_suite8 = 8.13.0`\n- `hospitality_suite8 = 8.14.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `log4j 2.12.3`\n- `network_security_manager 3.0`\n- `web_application_firewall 3.1.0`\n- `6bk1602-0aa12-0tp0_firmware 2.7.0`\n- `6bk1602-0aa22-0tp0_firmware 2.7.0`\n- `6bk1602-0aa32-0tp0_firmware 2.7.0`\n- `6bk1602-0aa42-0tp0_firmware 2.7.0`\n- `6bk1602-0aa52-0tp0_firmware 2.7.0`\n- `communications_element_manager 9.0`\n- `communications_session_report_manager 9.0`\n- `communications_session_route_manager 9.0`","depth":"midnight","depthScore":77,"depthScoreParts":{"impact":32.5,"likelihood":20,"exploitation":25,"ransomware":0},"changes":[{"seq":4555,"id":"CVE-2021-45105","ts":1788887189819,"field":"exploit_available","old":"false","new":"true"},{"seq":3438,"id":"CVE-2021-45105","ts":1788886307055,"field":"exploit_available","old":"true","new":"false"},{"seq":2292,"id":"CVE-2021-45105","ts":1788882976767,"field":"exploit_available","old":"false","new":"true"},{"seq":1321,"id":"CVE-2021-45105","ts":1788882388734,"field":"exploit_available","old":"true","new":"false"},{"seq":435,"id":"CVE-2021-45105","ts":1788881824341,"field":"exploit_available","old":"false","new":"true"}]}