Apply updates per vendor instructions.
Evidence dossier
CVE-2021-45046
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
gen-56ccdaf9Normalized restatement
It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in an information leak and remote code execution in some environments and local code execution in all environments. Log4j 2.16.0 (Java 8) and 2.12.2 (Java 7) fix this issue by removing support for message lookup patterns and disabling JNDI functionality by default.
- State
- PUBLISHED
- Published
- Dec 14, 2021
- Updated
- Oct 21, 2025
- Evidence coverage
- 72%
2026-07-18 · v2026.06.15 · percentile 100.0%
Distinct CVSS assessments remain side by side; none are averaged.
Source comparison
Who said what
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
Apache Log4j2 Deserialization of Untrusted Data Vulnerability
Probability 0.999770000000; percentile 0.999800000000
Applicability
Cited product scope
[{"status": "affected", "version": "Apache Log4j2", "lessThan": "2.16.0", "versionType": "custom"}]unknowncpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:*; start including 2.0.1; end excluding 2.12.2supportedcpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:*; start including 2.13.0; end excluding 2.16.0supportedcpe:2.3:a:apache:log4j:2.0:-:*:*:*:*:*:*supportedcpe:2.3:a:apache:log4j:2.0:beta9:*:*:*:*:*:*supportedcpe:2.3:a:apache:log4j:2.0:rc1:*:*:*:*:*:*supportedcpe:2.3:a:apache:log4j:2.0:rc2:*:*:*:*:*:*supportedcpe:2.3:a:cvat:computer_vision_annotation_tool:-:*:*:*:*:*:*:*supportedcpe:2.3:a:intel:audio_development_kit:-:*:*:*:*:*:*:*supportedcpe:2.3:a:intel:datacenter_manager:-:*:*:*:*:*:*:*supportedcpe:2.3:a:intel:genomics_kernel_library:-:*:*:*:*:*:*:*supportedcpe:2.3:a:intel:oneapi:-:*:*:*:*:eclipse:*:*supportedcpe:2.3:a:intel:secure_device_onboard:-:*:*:*:*:*:*:*supportedcpe:2.3:a:intel:sensor_solution_firmware_development_kit:-:*:*:*:*:*:*:*supportedcpe:2.3:a:intel:system_debugger:-:*:*:*:*:*:*:*supportedcpe:2.3:a:intel:system_studio:-:*:*:*:*:*:*:*supportedcpe:2.3:a:siemens:captial:*:*:*:*:*:*:*:*; end excluding 2019.1supportedcpe:2.3:a:siemens:captial:2019.1:-:*:*:*:*:*:*supportedcpe:2.3:a:siemens:captial:2019.1:sp1912:*:*:*:*:*:*supportedcpe:2.3:a:siemens:comos:*:*:*:*:*:*:*:*supportedcpe:2.3:a:siemens:desigo_cc_advanced_reports:4.0:*:*:*:*:*:*:*supportedcpe:2.3:a:siemens:desigo_cc_advanced_reports:4.1:*:*:*:*:*:*:*supportedcpe:2.3:a:siemens:desigo_cc_advanced_reports:4.2:*:*:*:*:*:*:*supportedcpe:2.3:a:siemens:desigo_cc_advanced_reports:5.0:*:*:*:*:*:*:*supportedcpe:2.3:a:siemens:desigo_cc_advanced_reports:5.1:*:*:*:*:*:*:*supportedcpe:2.3:a:siemens:desigo_cc_info_center:5.0:*:*:*:*:*:*:*supportedcpe:2.3:a:siemens:desigo_cc_info_center:5.1:*:*:*:*:*:*:*supportedcpe:2.3:a:siemens:e-car_operation_center:*:*:*:*:*:*:*:*; end excluding 2021-12-13supportedcpe:2.3:a:siemens:energy_engage:3.1:*:*:*:*:*:*:*supportedcpe:2.3:a:siemens:energyip:8.5:*:*:*:*:*:*:*supportedcpe:2.3:a:siemens:energyip:8.6:*:*:*:*:*:*:*supportedcpe:2.3:a:siemens:energyip:8.7:*:*:*:*:*:*:*supportedcpe:2.3:a:siemens:energyip:9.0:*:*:*:*:*:*:*supportedcpe:2.3:a:siemens:energyip_prepay:3.7:*:*:*:*:*:*:*supportedcpe:2.3:a:siemens:energyip_prepay:3.8:*:*:*:*:*:*:*supportedcpe:2.3:a:siemens:gma-manager:*:*:*:*:*:*:*:*; end excluding 8.6.2j-398supportedcpe:2.3:a:siemens:head-end_system_universal_device_integration_system:*:*:*:*:*:*:*:*supportedcpe:2.3:a:siemens:industrial_edge_management:*:*:*:*:*:*:*:*supportedcpe:2.3:a:siemens:industrial_edge_management_hub:*:*:*:*:*:*:*:*; end excluding 2021-12-13supportedcpe:2.3:a:siemens:logo\!