---
id: CVE-2021-45105
title: >-
  Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1)
  did not protect from uncontrolled recursion from self-referential lookups
summary: >-
  Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1)
  did not protect from uncontrolled recursion from self-referential lookups.
  This allows an attacker with control over Thread Context Map data to cause a
  denial …
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-20
  - CWE-674
  - CWE-20
  - CWE-674
vendor: apache
product: log4j
affected:
  - 'log4j >= 2.0, < 2.3.1'
  - 'log4j >= 2.4, < 2.12.3'
  - 'log4j >= 2.13.0, <= 2.16.0'
  - cloud_manager
  - debian_linux = 10.0
  - debian_linux = 11.0
  - email_security <= 10.0.12
  - 'network_security_manager >= 2.0, < 3.0'
  - 'web_application_firewall >= 3.0.0, < 3.1.0'
  - 6bk1602-0aa12-0tp0_firmware < 2.7.0
  - 6bk1602-0aa22-0tp0_firmware < 2.7.0
  - 6bk1602-0aa32-0tp0_firmware < 2.7.0
  - 6bk1602-0aa42-0tp0_firmware < 2.7.0
  - 6bk1602-0aa52-0tp0_firmware < 2.7.0
  - agile_engineering_data_management = 6.2.1.0
  - agile_plm_mcad_connector = 3.6
  - agile_product_lifecycle_management = 9.3.6
  - autovue_for_agile_product_lifecycle_management = 21.0.2
  - banking_deposits_and_lines_of_credit_servicing = 2.12.0
  - banking_enterprise_default_management = 2.7.1
  - banking_enterprise_default_management = 2.12.0
  - banking_loans_servicing = 2.12.0
  - banking_party_management = 2.7.0
  - banking_payments = 14.5
  - banking_platform = 2.6.2
  - banking_platform = 2.7.1
  - banking_platform = 2.12.0
  - banking_trade_finance = 14.5
  - banking_treasury_management = 14.5
  - business_intelligence = 5.5.0.0.0
  - communications_asap = 7.3
  - communications_billing_and_revenue_management = 12.0.0.4
  - communications_billing_and_revenue_management = 12.0.0.5
  - communications_cloud_native_core_console = 1.9.0
  - >-
    communications_cloud_native_core_network_function_cloud_native_environment =
    1.10.0
  - communications_cloud_native_core_network_repository_function = 1.15.0
  - communications_cloud_native_core_network_repository_function = 1.15.1
  - communications_cloud_native_core_network_slice_selection_function = 1.8.0
  - communications_cloud_native_core_policy = 1.15.0
  - communications_cloud_native_core_security_edge_protection_proxy = 1.7.0
  - communications_cloud_native_core_service_communication_proxy = 1.15.0
  - communications_cloud_native_core_unified_data_repository = 1.15.0
  - communications_convergence = 3.0.2.2.0
  - communications_convergence = 3.0.3.0
  - 'communications_convergent_charging_controller >= 12.0.1.0.0, <= 12.0.4.0.0'
  - communications_convergent_charging_controller = 6.0.1.0.0
  - 'communications_diameter_signaling_router >= 8.3.0.0, <= 8.5.1.0'
  - communications_eagle_element_management_system = 46.6
  - communications_eagle_ftp_table_base_retrieval = 4.5
  - communications_element_manager < 9.0
  - communications_evolved_communications_application_server = 7.1
  - communications_interactive_session_recorder = 6.3
  - communications_interactive_session_recorder = 6.4
  - communications_ip_service_activator = 7.4.0
  - communications_messaging_server = 8.1
  - 'communications_network_charging_and_control >= 12.0.1.0.0, <= 12.0.4.0.0'
  - communications_network_charging_and_control = 6.0.1.0.0
  - communications_network_integrity = 7.3.6
  - communications_performance_intelligence_center = 10.4.0.3
  - communications_pricing_design_center = 12.0.0.4
  - communications_pricing_design_center = 12.0.0.5
  - communications_service_broker = 6.2
  - communications_services_gatekeeper = 7.0
  - communications_session_report_manager < 9.0
  - communications_session_route_manager < 9.0
  - communications_unified_inventory_management = 7.3.5
  - communications_unified_inventory_management = 7.4.1
  - communications_unified_inventory_management = 7.4.2
  - communications_user_data_repository = 12.4
  - communications_webrtc_session_controller = 7.2.0.0
  - communications_webrtc_session_controller = 7.2.1
  - data_integrator = 12.2.1.3.0
  - data_integrator = 12.2.1.4.0
  - e-business_suite = 12.2
  - enterprise_manager_base_platform = 13.4.0.0
  - enterprise_manager_base_platform = 13.5.0.0
  - enterprise_manager_for_peoplesoft = 13.4.1.1
