[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Remote code execution in Log4j 1.x

ID: oval:org.secpod.oval:def:76377Date: (C)2021-12-14   (M)2023-12-26
Class: VULNERABILITYFamily: unix




A flaw was found in the Java logging library Apache Log4j in version 1.x. JMSAppender in Log4j 1.x is vulnerable to deserialization of untrusted data. This allows a remote attacker to execute code on the server if the deployed application is configured to use JMSAppender and to the attacker's JMS Broker.

Platform:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 8
Product:
log4j
log4j12
Reference:
CVE-2021-4104
CVE    1
CVE-2021-4104

© SecPod Technologies