Last Update: January 04, 2022
1. Overview
Multiple vulnerabilities have been found in Apache Log4j.
CVE-2021-44832: Remote Code Execution Vulnerability
Apache Log4j2 vulnerable to RCE via JDBC Appender when attacker controls configuration.
CVE-2021-45105: Denial of Service Vulnerability
Apache Log4j2 does not always protect from infinite recursion in lookup evaluation.
CVE-2021-45046: Code Execution Vulnerability
Apache Log4j2 Thread Context Lookup Pattern vulnerable to remote code execution in certain non-default configurations.
CVE-2021-44228: Remote Code Execution Vulnerability
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints.
2. Hitachi Product Information
December 28, 2021
December 17, 2021
hitachi-sec-2021-145 : Vulnerability in JP1/VERITAS
hitachi-sec-2021-146 : Vulnerability in Hitachi Device Manager, Hitachi Infrastructure Analytics Advisor, Hitachi Automation Director, Hitachi Ops Center Analyzer, Hitachi Ops Center Automator and Hitachi Ops Center Administrator
hitachi-sec-2021-147 : Vulnerability in Hitachi Storage Plug-in for VMware vCenter
December 14, 2021
December 10, 2021
3. References
The Apache Software Foundation
Apache Log4j Security Vulnerabilities
https://logging.apache.org/log4j/2.x/security.html
CERT Coordination Center
Vulnerability Note VU#930724
https://www.kb.cert.org/vuls/id/930724
CISA
Apache Log4j Vulnerability Guidance
https://www.cisa.gov/uscert/apache-log4j-vulnerability-guidance
4. Update history
January 04, 2022
Masato Terada (HIRT) and Naoko Ohnishi (HIRT)