  - enterprise_manager_for_peoplesoft = 13.5.1.1
  - enterprise_manager_ops_center = 12.4.0.0
  - 'financial_services_analytical_applications_infrastructure >= 8.0.7, <= 8.1.1'
  - financial_services_model_management_and_governance = 8.0.8.0.0
  - financial_services_model_management_and_governance = 8.1.0.0.0
  - financial_services_model_management_and_governance = 8.1.1.0.0
  - 'flexcube_universal_banking >= 12.1.0, <= 12.4'
  - 'flexcube_universal_banking >= 14.0.0, <= 14.3.0'
  - flexcube_universal_banking = 11.83.3
  - flexcube_universal_banking = 14.5
  - health_sciences_empirica_signal = 9.1.0.6
  - health_sciences_empirica_signal = 9.2.0.0
  - health_sciences_inform = 6.2.1.1
  - health_sciences_inform = 6.3.2.1
  - health_sciences_inform = 7.0.0.0
  - 'health_sciences_information_manager >= 3.0.1, <= 3.0.4'
  - healthcare_data_repository = 8.1.1
  - 'healthcare_foundation >= 7.3.0.1, <= 7.3.0.4'
  - healthcare_master_person_index = 5.0.1
  - healthcare_translational_research = 4.1.0
  - healthcare_translational_research = 4.1.1
  - hospitality_suite8 = 8.13.0
  - hospitality_suite8 = 8.14.0
patched:
  - log4j 2.12.3
  - network_security_manager 3.0
  - web_application_firewall 3.1.0
  - 6bk1602-0aa12-0tp0_firmware 2.7.0
  - 6bk1602-0aa22-0tp0_firmware 2.7.0
  - 6bk1602-0aa32-0tp0_firmware 2.7.0
  - 6bk1602-0aa42-0tp0_firmware 2.7.0
  - 6bk1602-0aa52-0tp0_firmware 2.7.0
  - communications_element_manager 9.0
  - communications_session_report_manager 9.0
  - communications_session_route_manager 9.0
published: '2021-12-18'
updated: '2026-08-25'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-45105'
references:
  - url: 'http://www.openwall.com/lists/oss-security/2021/12/19/1'
    label: security@apache.org
  - url: 'https://cert-portal.siemens.com/productcert/pdf/ssa-479842.pdf'
    label: security@apache.org
  - url: 'https://cert-portal.siemens.com/productcert/pdf/ssa-501673.pdf'
    label: security@apache.org
  - url: 'https://logging.apache.org/log4j/2.x/security.html'
    label: security@apache.org
  - url: 'https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0032'
    label: security@apache.org
  - url: 'https://security.netapp.com/advisory/ntap-20211218-0001/'
    label: security@apache.org
  - url: >-
      https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd
    label: security@apache.org
  - url: 'https://www.debian.org/security/2021/dsa-5024'
    label: security@apache.org
  - url: 'https://www.kb.cert.org/vuls/id/930724'
    label: security@apache.org
  - url: 'https://www.oracle.com/security-alerts/cpuapr2022.html'
    label: security@apache.org
  - url: 'https://www.oracle.com/security-alerts/cpujan2022.html'
    label: security@apache.org
  - url: 'https://www.oracle.com/security-alerts/cpujul2022.html'
    label: security@apache.org
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-21-1541/'
    label: security@apache.org
  - url: 'http://www.openwall.com/lists/oss-security/2021/12/19/1'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://cert-portal.siemens.com/productcert/pdf/ssa-479842.pdf'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://cert-portal.siemens.com/productcert/pdf/ssa-501673.pdf'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://logging.apache.org/log4j/2.x/security.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0032'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20211218-0001/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.debian.org/security/2021/dsa-5024'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.kb.cert.org/vuls/id/930724'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuapr2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujan2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujul2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-21-1541/'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - exploit-available
epss: 0.99999
epssPercentile: 0.99991
zeroDay: true
ingestedAt: '2026-08-25T17:29:31.858Z'
exploits:
  github: 7
  githubRepos:
    - 'https://github.com/cckuailong/Log4j_dos_CVE-2021-45105'
    - 'https://github.com/pravin-pp/log4j2-CVE-2021-45105'
    - 'https://github.com/tejas-nagchandi/CVE-2021-45105'
  checkedAt: '2026-09-08T15:36:49.499Z'
exploitAvailable: true
---