_soft_comfort:*:*:*:*:*:*:*:*supportedcpe:2.3:a:siemens:mendix:*:*:*:*:*:*:*:*supportedcpe:2.3:a:siemens:mindsphere:*:*:*:*:*:*:*:*; end excluding 2021-12-11supportedcpe:2.3:a:siemens:navigator:*:*:*:*:*:*:*:*; end excluding 2021-12-13supportedcpe:2.3:a:siemens:nx:*:*:*:*:*:*:*:*supportedcpe:2.3:a:siemens:opcenter_intelligence:*:*:*:*:*:*:*:*; end including 3.2supportedcpe:2.3:a:siemens:operation_scheduler:*:*:*:*:*:*:*:*; end including 1.1.3supportedcpe:2.3:a:siemens:sentron_powermanager:4.1:*:*:*:*:*:*:*supportedcpe:2.3:a:siemens:sentron_powermanager:4.2:*:*:*:*:*:*:*supportedcpe:2.3:a:siemens:siguard_dsa:4.2:*:*:*:*:*:*:*supportedcpe:2.3:a:siemens:siguard_dsa:4.3:*:*:*:*:*:*:*supportedcpe:2.3:a:siemens:siguard_dsa:4.4:*:*:*:*:*:*:*supportedcpe:2.3:a:siemens:sipass_integrated:2.80:*:*:*:*:*:*:*supportedcpe:2.3:a:siemens:sipass_integrated:2.85:*:*:*:*:*:*:*supportedcpe:2.3:a:siemens:siveillance_command:*:*:*:*:*:*:*:*; end including 4.16.2.1supportedcpe:2.3:a:siemens:siveillance_control_pro:*:*:*:*:*:*:*:*supportedcpe:2.3:a:siemens:siveillance_identity:1.5:*:*:*:*:*:*:*supportedcpe:2.3:a:siemens:siveillance_identity:1.6:*:*:*:*:*:*:*supportedcpe:2.3:a:siemens:siveillance_vantage:*:*:*:*:*:*:*:*supportedcpe:2.3:a:siemens:siveillance_viewpoint:*:*:*:*:*:*:*:*supportedcpe:2.3:a:siemens:solid_edge_cam_pro:*:*:*:*:*:*:*:*supportedcpe:2.3:a:siemens:solid_edge_harness_design:*:*:*:*:*:*:*:*; end excluding 2020supportedcpe:2.3:a:siemens:solid_edge_harness_design:2020:*:*:*:*:*:*:*supportedcpe:2.3:a:siemens:solid_edge_harness_design:2020:-:*:*:*:*:*:*supportedcpe:2.3:a:siemens:solid_edge_harness_design:2020:sp2002:*:*:*:*:*:*supportedcpe:2.3:a:siemens:spectrum_power_4:*:*:*:*:*:*:*:*; end excluding 4.70supportedcpe:2.3:a:siemens:spectrum_power_4:4.70:-:*:*:*:*:*:*supportedcpe:2.3:a:siemens:spectrum_power_4:4.70:sp7:*:*:*:*:*:*supportedcpe:2.3:a:siemens:spectrum_power_4:4.70:sp8:*:*:*:*:*:*supportedcpe:2.3:a:siemens:spectrum_power_7:*:*:*:*:*:*:*:*; end excluding 2.30supportedcpe:2.3:a:siemens:spectrum_power_7:2.30:*:*:*:*:*:*:*supportedcpe:2.3:a:siemens:spectrum_power_7:2.30:-:*:*:*:*:*:*supportedcpe:2.3:a:siemens:spectrum_power_7:2.30:sp2:*:*:*:*:*:*supportedcpe:2.3:a:siemens:teamcenter:*:*:*:*:*:*:*:*supportedcpe:2.3:a:siemens:tracealertserverplus:*:*:*:*:*:*:*:*supportedcpe:2.3:a:siemens:vesys:*:*:*:*:*:*:*:*; end excluding 2019.1supportedcpe:2.3:a:siemens:vesys:2019.1:*:*:*:*:*:*:*supportedcpe:2.3:a:siemens:vesys:2019.1:-:*:*:*:*:*:*supportedcpe:2.3:a:siemens:vesys:2019.1:sp1912:*:*:*:*:*:*supportedcpe:2.3:a:siemens:xpedition_enterprise:-:*:*:*:*:*:*:*supportedcpe:2.3:a:siemens:xpedition_package_integrator:-:*:*:*:*:*:*:*supportedcpe:2.3:a:sonicwall:email_security:*:*:*:*:*:*:*:*; end excluding 10.0.12supportedcpe:2.3:h:siemens:6bk1602-0aa12-0tp0:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:siemens:6bk1602-0aa22-0tp0:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:siemens:6bk1602-0aa32-0tp0:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:siemens:6bk1602-0aa42-0tp0:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:siemens:6bk1602-0aa52-0tp0:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:siemens:sppa-t3000_ses3000:-:*:*:*:*:*:*:*constrainedcpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*supportedcpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*supportedcpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*supportedcpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*supportedcpe:2.3:o:siemens:6bk1602-0aa12-0tp0_firmware:*:*:*:*:*:*:*:*; end excluding 2.7.0supportedcpe:2.3:o:siemens:6bk1602-0aa22-0tp0_firmware:*:*:*:*:*:*:*:*; end excluding 2.7.0supportedcpe:2.3:o:siemens:6bk1602-0aa32-0tp0_firmware:*:*:*:*:*:*:*:*; end excluding 2.7.0supportedcpe:2.3:o:siemens:6bk1602-0aa42-0tp0_firmware:*:*:*:*:*:*:*:*; end excluding 2.7.0supportedcpe:2.3:o:siemens:6bk1602-0aa52-0tp0_firmware:*:*:*:*:*:*:*:*; end excluding 2.7.0supportedcpe:2.3:o:siemens:sppa-t3000_ses3000_firmware:*:*:*:*:*:*:*:*supportedAssessments
CVSS by origin
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:HAV:N/AC:H/Au:N/C:P/I:P/A:PCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:HCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:HLimitations and unknowns
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; unresolved scope remains unknown.
- NVD-carried upstream facts remain derivative and are not independent corroboration.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Factor D is unknown in Public Core because no accepted canonical mapping-obligation ledger is present.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.