## Overview

Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.

## Affected

- `log4j >= 2.0, < 2.3.1`
- `log4j >= 2.4, < 2.12.3`
- `log4j >= 2.13.0, <= 2.16.0`
- `cloud_manager`
- `debian_linux = 10.0`
- `debian_linux = 11.0`
- `email_security <= 10.0.12`
- `network_security_manager >= 2.0, < 3.0`
- `web_application_firewall >= 3.0.0, < 3.1.0`
- `6bk1602-0aa12-0tp0_firmware < 2.7.0`
- `6bk1602-0aa22-0tp0_firmware < 2.7.0`
- `6bk1602-0aa32-0tp0_firmware < 2.7.0`
- `6bk1602-0aa42-0tp0_firmware < 2.7.0`
- `6bk1602-0aa52-0tp0_firmware < 2.7.0`
- `agile_engineering_data_management = 6.2.1.0`
- `agile_plm_mcad_connector = 3.6`
- `agile_product_lifecycle_management = 9.3.6`
- `autovue_for_agile_product_lifecycle_management = 21.0.2`
- `banking_deposits_and_lines_of_credit_servicing = 2.12.0`
- `banking_enterprise_default_management = 2.7.1`
- `banking_enterprise_default_management = 2.12.0`
- `banking_loans_servicing = 2.12.0`
- `banking_party_management = 2.7.0`
- `banking_payments = 14.5`
- `banking_platform = 2.6.2`
- `banking_platform = 2.7.1`
- `banking_platform = 2.12.0`
- `banking_trade_finance = 14.5`
- `banking_treasury_management = 14.5`
- `business_intelligence = 5.5.0.0.0`
- `communications_asap = 7.3`
- `communications_billing_and_revenue_management = 12.0.0.4`
- `communications_billing_and_revenue_management = 12.0.0.5`
- `communications_cloud_native_core_console = 1.9.0`
- `communications_cloud_native_core_network_function_cloud_native_environment = 1.10.0`
- `communications_cloud_native_core_network_repository_function = 1.15.0`
- `communications_cloud_native_core_network_repository_function = 1.15.1`
- `communications_cloud_native_core_network_slice_selection_function = 1.8.0`
- `communications_cloud_native_core_policy = 1.15.0`
- `communications_cloud_native_core_security_edge_protection_proxy = 1.7.0`
- `communications_cloud_native_core_service_communication_proxy = 1.15.0`
- `communications_cloud_native_core_unified_data_repository = 1.15.0`
- `communications_convergence = 3.0.2.2.0`
- `communications_convergence = 3.0.3.0`
- `communications_convergent_charging_controller >= 12.0.1.0.0, <= 12.0.4.0.0`
- `communications_convergent_charging_controller = 6.0.1.0.0`
- `communications_diameter_signaling_router >= 8.3.0.0, <= 8.5.1.0`
- `communications_eagle_element_management_system = 46.6`
- `communications_eagle_ftp_table_base_retrieval = 4.5`
- `communications_element_manager < 9.0`
- `communications_evolved_communications_application_server = 7.1`
- `communications_interactive_session_recorder = 6.3`
- `communications_interactive_session_recorder = 6.4`
- `communications_ip_service_activator = 7.4.0`
- `communications_messaging_server = 8.1`
- `communications_network_charging_and_control >= 12.0.1.0.0, <= 12.0.4.0.0`
- `communications_network_charging_and_control = 6.0.1.0.0`
- `communications_network_integrity = 7.3.6`
- `communications_performance_intelligence_center = 10.4.0.3`
- `communications_pricing_design_center = 12.0.0.4`
- `communications_pricing_design_center = 12.0.0.5`
- `communications_service_broker = 6.2`
- `communications_services_gatekeeper = 7.0`
- `communications_session_report_manager < 9.0`
- `communications_session_route_manager < 9.0`
- `communications_unified_inventory_management = 7.3.5`
- `communications_unified_inventory_management = 7.4.1`
- `communications_unified_inventory_management = 7.4.2`
- `communications_user_data_repository = 12.4`
- `communications_webrtc_session_controller = 7.2.0.0`
- `communications_webrtc_session_controller = 7.2.1`
- `data_integrator = 12.2.1.3.0`
- `data_integrator = 12.2.1.4.0`
- `e-business_suite = 12.2`
- `enterprise_manager_base_platform = 13.4.0.0`
- `enterprise_manager_base_platform = 13.5.0.0`
- `enterprise_manager_for_peoplesoft = 13.4.1.1`
- `enterprise_manager_for_peoplesoft = 13.5.1.1`
- `enterprise_manager_ops_center = 12.4.0.0`
- `financial_services_analytical_applications_infrastructure >= 8.0.7, <= 8.1.1`
- `financial_services_model_management_and_governance = 8.0.8.0.0`
- `financial_services_model_management_and_governance = 8.1.0.0.0`
- `financial_services_model_management_and_governance = 8.1.1.0.0`
- `flexcube_universal_banking >= 12.1.0, <= 12.4`
- `flexcube_universal_banking >= 14.0.0, <= 14.3.0`
- `flexcube_universal_banking = 11.83.3`
- `flexcube_universal_banking = 14.5`
- `health_sciences_empirica_signal = 9.1.0.6`
- `health_sciences_empirica_signal = 9.2.0.0`
- `health_sciences_inform = 6.2.1.1`
- `health_sciences_inform = 6.3.2.1`
- `health_sciences_inform = 7.0.0.0`
- `health_sciences_information_manager >= 3.0.1, <= 3.0.4`
- `healthcare_data_repository = 8.1.1`
- `healthcare_foundation >= 7.3.0.1, <= 7.3.0.4`
- `healthcare_master_person_index = 5.0.1`
- `healthcare_translational_research = 4.1.0`
- `healthcare_translational_research = 4.1.1`
- `hospitality_suite8 = 8.13.0`
- `hospitality_suite8 = 8.14.0`

## Remediation

Upgrade past the affected range:

- `log4j 2.12.3`
- `network_security_manager 3.0`
- `web_application_firewall 3.1.0`
- `6bk1602-0aa12-0tp0_firmware 2.7.0`
- `6bk1602-0aa22-0tp0_firmware 2.7.0`
- `6bk1602-0aa32-0tp0_firmware 2.7.0`
- `6bk1602-0aa42-0tp0_firmware 2.7.0`
- `6bk1602-0aa52-0tp0_firmware 2.7.0`
- `communications_element_manager 9.0`
- `communications_session_report_manager 9.0`
- `communications_session_route_manager 9.0`
